Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Zyufoye

#18193of 56,330
15.7Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2026-56010
9.2
2026-07-06
Unknown · Fossbilling · CVE-2026-42341
**Name of the Vulnerable Software and Affected Versions** FOSSBilling versions 0.6.0 through 0.7.2 **Description** An unauthenticated payment bypass exists in the IPN callback endpoint `/ipn.php`. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment by sending a single crafted HTTP request. **Recommendations** Update to version 0.8.0. Disable the Custom payment gateway if not actively needed. Restrict access to the `/ipn.php` endpoint at the web server level using IP allowlisting.
PT-2025-16783
6.5
2025-04-16
Apache · Apache Hertzbeat · CVE-2024-56736
**Name of the Vulnerable Software and Affected Versions** Apache HertzBeat versions prior to 1.7.0 **Description** The issue is a Server-Side Request Forgery (SSRF) vulnerability. It affects the Api Config Oss. Users are recommended to upgrade to version 1.7.0 to fix the issue. **Recommendations** For versions prior to 1.7.0, upgrade to version 1.7.0 to resolve the issue. As a temporary workaround, consider restricting access to the Api Config Oss to minimize the risk of exploitation.