Vulnerabilidades en Termix-SSH
25 resultadosAnálisis Vexday
Termix-SSH apresenta 11 vulnerabilidades registradas, com 5 em nível crítico e 10 publicadas nos últimos 90 dias, indicando ritmo acelerado de descobertas. A fraqueza dominante é injeção de comando (CWE-78), padrão de risco elevado em software de acesso remoto. Apesar do volume e severidade, nenhuma vulnerabilidade está sob ataque ativo documentado até o momento.
CVE-2026-79760MEDIUMTermix: Authenticated blind SSRF through notification channel test endpointsEPSS 0.3%CVE-2026-79759MEDIUMTermix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host EndpointEPSS 0.3%CVE-2026-45745HIGHTermix has improper certificate validation in Electron desktop client that enables MITM credential/token theftEPSS 0.2%CVE-2026-22804HIGHTermix has a Stored XSS in File Manager leading to Local File Inclusion (LFI) in Electron and Session Hijacking in BrowserEPSS 0.2%CVE-2026-79762MEDIUMTermix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — full offline decryption from a database copyEPSS 0.1%