VulnSea

CWE-489

CVEs classified under CWE-489, newest first.

8 CVEsRSS

CVE-2026-81943Medium· 6.7
4d ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software. An attacker with privileged access to the device can enable …

SunlitPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 0.13%via NVD
CVE-2026-53952Critical· 9.8
1w ago

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to …

MidnightGetSimpleCMS-CE · GetSimpleCMS-CEEPSS 0.33%via NVD
CVE-2026-6485High· 8.2
1w ago

UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.

UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.

TwilightInsyde Software · InsydeH2OEPSS 0.12%via NVD
CVE-2026-58191Medium· 6.5PoC
3w ago

Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

Twilightappium · @appium/base-driverEPSS 0.44%via GHSA
CVE-2026-41186High· 7.5
1mo ago

When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication

When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listen…

Twilighttigera · calicoEPSS 0.34%via NVD
GHSA-fq3w-p4fg-mw73Low
2mo ago

fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`

fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`

Sunlitfixurjavainstall · fixurjavainstallvia GHSA
CVE-2026-32662Medium· 5.3PoC
5mo ago

Development and test API endpoints are present that mirror production functionality.

Development and test API endpoints are present that mirror production functionality.

Twilightmygardyn · cloud_apiEPSS 0.32%via NVD
CVE-2025-4106None
11mo ago

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover dia…

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover dia…

SunlitEPSS 0.30%via NVD
CWE-489 vulnerabilities (CVEs) · VulnSea