Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Wl Nu516u1 Firmware HIGH 7.2
CVE-2026-3662EPSS 18%

A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the file /cgi-bin/adm.cgi. Such mani…

No fix yet
Fix from $1,950 2026-03-07
Wl Nu516u1 Firmware HIGH 7.2
CVE-2026-3661EPSS 17%

A flaw has been found in Wavlink WL-NU516U1 240425. This affects the function ota_new_upgrade of the file /cgi-bin/adm.cgi. This manipulation of the …

No fix yet
Fix from $1,950 2026-03-07
Wl Nu516u1 Firmware HIGH 7.2
CVE-2026-3612EPSS 13%

A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/adm.cgi of the component OTA …

No fix yet
Fix from $1,950 2026-03-06
Dir 868l Firmware CRITICAL 9.8
CVE-2026-3485

A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument…

Mitigation only
Fix from $2,300 2026-03-03
Mcp Nmap Server HIGH 8.8
CVE-2026-3484

A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function…

Fix: after 1.0.1
Fix from $1,950 2026-03-03
Unclassified HIGH 7.8
CVE-2025-52365

A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to execute arbitrary system comm…

Mitigation only
Fix from $1,950 2026-03-03
Unclassified MEDIUM 6.5
CVE-2026-2256

A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating…

Mitigation only
Fix from $1,600 2026-03-02
N300rh Firmware CRITICAL 9.8
CVE-2026-3301

A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file …

Mitigation only
Fix from $2,300 2026-02-27
Aria Operations HIGH 8.1
CVE-2026-22719 KEVEPSS 17%

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary comm…

Fix: 5.2.3 / 8.18.6+
Fix from $1,950 2026-02-25
Cumulus Linux HIGH 8.8
CVE-2025-33181

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successfu…

Fix: 5.9.4 / 5.11.4+
Fix from $1,950 2026-02-24
Cumulus Linux HIGH 8.8
CVE-2025-33180

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successfu…

Fix: 5.9.4 / 5.11.4+
Fix from $1,950 2026-02-24
Tip 635g Firmware HIGH 8.8
CVE-2026-3101EPSS 6%

A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code of the component Ping Handler. The manipulation res…

No fix yet
Fix from $1,950 2026-02-24
Exiftool HIGH 8.8
CVE-2026-3102

A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm…

Fix: 13.50+
Fix from $1,950 2026-02-24
Hummerrisk HIGH 8.8
CVE-2026-3066EPSS 12%

A flaw has been found in HummerRisk up to 1.5.0. This vulnerability affects the function fixedCommand of the file hummer-common/hummer-common-core/sr…

Fix: after 1.5.0
Fix from $1,950 2026-02-24
Hummerrisk HIGH 8.8
CVE-2026-3064EPSS 19%

A security vulnerability has been detected in HummerRisk up to 1.5.0. Affected by this issue is some unknown functionality of the file ResourceCreate…

Fix: after 1.5.0
Fix from $1,950 2026-02-24
Hummerrisk HIGH 8.8
CVE-2026-3065EPSS 30%

A vulnerability was detected in HummerRisk up to 1.5.0. This affects the function CommandUtils.commonExecCmdWithResult of the file CloudTaskService.j…

Fix: after 1.5.0
Fix from $1,950 2026-02-24
Vigor300b Firmware HIGH 7.2
CVE-2026-3040EPSS 9%

A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/upload…

Fix: after 1.5.1.6
Fix from $1,950 2026-02-23
Dst Admin HIGH 8.8
CVE-2026-2956EPSS 8%

A security flaw has been discovered in qinming99 dst-admin up to 1.5.0. This affects the function revertBackup of the file /home/restore. The manipul…

Fix: after 1.5.0
Fix from $1,950 2026-02-22
Vaelsys CRITICAL 9.8
CVE-2026-2952EPSS 7%

A flaw has been found in Vaelsys 4.1.0. This vulnerability affects unknown code of the file /tree/tree_server.php of the component HTTP POST Request …

Mitigation only
Fix from $2,300 2026-02-22
Online Store Management System CRITICAL 9.8
CVE-2026-2944EPSS 6%

A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function system of the file …

Mitigation only
Fix from $2,300 2026-02-22
Opds Talon CRITICAL 9.8
CVE-2026-2333

Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted networ…

Mitigation only
Fix from $2,300 2026-02-20
Opds Talon CRITICAL 9.8
CVE-2026-26093

Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted networ…

Mitigation only
Fix from $2,300 2026-02-20
520 Firmware HIGH 7.2
CVE-2026-2846EPSS 10%

A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the file /goform/formPdbUpConfig of…

No fix yet
Fix from $1,950 2026-02-20
520 Firmware HIGH 7.2
CVE-2026-2847EPSS 9%

A vulnerability was detected in UTT HiPER 520 1.7.7-160105. Affected is the function sub_44EFB4 of the file /goform/formReleaseConnect of the compone…

No fix yet
Fix from $1,950 2026-02-20
Unclassified HIGH 8.1
CVE-2026-20761

A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management mess…

Mitigation only
Fix from $1,950 2026-02-20
Cf E7 Firmware HIGH 8.8
CVE-2026-2824EPSS 15%

A flaw has been found in Comfast CF-E7 2.6.0.9. This affects the function sub_441CF4 of the file /cgi-bin/mbox-config?method=SET&section=ping_config …

No fix yet
Fix from $1,950 2026-02-20
Cf E7 Firmware HIGH 8.8
CVE-2026-2823EPSS 17%

A vulnerability was detected in Comfast CF-E7 2.6.0.9. The impacted element is the function sub_41ACCC of the file /cgi-bin/mbox-config?method=SET&se…

No fix yet
Fix from $1,950 2026-02-20
Openclaw HIGH 7.8
CVE-2026-27001

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (workspace path) into the agent syst…

Fix: 2026.2.15+
Fix from $1,950 2026-02-20
Unclassified CRITICAL 9.8
CVE-2026-2686

A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file /cgi-bin/session_login.cgi. …

Mitigation only
Fix from $2,300 2026-02-19
Unclassified HIGH 7.2
CVE-2026-2670EPSS 16%

A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply o…

Mitigation only
Fix from $1,950 2026-02-18