Loading HuntDB...

Known Exploited Vulnerabilities

Search through CISA's catalog of actively exploited vulnerabilities

Press Enter to search
356,740 vulnerabilities found
Showing 21 - 40

CWP Control Web Panel OS Command Injection Vulnerability

Added November 4, 2025 CVE-2025-48703
Due Soon

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CWP Control Web Panel
Due by November 25, 2025
Catalog 2025.11.21

CWP Control Web Panel OS Command Injection Vulnerability

Added November 4, 2025 CVE-2025-48703
Due Soon

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CWP Control Web Panel
Due by November 25, 2025
Catalog 2025.11.21

CWP Control Web Panel OS Command Injection Vulnerability

Added November 4, 2025 CVE-2025-48703
Due Soon

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CWP Control Web Panel
Due by November 25, 2025
Catalog 2025.11.21

CWP Control Web Panel OS Command Injection Vulnerability

Added November 4, 2025 CVE-2025-48703
Due Soon

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CWP Control Web Panel
Due by November 25, 2025
Catalog 2025.11.21

CWP Control Web Panel OS Command Injection Vulnerability

Added November 4, 2025 CVE-2025-48703
Due Soon

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CWP Control Web Panel
Due by November 25, 2025
Catalog 2025.11.21

CWP Control Web Panel OS Command Injection Vulnerability

Added November 4, 2025 CVE-2025-48703
Due Soon

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CWP Control Web Panel
Due by November 25, 2025
Catalog 2025.11.21

CWP Control Web Panel OS Command Injection Vulnerability

Added November 4, 2025 CVE-2025-48703
Due Soon

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CWP Control Web Panel
Due by November 25, 2025
Catalog 2025.11.21

CWP Control Web Panel OS Command Injection Vulnerability

Added November 4, 2025 CVE-2025-48703
Due Soon

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CWP Control Web Panel
Due by November 25, 2025
Catalog 2025.11.21

CWP Control Web Panel OS Command Injection Vulnerability

Added November 4, 2025 CVE-2025-48703
Due Soon

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CWP Control Web Panel
Due by November 25, 2025
Catalog 2025.11.21

CWP Control Web Panel OS Command Injection Vulnerability

Added November 4, 2025 CVE-2025-48703
Due Soon

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CWP Control Web Panel
Due by November 25, 2025
Catalog 2025.11.21

XWiki Platform Eval Injection Vulnerability

Added October 30, 2025 CVE-2025-24893
Overdue

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.

XWiki Platform
Due by November 20, 2025
Catalog 2025.11.21

Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

Added October 30, 2025 CVE-2025-41244
Overdue

Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Broadcom VMware Aria Operations and VMware Tools
Due by November 20, 2025
Catalog 2025.11.21

Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

Added October 30, 2025 CVE-2025-41244
Overdue

Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Broadcom VMware Aria Operations and VMware Tools
Due by November 20, 2025
Catalog 2025.11.21

XWiki Platform Eval Injection Vulnerability

Added October 30, 2025 CVE-2025-24893
Overdue

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.

XWiki Platform
Due by November 20, 2025
Catalog 2025.11.21

Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

Added October 30, 2025 CVE-2025-41244
Overdue

Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Broadcom VMware Aria Operations and VMware Tools
Due by November 20, 2025
Catalog 2025.11.21

XWiki Platform Eval Injection Vulnerability

Added October 30, 2025 CVE-2025-24893
Overdue

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.

XWiki Platform
Due by November 20, 2025
Catalog 2025.11.21

Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

Added October 30, 2025 CVE-2025-41244
Overdue

Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Broadcom VMware Aria Operations and VMware Tools
Due by November 20, 2025
Catalog 2025.11.21

XWiki Platform Eval Injection Vulnerability

Added October 30, 2025 CVE-2025-24893
Overdue

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.

XWiki Platform
Due by November 20, 2025
Catalog 2025.11.21

Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

Added October 30, 2025 CVE-2025-41244
Overdue

Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Broadcom VMware Aria Operations and VMware Tools
Due by November 20, 2025
Catalog 2025.11.21

XWiki Platform Eval Injection Vulnerability

Added October 30, 2025 CVE-2025-24893
Overdue

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.

XWiki Platform
Due by November 20, 2025
Catalog 2025.11.21