Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-53982 PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate databas… Pmb No fix yet Fix from $1,9502025-12-23 CRITICAL 9.8 CVE-2025-61168 An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file. Pmb Mitigation only Fix from $2,3002025-11-25 MEDIUM 6.5 CVE-2025-61167 SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php component via the id and datas… Pmb Mitigation only Fix from $1,6002025-11-25 CRITICAL 9.8 CVE-2025-48742 The installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution. Pmb 8.0.1.2+ Fix from $2,3002025-05-27 CRITICAL 9.8 CVE-2025-48743 SIGB PMB before 8.0.1.2 allows SQL injection. Pmb 8.0.1.2+ Fix from $2,3002025-05-27 CRITICAL 9.8 CVE-2025-48744 In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution. Pmb 8.0.1.2+ Fix from $2,3002025-05-27 HIGH 7.5 CVE-2025-0472 Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to upload a file to the environ… Pmb after 4.2.13 Fix from $1,9502025-01-16 HIGH 7.5 CVE-2025-0473 Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4.0.10 and above. This vulnera… Pmb Mitigation only Fix from $1,9502025-01-16 CRITICAL 9.8 CVE-2025-0471 Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload… Pmb Mitigation only Fix from $2,3002025-01-16 CRITICAL 9.8 CVE-2024-26289 Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB: from 7.5.1 before 7.5.6-2, f… Pmb 7.3.18 / 7.4.9+ Fix from $2,3002024-05-27 CRITICAL 9.8 CVE-2023-52153 A SQL Injection vulnerability in /pmb/opac_css/includes/sessions.inc.php in PMB 7.4.7 and earlier allows remote unauthenticated attackers to inject a… Pmb after 7.4.7 Fix from $2,3002024-02-21 HIGH 7.2 CVE-2023-52154 File Upload vulnerability in pmb/camera_upload.php in PMB 7.4.7 and earlier allows attackers to run arbitrary code via upload of crafted PHTML files. Pmb after 7.4.7 Fix from $1,9502024-02-21 HIGH 7.2 CVE-2023-52155 A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attackers to execute arbitrary SQL co… Pmb after 7.4.7 Fix from $1,9502024-02-21 CRITICAL 9.8 CVE-2023-51828 A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute… Pmb after 7.4.7 Fix from $2,3002024-02-21 CRITICAL 9.8 CVE-2023-37177 SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query p… Pmb after 7.4.7 Fix from $2,3002024-02-21 HIGH 7.5 CVE-2023-38844 SQL injection vulnerability in PMB v.7.4.7 and earlier allows a remote attacker to execute arbitrary code via the thesaurus parameter in export_skos.… Pmb after 7.4.7 Fix from $1,9502024-02-21 HIGH 7.2 CVE-2023-46474EPSS 21% File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to t… Pmb after 7.5.3 Fix from $1,9502024-01-11 CRITICAL 9.8 CVE-2023-24734EPSS 21% An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted imag… Pmb No fix yet Fix from $2,3002023-03-06 CRITICAL 9.8 CVE-2023-24736 PMB v7.4.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /sauvegarde/restaure_act.php. Pmb No fix yet Fix from $2,3002023-03-06 MEDIUM 6.1 CVE-2023-24733 PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950_new.… Pmb No fix yet Fix from $1,6002023-03-06 MEDIUM 6.1 CVE-2023-24735 PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redir… Pmb No fix yet Fix from $1,6002023-03-06 MEDIUM 6.1 CVE-2023-24737 PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950.php. Pmb No fix yet Fix from $1,6002023-03-06 MEDIUM 6.1 CVE-2022-34328 PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php. Pmb No fix yet Fix from $1,6002022-06-23