Vulnerabilities
33 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-40602 | The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no restrictions. This gave users access to Python's internals and extended the scope of templating beyond the intended usage. This vulnerability is fixed in 1.0.0. NVD description · AI analysis pending | 5.6 | <1% |
| — | ||
| CVE-2025-22984 +1 in the same advisory: …22983 | An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information. An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2024-48202 | icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile. icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2024-46612 | IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information. IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2023-6756 | A vulnerability was found in Thecosy IceCMS 2.0.1. A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown function of the file /login of the component Captcha Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247884. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2023-6466 +1 in the same advisory: …6467 | A vulnerability was found in Thecosy IceCMS 2.0.1. A vulnerability was found in Thecosy IceCMS 2.0.1. It has been declared as problematic. This vulnerability affects unknown code of the file /planet of the component User Comment Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-246616. NVD description · AI analysis pending | 6.1 group max | <1% | PoC |
| — | |
| CVE-2023-6438 | A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /WebArticle/articles/ of the component Like Handler. The manipulation leads to improper enforcement of a single, unique action. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-246438 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2023-40833 | An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSetting. An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSetting. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-33355 +1 in the same advisory: …33356 | IceCMS v1.0.0 has Insecure Permissions. IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitive information. NVD description · AI analysis pending | 7.5 group max | <1% | PoC |
| — | |
| CVE-2021-27417 | eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflow. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2018-12338 | Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confidential information and manipulate security Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confidential information and manipulate security relevant configurations via remote root SSH access. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2018-12336 | Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH access. Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH access. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2017-1000020 | SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos Embedded Web Servers used by Multiple Routers and Home devices, while sending SYN Flood or FIN Flood packets fails to validate and handle the packets and does not ask for any sign of authentication resulting in Authentication Bypass. An attacker can take complete advantage of this bug and take over the device remotely or locally. The bug has been successfully tested and reproduced in some versions of SOHO Routers manufactured by TOTOLINK, GREATEK and others." NVD description · AI analysis pending | 9.8 | 3% |
| — |