VulnSea

CWE-912

CVEs classified under CWE-912, newest first.

7 CVEsRSS

CVE-2026-80217High· 8.8
1w ago

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

TwilightLITE-ON Technology Corporation · FF-RFI079I4EPSS 0.28%via NVD
CVE-2026-18844High· 8.1
1mo ago

The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface

The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion m…

TwilightEPSS 0.13%via NVD
CVE-2026-61515Critical· 9.8
1mo ago

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShel…

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShel…

MidnightEPSS 1.6%via NVD
CVE-2026-4769Critical· 9.8
2mo ago

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief p…

MidnightEPSS 0.76%via NVD
CVE-2026-31847High· 8.8
6mo ago

Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service

Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sending a crafted POST request with parameters such as telnetMa…

Twilightnexxtsolutions · nebula300plus_firmwareEPSS 0.42%via NVD
CVE-2010-20103Critical· 9.8PoC
1y ago

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute a…

Abyssalproftpd · proftpdEPSS 5.1%via NVD
CVE-2020-3352Medium· 5.5
5y ago

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access hidden commands

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access hidden commands. The vulnerability is due to the presence of undocumented configuration commands. An attac…

Sunlitcisco · secure_firewall_threat_defenseEPSS 0.27%via NVD
CWE-912 vulnerabilities (CVEs) · VulnSea