Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Xy-0

#21666of 57,338
13.1Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-98869
5.6
2026-09-25
Zhonglun · Cloudpos · CVE-2026-97866
**Name of the Vulnerable Software and Affected Versions** Zhonglun CloudPOS version 3.0 **Description** A weakness exists in the Automatic Update component within the `Program.cs` file. A remote attacker can manipulate the `version`, `url`, `packagekey`, and `package name` arguments to make a channel accessible to non-endpoints. This attack is highly complex and difficult to exploit. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-98933
7.5
2026-09-25
Zhonglun · Cloudpos · CVE-2026-97871
A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of the file ZlPos/ZlPos/Bizlogic/JSBridge.cs of the component JSBridge. Such manipulation of the argument url leads to code injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.