Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2025-59818
This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
Tcis 3 Firmware
9.2.3.3+
CRITICAL 9.8
CVE-2025-64093
Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.
Icx500 Firmware
1.4.3.3+
HIGH 8.8
CVE-2025-64090
This vulnerability allows authenticated attackers to execute commands via the hostname of the device.
Tcis 3 Firmware
9.2.3.3+
HIGH 8.8
CVE-2025-64091
This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.
Tcis 3 Firmware
9.2.3.3+
HIGH 7.5
CVE-2025-64092
This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly query the underlying database.
Icx500 Firmware
1.4.3.3+
HIGH 8.8
CVE-2021-40845
The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section a…
Alphacom Xe Audio Server
after 11.2.3.10
MEDIUM 6.1
CVE-2018-19926
Zenitel Norway IP-StationWeb before 4.2.3.9 allows reflected XSS via the goform/ PATH_INFO.
Ip Stationweb Firmware
4.2.3.9+