Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Tew 800mb Firmware HIGH 8.8
CVE-2025-15137EPSS 11%

A vulnerability was detected in TRENDnet TEW-800MB 1.0.1.0. Affected by this vulnerability is the function sub_F934  of the file NTPSyncWithHost.cgi.…

No fix yet
Fix from $1,950 2025-12-28
Tew 800mb Firmware HIGH 8.8
CVE-2025-15136EPSS 10%

A security vulnerability has been detected in TRENDnet TEW-800MB 1.0.1.0. Affected is the function do_setWizard_asp of the file /goform/wizardset of …

No fix yet
Fix from $1,950 2025-12-28
Z4pro\+ Firmware HIGH 8.8
CVE-2025-15133EPSS 7%

A vulnerability was identified in ZSPACE Z4Pro+ 1.0.0440024. The impacted element is the function zfilev2_api_CloseSafe of the file /v2/file/safe/clo…

No fix yet
Fix from $1,950 2025-12-28
Z4pro\+ Firmware HIGH 8.8
CVE-2025-15132EPSS 7%

A vulnerability was determined in ZSPACE Z4Pro+ 1.0.0440024. The affected element is the function zfilev2_api_open of the file /v2/file/safe/open of …

Fix: after 1.0.0440024
Fix from $1,950 2025-12-28
Z4pro\+ Firmware HIGH 8.8
CVE-2025-15131EPSS 7%

A vulnerability was found in ZSPACE Z4Pro+ 1.0.0440024. Impacted is the function zfilev2_api_SafeStatus of the file /v2/file/safe/status of the compo…

Fix: after 1.0.0440024
Fix from $1,950 2025-12-28
Sip T21\(p\)e2 Firmware HIGH 8.8
CVE-2025-66738

An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping func…

No fix yet
Fix from $1,950 2025-12-26
Delight Custom Firmware MEDIUM 5.1
CVE-2025-65885

An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight v6.7), No…

Mitigation only
Fix from $1,600 2025-12-26
Unclassified MEDIUM 6.3
CVE-2025-15081

A vulnerability has been found in JD Cloud BE6500 4.4.1.r4308. This issue affects the function sub_4780 of the file /jdcapi. Such manipulation of the…

Mitigation only
Fix from $1,600 2025-12-25
Wh450 Firmware CRITICAL 9.8
CVE-2025-15048EPSS 12%

A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request…

Mitigation only
Fix from $2,300 2025-12-23
Speedify HIGH 8.4
CVE-2025-25364

A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to execute arbitra…

Fix: after 15.0.0
Fix from $1,950 2025-12-23
E5600 Firmware CRITICAL 9.8
CVE-2025-29228

Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.

Mitigation only
Fix from $2,300 2025-12-23
E5600 Firmware CRITICAL 9.8
CVE-2025-29229

linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

Mitigation only
Fix from $2,300 2025-12-23
Ex8000 Firmware MEDIUM 6.5
CVE-2025-45493

Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.

Mitigation only
Fix from $1,600 2025-12-23
Ex8000 Firmware CRITICAL 9.8
CVE-2025-50526

Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.

Mitigation only
Fix from $2,300 2025-12-23
Pluxml MEDIUM 6.5
CVE-2025-67436

Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell …

No fix yet
Fix from $1,600 2025-12-22
Dir 605 Firmware HIGH 7.2
CVE-2025-14884EPSS 11%

A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the component Firmware Update Servic…

No fix yet
Fix from $1,950 2025-12-18
Zed HIGH 7.3
CVE-2025-68432

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Language Server Protocol (LSP) …

Fix: 0.218.2+
Fix from $1,950 2025-12-17
Zed HIGH 7.3
CVE-2025-68433

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Model Context Protocol (MCP) co…

Fix: 0.218.2+
Fix from $1,950 2025-12-17
Anaconda3 HIGH 7.8
CVE-2024-46060

Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. Duri…

Fix: 2024.06-1+
Fix from $1,950 2025-12-17
Miniconda3 HIGH 7.8
CVE-2024-46062

Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. Dur…

Fix: 23.11.0-1+
Fix from $1,950 2025-12-17
N200re Firmware MEDIUM 6.5
CVE-2025-55893

TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName.

No fix yet
Fix from $1,600 2025-12-15
A3300r Firmware MEDIUM 6.5
CVE-2025-55901

TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_time parameter.

No fix yet
Fix from $1,600 2025-12-15
N3 Firmware CRITICAL 9.8
CVE-2025-14707EPSS 19%

A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the c…

Fix: after 2.0.25
Fix from $2,300 2025-12-15
N3 Firmware CRITICAL 9.8
CVE-2025-14706EPSS 19%

A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/http_eshell_server of the compo…

Fix: after 2.0.25
Fix from $2,300 2025-12-15
N3 Firmware CRITICAL 9.8
CVE-2025-14705EPSS 17%

A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESERVER Feature. This manipulati…

Fix: after 2.0.25
Fix from $2,300 2025-12-15
Dir 868l B1 Firmware CRITICAL 9.8
CVE-2025-14659

A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the component DHCP Daemon. The man…

Fix: after 203b03
Fix from $2,300 2025-12-14
Dedebiz HIGH 7.2
CVE-2025-14648EPSS 7%

A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown functionality of the file /src/admin/…

Fix: after 6.5.9
Fix from $1,950 2025-12-14
X5000r Firmware CRITICAL 9.8
CVE-2025-14586

A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecg…

Mitigation only
Fix from $2,300 2025-12-13
Fireshare CRITICAL 9.8
CVE-2025-67728

Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Publi…

Fix: 1.3.0+
Fix from $2,300 2025-12-12
Gardenctl HIGH 8.4
CVE-2025-67508

gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. When using non‑POSIX shells suc…

Fix: 2.12.0+
Fix from $1,950 2025-12-12