6.8

CVSS3.1

CVE-2025-64990 - Command Injection in 1E-Explorer-TachyonCore-LogoffUser Instruction

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation ena…

πŸ“… Published: Dec. 11, 2025, 11:27 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 8:18 p.m.

7.2

CVSS3.1

CVE-2025-64989 - Command Injection in 1E-Explorer-TachyonCore-FindFileBySizeAndHash Instruction

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-FindFileBySizeAndHash instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Explo…

πŸ“… Published: Dec. 11, 2025, 11:27 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 8:17 p.m.

7.2

CVSS3.1

CVE-2025-64988 - Command Injection in 1E-Nomad-GetCmContentLocations Instruction

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instruction prior V19.2. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables…

πŸ“… Published: Dec. 11, 2025, 11:26 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

7.2

CVSS3.1

CVE-2025-64987 - Command Injection in 1E-Explorer-TachyonCore-CheckSimpleIoC Instruction

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables rem…

πŸ“… Published: Dec. 11, 2025, 11:26 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 7:58 p.m.

7.2

CVSS3.1

CVE-2025-64986 - Command Injection in 1E-Explorer-TachyonCore-DevicesListeningOnAPort Instruction

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningOnAPort instruction prior V21. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Explo…

πŸ“… Published: Dec. 11, 2025, 11:26 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 8 p.m.

4.3

CVSS3.1

CVE-2025-46266 - Unauthenticated Transmission of Data in NomadBranch.exe

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to coerce the service into transmitting data to an arbitrary internal IP address, potentially leaking sensitive information.

πŸ“… Published: Dec. 11, 2025, 11:25 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 7:57 p.m.

8.8

CVSS3.1

CVE-2025-44016 - File Hash Validation Bypass in NomadBranch.exe

A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted request. By providing a valid hash for a malicious file, an attacker can cause the s…

πŸ“… Published: Dec. 11, 2025, 11:24 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 7:57 p.m.

6.5

CVSS3.1

CVE-2025-12687 - Denial-of-Service Vulnerability in NomadBranch.exe

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to cause a denial of service (application crash) via a crafted command, resulting in service termination.

πŸ“… Published: Dec. 11, 2025, 11:24 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 7:56 p.m.

8.5

CVSS4.0

CVE-2025-64701 -

QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system with the affected product to gain administrator privileges. As a result, sensitive information may be accessed or altered, and arbitrary action…

πŸ“… Published: Dec. 11, 2025, 8:13 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 3:18 p.m.

8

CVSS3.1

CVE-2025-12029 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious e…

πŸ“… Published: Dec. 11, 2025, 7:32 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.
Total resulsts: 343040
Page 2050 of 34,304
Β« previous page Β» next page
Filters