Vulnerabilities
Vulnerable Software
 >> Op-Tee Os  Security Vulnerabilities
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appended recipient addresses to the sendmail command line without a -- end-of-options separator, allowing an address beginning with - to be interpreted as a sendmail command-line option instead of an address. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
CVSS Score
8.7
EPSS Score
0.004
Published
2026-07-14
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external entity resolution and allowing attacker-supplied XML to expand file:// entities such as local files. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
CVSS Score
8.7
EPSS Score
0.005
Published
2026-07-14
CVE-2026-15409
Known exploited
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
CVSS Score
10.0
EPSS Score
0.784
Published
2026-07-14
CVE-2026-15410
Known exploited
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
CVSS Score
7.2
EPSS Score
0.763
Published
2026-07-14
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty while $_SERVER['argv'] still carries attacker-controlled --env or --no-debug flags that change APP_ENV or APP_DEBUG. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
CVSS Score
8.3
EPSS Score
0.004
Published
2026-07-14
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.8
EPSS Score
0.005
Published
2026-07-14
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.8
EPSS Score
0.005
Published
2026-07-14
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVSS Score
7.5
EPSS Score
0.01
Published
2026-07-14
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.8
EPSS Score
0.007
Published
2026-07-14
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVSS Score
8.1
EPSS Score
0.002
Published
2026-07-14


Contact Us

Shodan ® - All rights reserved