Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2023-53982
PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate databas…
Pmb
No fix yet
CRITICAL 9.8
CVE-2025-61168
An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.
Pmb
Mitigation only
MEDIUM 6.5
CVE-2025-61167
SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php component via the id and datas…
Pmb
Mitigation only
CRITICAL 9.8
CVE-2025-48742
The installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution.
Pmb
8.0.1.2+
CRITICAL 9.8
CVE-2025-48743
SIGB PMB before 8.0.1.2 allows SQL injection.
Pmb
8.0.1.2+
CRITICAL 9.8
CVE-2025-48744
In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution.
Pmb
8.0.1.2+
HIGH 7.5
CVE-2025-0472
Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to upload a file to the environ…
Pmb
after 4.2.13
HIGH 7.5
CVE-2025-0473
Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4.0.10 and above. This vulnera…
Pmb
Mitigation only
CRITICAL 9.8
CVE-2025-0471
Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload…
Pmb
Mitigation only
CRITICAL 9.8
CVE-2024-26289
Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB: from 7.5.1 before 7.5.6-2, f…
Pmb
7.3.18 / 7.4.9+
CRITICAL 9.8
CVE-2023-52153
A SQL Injection vulnerability in /pmb/opac_css/includes/sessions.inc.php in PMB 7.4.7 and earlier allows remote unauthenticated attackers to inject a…
Pmb
after 7.4.7
HIGH 7.2
CVE-2023-52154
File Upload vulnerability in pmb/camera_upload.php in PMB 7.4.7 and earlier allows attackers to run arbitrary code via upload of crafted PHTML files.
Pmb
after 7.4.7
HIGH 7.2
CVE-2023-52155
A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attackers to execute arbitrary SQL co…
Pmb
after 7.4.7
CRITICAL 9.8
CVE-2023-51828
A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute…
Pmb
after 7.4.7
CRITICAL 9.8
CVE-2023-37177
SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query p…
Pmb
after 7.4.7
HIGH 7.5
CVE-2023-38844
SQL injection vulnerability in PMB v.7.4.7 and earlier allows a remote attacker to execute arbitrary code via the thesaurus parameter in export_skos.…
Pmb
after 7.4.7
HIGH 7.2
CVE-2023-46474EPSS 21%
File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to t…
Pmb
after 7.5.3
CRITICAL 9.8
CVE-2023-24734EPSS 21%
An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted imag…
Pmb
No fix yet
CRITICAL 9.8
CVE-2023-24736
PMB v7.4.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /sauvegarde/restaure_act.php.
Pmb
No fix yet
MEDIUM 6.1
CVE-2023-24733
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950_new.…
Pmb
No fix yet
MEDIUM 6.1
CVE-2023-24735
PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redir…
Pmb
No fix yet
MEDIUM 6.1
CVE-2023-24737
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950.php.
Pmb
No fix yet
MEDIUM 6.1
CVE-2022-34328
PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.
Pmb
No fix yet