Vulnerabilidades em Termix-SSH

25 resultados
Análise Vexday

Termix-SSH apresenta 11 vulnerabilidades registradas, com 5 em nível crítico e 10 publicadas nos últimos 90 dias, indicando ritmo acelerado de descobertas. A fraqueza dominante é injeção de comando (CWE-78), padrão de risco elevado em software de acesso remoto. Apesar do volume e severidade, nenhuma vulnerabilidade está sob ataque ativo documentado até o momento.

CVE-2026-45744CRITICALTermix has an OS Command Injection in File Manager resolvePath endpointEPSS 3.0%CVE-2026-45748CRITICALTermix Vulnerable to Remote Code Execution via SSH Tunnel Forward Command InjectionEPSS 2.5%CVE-2026-42453HIGHTermix: Command injection in extractArchive/compressFiles via double-quote escaping bypassEPSS 1.6%CVE-2026-42454CRITICALTermix: OS Command Injection in Docker Container Management EndpointsEPSS 0.9%CVE-2026-53545CRITICALTermix: Remote Code Execution via Tunnel Disconnect pkill Command InjectionEPSS 0.7%CVE-2026-53542HIGHTermix: Tar option injection in file-manager archive creation allows command execution on managed SSH hostsEPSS 0.7%CVE-2026-45746CRITICALTermix Vulnerable to Arbitrary Command Execution via Session HijackingEPSS 0.6%CVE-2026-53547HIGHTermix: Account Takeover via Global Settings DisclosureEPSS 0.5%CVE-2026-45749HIGHTermix's TOTP two-factor authentication can be disabled or bypassed using only the account passwordEPSS 0.5%CVE-2026-53548CRITICALTermix: IDOR — Authenticated user can fetch SSH passwords for hosts owned by other usersEPSS 0.5%CVE-2026-53546CRITICALTermix: Missing authorization in SSH host credential resolution exposes stored credentialsEPSS 0.5%CVE-2026-53549HIGHTermix: Server-Side Request Forgery via Proxy Connectivity TestEPSS 0.5%CVE-2026-79758MEDIUMTermix: Authenticated users can read other users' host status and clear global SSH connectionsEPSS 0.4%CVE-2026-45750CRITICALTermix Vulnerable to Arbitrary Command Execution in File ManagerEPSS 0.4%CVE-2026-79764HIGHTermix: Authenticated SSRF via `/homepage/proxy` — No Destination AllowlistEPSS 0.4%CVE-2026-45743HIGHTermix has a File-Manager Session Hijack via Missing Ownership Check (IDOR)EPSS 0.4%CVE-2026-42452HIGHTermix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTPEPSS 0.4%CVE-2026-79766CRITICALTermix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/emailEPSS 0.4%CVE-2026-79761MEDIUMTermix: Command injection in SSH key deployment verificationEPSS 0.4%CVE-2026-79763MEDIUMTermix: MFA-critical operations accept the account password as a sole factor (regression of CVE-2026-45749)EPSS 0.3%