Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

HGiga — Vulnerabilities & Security Advisories 43

Browse all 43 CVE security advisories affecting HGiga. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HGiga operates as a digital content aggregation and streaming platform, primarily facilitating access to media files through decentralized networks. Security audits have identified forty-one distinct Common Vulnerabilities and Exposures (CVEs) associated with its infrastructure, indicating a persistent pattern of technical debt. The most prevalent vulnerability classes involve remote code execution (RCE) and cross-site scripting (XSS), often stemming from inadequate input validation in web interfaces. Additionally, instances of broken access control and privilege escalation have been documented, allowing unauthorized users to manipulate system resources or access restricted data. These flaws frequently arise from legacy codebases and insufficient security testing during rapid deployment cycles. While no single catastrophic data breach has been widely publicized, the cumulative risk of these vulnerabilities poses significant threats to user privacy and system integrity, highlighting the urgent need for comprehensive architectural remediation and rigorous patch management protocols within the organization.

CVE ID Title CVSS Severity Published
CVE-2026-93468 HGiga|OAKlouds - Arbitrary File Read — OAKlouds-bulletin_v3-2.0 CWE-23 7.5 High 2026-09-18
CVE-2026-93467 HGiga|OAKlouds - Insecure Deserialization — OAKlouds-custom_page-2.0 CWE-502 9.8 Critical 2026-09-18
CVE-2026-6349 HGiga|iSherlock - OS Command Injection — iSherlock-base-4.5 CWE-78 9.8 Critical 2026-04-16
CVE-2026-2236 HGiga|C&Cm@il - SQL Injection — C&Cm@il package olln-base CWE-89 7.5 High 2026-02-09
CVE-2026-2235 HGiga|C&Cm@il - SQL Injection — C&Cm@il package olln-base CWE-89 6.5 Medium 2026-02-09
CVE-2026-2234 HGiga|C&Cm@il - Missing Authentication — C&Cm@il package olln-base CWE-306 9.1 Critical 2026-02-09
CVE-2025-11900 HGiga|iSherlock - OS Command Injection — iSherlock 4.5 CWE-78 9.8 Critical 2025-10-17
CVE-2025-7451 Hgiga|iSherlock - OS Command Injection — iSherlock-maillog-4.5 CWE-78 9.8 Critical 2025-07-14
CVE-2025-3364 HGiga PowerStation - Chroot Escape — PowerStation CWE-250 6.7 Medium 2025-04-08
CVE-2025-3363 HGiga iSherlock - OS Command Injection — iSherlock 4.5 CWE-78 9.8 Critical 2025-04-08
CVE-2025-3362 HGiga iSherlock - OS Command Injection — iSherlock 4.5 CWE-78 9.8 Critical 2025-04-08
CVE-2025-3361 HGiga iSherlock - OS Command Injection — iSherlock 4.5 CWE-78 9.8 Critical 2025-04-08
CVE-2025-2150 HGiga C&Cm@il - Stored Cross-Site Scripting — C&Cm@il CWE-79 5.4 Medium 2025-03-10
CVE-2024-9924 Hgiga OAKlouds - Arbitrary File Read And Delete — OAKlouds CWE-36 9.8 Critical 2024-10-14
CVE-2024-4299 HGiga iSherlock - Command Injection — iSherlock 4.5 CWE-78 7.2 High 2024-04-29
CVE-2024-4298 HGiga iSherlock - Command Injection — iSherlock 4.5 CWE-78 7.2 High 2024-04-29
CVE-2024-4297 HGiga iSherlock - Arbitrary File Download — iSherlock 4.5 CWE-22 4.9 Medium 2024-04-29
CVE-2024-4296 HGiga iSherlock - Arbitrary File Download — iSherlock 4.5 CWE-22 4.9 Medium 2024-04-29
CVE-2024-26261 Hgiga OAKlouds - Arbitrary File Read And Delete — OAKlouds CWE-22 9.8 Critical 2024-02-15
CVE-2024-26260 Hgiga OAKlouds - Command Injection — OAKlouds CWE-78 9.8 Critical 2024-02-15
CVE-2023-37292 HGiga iSherlock - Command Injection — iSherlock 4.5 CWE-78 9.8 Critical 2023-07-21
CVE-2023-24842 HGiga MailSherlock - Broken Access Control — MailSherlock CWE-639 5.3 Medium 2023-03-27
CVE-2023-24841 HGiga MailSherlock - Command Injection — MailSherlock CWE-78 7.2 High 2023-03-27
CVE-2023-24840 HGiga MailSherlock - SQL Injection — MailSherlock CWE-89 7.2 High 2023-03-27
CVE-2023-24839 HGiga MailSherlock - Reflected XSS — MailSherlock CWE-79 6.1 Medium 2023-03-27
CVE-2023-24838 HGiga PowerStation - Information Leakage — PowerStation CWE-200 9.8 Critical 2023-03-27
CVE-2023-24837 HGiga PowerStation - Command Injection — PowerStation CWE-78 8.8 High 2023-03-27
CVE-2022-38118 HGiga OAKlouds - SQL Injection — OAKlouds CWE-89 8.8 High 2022-08-30
CVE-2021-37913 HGiga OAKlouds - Command Injection-2 — OAKlouds OAKSv2 CWE-78 9.8 Critical 2021-09-15
CVE-2021-37912 HGiga OAKlouds - Command Injection-1 — OAKlouds OAKSv2 CWE-78 9.8 Critical 2021-09-15

This page lists every published CVE security advisory associated with HGiga. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.