Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Br 6208ac Firmware CRITICAL 9.8
CVE-2025-70161EPSS 24%

EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the …

Mitigation only
Fix from $2,300 2026-01-09
Tcis 3 Firmware HIGH 8.8
CVE-2025-64090

This vulnerability allows authenticated attackers to execute commands via the hostname of the device.

Fix: 9.2.3.3+
Fix from $1,950 2026-01-09
Icx500 Firmware CRITICAL 9.8
CVE-2025-64093

Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.

Fix: 1.4.3.3+
Fix from $2,300 2026-01-09
Di 8200g Firmware CRITICAL 9.8
CVE-2026-0732EPSS 10%

A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the ar…

Mitigation only
Fix from $2,300 2026-01-09
Ubb Xg Firmware HIGH 8.8
CVE-2026-21638

A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code exec…

Fix: 1.2.3 / 1.4.2+
Fix from $1,950 2026-01-08
Airmax Ac Firmware HIGH 8.8
CVE-2026-21639

A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code exec…

Fix: 1.2.3 / 2.6.8+
Fix from $1,950 2026-01-08
Veeam Backup \& Replication CRITICAL 9.1
CVE-2025-59468

This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password paramet…

Fix: 13.0.1.1071+
Fix from $2,300 2026-01-08
Veeam Backup \& Replication CRITICAL 9.0
CVE-2025-59470

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order para…

Fix: 13.0.1.1071+
Fix from $2,300 2026-01-08
Veeam Backup \& Replication CRITICAL 9.8
CVE-2025-55125

This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.

Fix: 13.0.1.1071+
Fix from $2,300 2026-01-08
Enaio CRITICAL 9.1
CVE-2025-56425

An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.18…

Fix: 10.10.0.183 / 11.0.0.183+
Fix from $2,300 2026-01-08
Gl Axt1800 Firmware HIGH 8.1
CVE-2025-67089

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_packa…

No fix yet
Fix from $1,950 2026-01-08
Terminal Controller Mcp CRITICAL 10.0
CVE-2025-61492

A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via…

Mitigation only
Fix from $2,300 2026-01-07
Mcp Shell MEDIUM 6.5
CVE-2025-61489

A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplyin…

No fix yet
Fix from $1,600 2026-01-07
Tew 811dru Firmware HIGH 7.2
CVE-2025-15472EPSS 20%

A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL  of the file uapply.cgi of the component httpd . This ma…

No fix yet
Fix from $1,950 2026-01-07
Tew 713re Firmware CRITICAL 9.8
CVE-2025-15471EPSS 12%

A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation…

Mitigation only
Fix from $2,300 2026-01-07
Wa300 Firmware HIGH 8.8
CVE-2026-0641

A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cst…

No fix yet
Fix from $1,950 2026-01-06
Coolify HIGH 8.8
CVE-2025-64424

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-be…

Fix: 4.0.0+
Fix from $1,950 2026-01-05
Coolify HIGH 8.8
CVE-2025-64419

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters comin…

Fix: 4.0.0+
Fix from $1,950 2026-01-05
Passy CRITICAL 9.1
CVE-2025-67397

An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP request using a specific payload in…

Mitigation only
Fix from $2,300 2026-01-05
Ac1206 Firmware CRITICAL 9.8
CVE-2026-0581EPSS 9%

A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorMa…

Mitigation only
Fix from $2,300 2026-01-05
Dir 806a Firmware CRITICAL 9.8
CVE-2025-15391

A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP Request Handler. This manipul…

Mitigation only
Fix from $2,300 2025-12-31
Di 7400g\+ Firmware CRITICAL 9.8
CVE-2025-15357

A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?flag=cmd. The manipulation of th…

Mitigation only
Fix from $2,300 2025-12-30
Serverless HIGH 7.5
CVE-2025-69256

The Serverless Framework is a framework for using AWS Lambda and other managed cloud services to build applications. Starting in version 4.29.0 and p…

Fix: 4.29.3+
Fix from $1,950 2025-12-30
Br 6208ac Firmware CRITICAL 9.8
CVE-2025-15257

A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formR…

Mitigation only
Fix from $2,300 2025-12-30
Br 6208ac Firmware CRITICAL 9.8
CVE-2025-15256

A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /goform/formStaDrvSetup of the com…

Mitigation only
Fix from $2,300 2025-12-30
W6 S Firmware HIGH 8.8
CVE-2025-15254

A vulnerability was found in Tenda W6-S 1.0.0.4(510). This affects the function TendaAte of the file /goform/ate of the component ATE Service. Perfor…

No fix yet
Fix from $1,950 2025-12-30
Tugtainer CRITICAL 9.8
CVE-2025-69201

Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtai…

Fix: 1.15.1+
Fix from $2,300 2025-12-29
Dwr M920 Firmware HIGH 8.8
CVE-2025-15192

A security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_415328 of the file /boafrm/formL…

Fix: after 1.1.50
Fix from $1,950 2025-12-29
Dwr M920 Firmware HIGH 8.8
CVE-2025-15191

A weakness has been identified in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_4155B4 of the file /boafrm/formLtefotaUpgrad…

Fix: after 1.1.50
Fix from $1,950 2025-12-29
Tew 822dre Firmware HIGH 8.8
CVE-2025-15139EPSS 12%

A vulnerability has been found in TRENDnet TEW-822DRE 1.00B21/1.01B06. This affects the function sub_43ACF4  of the file /boafrm/formWsc. Such manipu…

No fix yet
Fix from $1,950 2025-12-28