6.5

CVSS3.1

CVE-2025-64994 - Privilege Escalation via Uncontrolled Search Path in 1E-Nomad-SetWorkRate instruction

A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior V17.1. The improper handling of executable search paths could allow local attackers with write access to a PATH directory on a device to escalate pri…

πŸ“… Published: Dec. 11, 2025, 11:29 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 2:04 a.m.

6.8

CVSS3.1

CVE-2025-64993 - Command Injection in 1E-ConfigMgrConsoleExtensions Instructions

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote exec…

πŸ“… Published: Dec. 11, 2025, 11:29 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 2:06 a.m.

6.8

CVSS3.1

CVE-2025-64992 - Command Injection in 1E-Nomad-PauseNomadJobQueue Instruction

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction prior V25. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remo…

πŸ“… Published: Dec. 11, 2025, 11:28 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 2:08 a.m.

6.8

CVSS3.1

CVE-2025-64991 - Command Injection in 1E-PatchInsights-Deploy Instruction

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior V15. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote e…

πŸ“… Published: Dec. 11, 2025, 11:28 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 2:09 a.m.

6.8

CVSS3.1

CVE-2025-64990 - Command Injection in 1E-Explorer-TachyonCore-LogoffUser Instruction

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation ena…

πŸ“… Published: Dec. 11, 2025, 11:27 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 8:18 p.m.

7.2

CVSS3.1

CVE-2025-64989 - Command Injection in 1E-Explorer-TachyonCore-FindFileBySizeAndHash Instruction

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-FindFileBySizeAndHash instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Explo…

πŸ“… Published: Dec. 11, 2025, 11:27 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 8:17 p.m.

7.2

CVSS3.1

CVE-2025-64988 - Command Injection in 1E-Nomad-GetCmContentLocations Instruction

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instruction prior V19.2. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables…

πŸ“… Published: Dec. 11, 2025, 11:26 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

7.2

CVSS3.1

CVE-2025-64987 - Command Injection in 1E-Explorer-TachyonCore-CheckSimpleIoC Instruction

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables rem…

πŸ“… Published: Dec. 11, 2025, 11:26 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 7:58 p.m.

7.2

CVSS3.1

CVE-2025-64986 - Command Injection in 1E-Explorer-TachyonCore-DevicesListeningOnAPort Instruction

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningOnAPort instruction prior V21. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Explo…

πŸ“… Published: Dec. 11, 2025, 11:26 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 8 p.m.

4.3

CVSS3.1

CVE-2025-46266 - Unauthenticated Transmission of Data in NomadBranch.exe

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to coerce the service into transmitting data to an arbitrary internal IP address, potentially leaking sensitive information.

πŸ“… Published: Dec. 11, 2025, 11:25 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 7:57 p.m.
Total resulsts: 346617
Page 2406 of 34,662
Β« previous page Β» next page
Filters