CVE-2025-54322Critical· 10.0▾ AbyssalPoC availableXspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 55 · likelihood 3 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
15%
2 GitHub repos (last check)
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.
sxzos <= 2025-12-26Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105315Medium· 4.7A vulnerability has been found in django-haystack up to 3.3.0
CVE-2023-3519Critical· 9.8Unauthenticated remote code execution
CVE-2021-44529Critical· 9.8A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
CVE-2021-22205Critical· 10.0An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9
CVE-2025-34159High· 8.8Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow
CVE-2025-15148Medium· 4.7A flaw has been found in CmsEasy up to 7.7.7