termix records
9 published records for vendor termix.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 22.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-284 Improper Access Control2
- CWE-295 Improper Certificate Validation1
- CWE-308 Use of Single-factor Authentication1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-45744No exploit | Termix has an OS Command Injection in File Manager resolvePath endpointtermix · termix · CWE-78 | Critical9.9 | — | 3.0% | Jun 5, 2026 |
40Plan | CVE-2026-45748No exploit | Termix Vulnerable to Remote Code Execution via SSH Tunnel Forward Command Injectiontermix · termix · CWE-78 | Critical9.8 | — | 2.5% | Jun 5, 2026 |
37Monitor | CVE-2025-59951No exploit | Termix' official Docker image contains an authentication bypass vulnerabilitytermix · termix · CWE-284 | Critical9.2 | — | 4.3% | Oct 1, 2025 |
36Monitor | CVE-2026-45746Proof of concept | Termix Vulnerable to Arbitrary Command Execution via Session Hijackingtermix · termix · CWE-284 | Critical9.0 | — | 0.6% | Jun 5, 2026 |
36Monitor | CVE-2026-45750No exploit | Termix Vulnerable to Arbitrary Command Execution in File Managertermix · termix · CWE-78 | Critical9.0 | — | 0.4% | Jun 5, 2026 |
32Monitor | CVE-2026-45749No exploit | Termix's TOTP two-factor authentication can be disabled or bypassed using only the account passwordtermix · termix · CWE-308 | High8.1 | — | 0.5% | Jun 5, 2026 |
32Monitor | CVE-2026-45743No exploit | Termix has a File-Manager Session Hijack via Missing Ownership Check (IDOR)termix · termix · CWE-639 | High8.1 | — | 0.4% | Jun 5, 2026 |
32Monitor | CVE-2026-45745No exploit | Termix has improper certificate validation in Electron desktop client that enables MITM credential/token thefttermix · termix · CWE-295 | High8.0 | — | 0.2% | Jun 5, 2026 |
18Monitor | CVE-2026-22804Proof of concept | Termix has a Stored XSS in File Manager leading to Local File Inclusion (LFI) in Electron and Session Hijacking in Browsertermix · termix · CWE-79 | Medium4.7 | — | 0.2% | Jan 12, 2026 |
- CVE-2026-4574440Plan
Termix has an OS Command Injection in File Manager resolvePath endpoint
CriticalCVSS 9.9No exploitEPSS 3%termix · termixJun 5, 2026
- CVE-2026-4574840Plan
Termix Vulnerable to Remote Code Execution via SSH Tunnel Forward Command Injection
CriticalCVSS 9.8No exploitEPSS 3%termix · termixJun 5, 2026
- CVE-2025-5995137Monitor
Termix' official Docker image contains an authentication bypass vulnerability
CriticalCVSS 9.2No exploitEPSS 4%termix · termixOct 1, 2025
- CVE-2026-4574636Monitor
Termix Vulnerable to Arbitrary Command Execution via Session Hijacking
CriticalCVSS 9.0Proof of conceptEPSS 1%termix · termixJun 5, 2026
- CVE-2026-4575036Monitor
Termix Vulnerable to Arbitrary Command Execution in File Manager
CriticalCVSS 9.0No exploitEPSS 0%termix · termixJun 5, 2026
- CVE-2026-4574932Monitor
Termix's TOTP two-factor authentication can be disabled or bypassed using only the account password
HighCVSS 8.1No exploitEPSS 0%termix · termixJun 5, 2026
- CVE-2026-4574332Monitor
Termix has a File-Manager Session Hijack via Missing Ownership Check (IDOR)
HighCVSS 8.1No exploitEPSS 0%termix · termixJun 5, 2026
- CVE-2026-4574532Monitor
Termix has improper certificate validation in Electron desktop client that enables MITM credential/token theft
HighCVSS 8.0No exploitEPSS 0%termix · termixJun 5, 2026
- CVE-2026-2280418Monitor
Termix has a Stored XSS in File Manager leading to Local File Inclusion (LFI) in Electron and Session Hijacking in Browser
MediumCVSS 4.7Proof of conceptEPSS 0%termix · termixJan 12, 2026