Browse all 4 CVE security advisories affecting part-db. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Part-db serves as an inventory management system for electronic components, enabling users to track parts, suppliers, and projects. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, often stemming from insufficient input validation and access controls. The application's web interface and database integration have created attack surfaces for unauthorized access. While no major public security incidents have been documented, the four recorded CVEs highlight consistent security concerns in areas such as file handling and authentication. Users should implement strict access controls and maintain regular updates to mitigate risks associated with these common vulnerability classes.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2019-25432 | Part-DB 0.4 Authentication Bypass via login.php — Part-DBCWE-89 | 7.5 | High | 2026-02-20 |
| CVE-2025-55194 | Part-DB Persistent Denial of Service via Uncaught Exception from Misleading File Extension in Avatar Upload — Part-DB-serverCWE-248 | 5.7 | Medium | 2025-08-13 |
| CVE-2023-26042 | HTML/XSS injection possibilities in Part-DB — Part-DB-serverCWE-79 | 6.1 | Medium | 2023-02-27 |
| CVE-2022-0848 | OS Command Injection in part-db/part-db — part-db/part-dbCWE-78 | 9.8 | - | 2022-03-04 |
This page lists every published CVE security advisory associated with part-db. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.