Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Dir 823x Firmware HIGH 7.2
CVE-2026-2063

A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/set_ac_server of the compo…

No fix yet
Fix from $1,950 2026-02-06
Dir 823x Firmware HIGH 7.2
CVE-2026-2061

A vulnerability was determined in D-Link DIR-823X 250416. Affected by this issue is the function sub_424D20 of the file /goform/set_ipv6. Executing a…

No fix yet
Fix from $1,950 2026-02-06
Dcme 320 Firmware HIGH 7.2
CVE-2026-2000EPSS 17%

A vulnerability was found in DCN DCME-320 up to 20260121. Impacted is the function apply_config of the file /function/system/basic/bridge_cfg.php of …

Fix: after 20260121
Fix from $1,950 2026-02-06
Tcis 3 Firmware CRITICAL 9.8
CVE-2025-59818

This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.

Fix: 9.2.3.3+
Fix from $2,300 2026-02-04
Unclassified HIGH 7.3
CVE-2026-1802

A security flaw has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function macAddrClone of the file luci\controller\api\zrMac…

Mitigation only
Fix from $1,950 2026-02-03
Unclassified HIGH 8.1
CVE-2025-24293

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transfo…

Mitigation only
Fix from $1,950 2026-01-30
Hg10 Firmware HIGH 7.3
CVE-2026-1689

A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function checkUserFromLanOrWan of the fil…

No fix yet
Fix from $1,950 2026-01-30
Hg10 Firmware HIGH 7.3
CVE-2026-1687

A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. Impacted is an unknown function of the file /boaform/formSamba of t…

No fix yet
Fix from $1,950 2026-01-30
Unclassified HIGH 7.2
CVE-2026-22623

Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can execute arbitrary commands o…

Mitigation only
Fix from $1,950 2026-01-30
Unclassified CRITICAL 9.5
CVE-2025-26385

Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability…

Mitigation only
Fix from $2,300 2026-01-30
Ac21 Firmware HIGH 8.8
CVE-2026-1638

A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZSetCfg of the file /goform/mD…

Mitigation only
Fix from $1,950 2026-01-30
Inspektor Gadget HIGH 7.8
CVE-2026-24905

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig…

Fix: 0.48.1+
Fix from $1,950 2026-01-29
Dwr M961 Firmware HIGH 8.8
CVE-2026-1625

A vulnerability was detected in D-Link DWR-M961 1.1.47. The impacted element is the function sub_4250E0 of the file /boafrm/formSmsManage of the comp…

Mitigation only
Fix from $1,950 2026-01-29
Dwr M961 Firmware HIGH 8.8
CVE-2026-1624

A security vulnerability has been detected in D-Link DWR-M961 1.1.47. The affected element is an unknown function of the file /boafrm/formLtefotaUpgr…

Mitigation only
Fix from $1,950 2026-01-29
A7000r Firmware MEDIUM 6.3
CVE-2026-1623

A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulati…

No fix yet
Fix from $1,600 2026-01-29
A7000r Firmware MEDIUM 6.3
CVE-2026-1601

A weakness has been identified in Totolink A7000R 4.1cu.4154. The impacted element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi…

No fix yet
Fix from $1,600 2026-01-29
Dwr M961 Firmware HIGH 8.8
CVE-2026-1596

A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. Th…

Mitigation only
Fix from $1,950 2026-01-29
A7000r Firmware HIGH 8.8
CVE-2026-1548

A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. This man…

No fix yet
Fix from $1,950 2026-01-28
Dir 823x Firmware HIGH 8.8
CVE-2026-1544

A security flaw has been discovered in D-Link DIR-823X 250416. Impacted is the function sub_41E2A0 of the file /goform/set_mode. Performing a manipul…

No fix yet
Fix from $1,950 2026-01-28
A7000r Firmware CRITICAL 9.8
CVE-2026-1547

A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipul…

Mitigation only
Fix from $2,300 2026-01-28
Rbr20 Firmware HIGH 7.7
CVE-2022-40619

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devi…

Fix: 1.0.5.42 / 1.0.11.134+
Fix from $1,950 2026-01-28
Openproject HIGH 8.8
CVE-2026-24685

OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability …

Fix: 16.6.6 / 17.0.2+
Fix from $1,950 2026-01-28
Dir 615 Firmware HIGH 7.2
CVE-2026-1506EPSS 5%

A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php of the component MAC Filter Co…

No fix yet
Fix from $1,950 2026-01-28
Dir 615 Firmware HIGH 7.2
CVE-2026-1505

A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes.php of the component URL Fil…

No fix yet
Fix from $1,950 2026-01-28
Dir 615 Firmware HIGH 7.2
CVE-2026-1448EPSS 5%

A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component We…

Fix: after 4.10
Fix from $1,950 2026-01-27
Archer Mr600 Firmware HIGH 8.8
CVE-2025-14756

Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to e…

Fix: 1.1.0+
Fix from $1,950 2026-01-26
Continuum CRITICAL 9.9
CVE-2016-15057

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum…

Mitigation only
Fix from $2,300 2026-01-26
Dcs 700l Firmware HIGH 7.2
CVE-2026-1419EPSS 15%

A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode of the component Web Form Hand…

No fix yet
Fix from $1,950 2026-01-26
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2026-1414

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This impacts the function getInformation…

Fix: after 3.0.12
Fix from $2,300 2026-01-26
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2026-1413

A vulnerability was found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function portValidate of the…

Fix: after 3.0.12
Fix from $2,300 2026-01-26