|
741
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users …
Update
|
CWE-78
OS Command
|
CVE-2026-45630
|
2026-06-2 04:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
742
|
7.2 |
HIGH
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version…
Update
|
CWE-78
OS Command
|
CVE-2025-41265
|
2026-06-2 03:58 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
743
|
7.2 |
HIGH
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version…
Update
|
CWE-78
OS Command
|
CVE-2025-41266
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
744
|
7.2 |
HIGH
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version…
Update
|
CWE-78
OS Command
|
CVE-2025-41267
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
745
|
9.1 |
CRITICAL
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated att…
Update
|
CWE-23
Relative Path Traversal
|
CVE-2025-41268
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
746
|
9.8 |
CRITICAL
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…
Update
|
CWE-78
OS Command
|
CVE-2025-41269
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
747
|
9.8 |
CRITICAL
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…
Update
|
CWE-78
OS Command
|
CVE-2025-41270
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
748
|
7.5 |
HIGH
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers …
Update
|
CWE-23
Relative Path Traversal
|
CVE-2025-41271
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
749
|
9.8 |
CRITICAL
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…
Update
|
CWE-78
OS Command
|
CVE-2025-41272
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
750
|
9.8 |
CRITICAL
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows…
Update
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-41273
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|