magicbug records
6 published records for vendor magicbug.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-48253No exploit | Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.magicbug · cloudlog · CWE-89 | Critical9.8 | — | 0.4% | Oct 14, 2024 |
39Monitor | CVE-2024-48255No exploit | Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.magicbug · cloudlog · CWE-89 | Critical9.8 | — | 0.4% | Oct 14, 2024 |
39Monitor | CVE-2024-44065No exploit | Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parametmagicbug · cloudlog · CWE-89 | Critical9.8 | — | 0.4% | Dec 26, 2025 |
39Monitor | CVE-2024-45999No exploit | A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /appmagicbug · cloudlog · CWE-89 | Critical9.8 | — | 0.4% | Oct 1, 2024 |
29Monitor | CVE-2024-48259Proof of concept | Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.magicbug · cloudlog · CWE-89 | High7.3 | — | 0.9% | Oct 14, 2024 |
21Monitor | CVE-2025-64084No exploit | An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier.magicbug · cloudlog · CWE-89 | Medium5.4 | — | 0.3% | Nov 14, 2025 |
- CVE-2024-4825339Monitor
Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.
CriticalCVSS 9.8No exploitEPSS 0%magicbug · cloudlogOct 14, 2024
- CVE-2024-4825539Monitor
Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.
CriticalCVSS 9.8No exploitEPSS 0%magicbug · cloudlogOct 14, 2024
- CVE-2024-4406539Monitor
Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults paramet
CriticalCVSS 9.8No exploitEPSS 0%magicbug · cloudlogDec 26, 2025
- CVE-2024-4599939Monitor
A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /app
CriticalCVSS 9.8No exploitEPSS 0%magicbug · cloudlogOct 1, 2024
- CVE-2024-4825929Monitor
Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.
HighCVSS 7.3Proof of conceptEPSS 1%magicbug · cloudlogOct 14, 2024
- CVE-2025-6408421Monitor
An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier.
MediumCVSS 5.4No exploitEPSS 0%magicbug · cloudlogNov 14, 2025