NVD disclosure day

Published threat advisories for August 30, 2025

CVE advisoryCRITICAL

CVE-2009-20011

ContentKeeper Web Appliance Remote Command Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in the ContentKeeper Web Appliance, allowing unauthenticated attackers to upload and execute arbitrary scripts via its web interface, potentially leading to root-level access. This could enable unauthorized command execution and system compromise. The reader should care because this web

CVE advisoryCRITICAL

CVE-2009-20010

Dogfood CRM Spell Script Remote Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Dogfood CRM's mail subsystem allows unauthenticated attackers to execute arbitrary server commands via the spell.php script. This occurs because user input is not properly sanitized, enabling command injection through a POST request. Reachable via the network, this issue could lead to server

CVE advisoryCRITICAL

CVE-2009-20009

Belkin Bulldog Plus Authentication Handler Buffer Overflow

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical buffer overflow vulnerability exists in Belkin Bulldog Plus web services, potentially allowing unauthenticated remote code execution via specially crafted HTTP requests. This issue stems from improper input validation in the authentication handler. Confirmation is needed to determine if the affected product