CWE-489
CVEs classified under CWE-489, newest first.
8 CVEsRSS
CVE-2026-81943Medium· 6.7PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software
PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software. An attacker with privileged access to the device can enable …
CVE-2026-53952Critical· 9.8GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to …
CVE-2026-6485High· 8.2UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
CVE-2026-58191Medium· 6.5PoCAppium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
CVE-2026-41186High· 7.5When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication
When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listen…
GHSA-fq3w-p4fg-mw73Lowfixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`
fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`
CVE-2026-32662Medium· 5.3PoCDevelopment and test API endpoints are present that mirror production functionality.
Development and test API endpoints are present that mirror production functionality.
CVE-2025-4106NoneAn authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover dia…
An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover dia…