Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Digital Employee Experience HIGH 7.2
CVE-2025-64991

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior…

Fix: 15.0+
Fix from $1,950 2025-12-11
Digital Employee Experience HIGH 7.2
CVE-2025-64992

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction p…

Fix: 25.0+
Fix from $1,950 2025-12-11
Digital Employee Experience HIGH 7.2
CVE-2025-64993

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instruction…

Fix: 29.0+
Fix from $1,950 2025-12-11
Digital Employee Experience HIGH 7.2
CVE-2025-64986

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningO…

Fix: 21.0+
Fix from $1,950 2025-12-11
Digital Employee Experience HIGH 7.2
CVE-2025-64987

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC in…

Fix: 21.0+
Fix from $1,950 2025-12-11
Digital Employee Experience HIGH 7.2
CVE-2025-64988

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instructio…

Fix: 19.2+
Fix from $1,950 2025-12-11
Unclassified MEDIUM 5.0
CVE-2025-14485

A weakness has been identified in EFM ipTIME A3004T 14.19.0. This vulnerability affects the function show_debug_screen of the file /sess-bin/timepro.…

Mitigation only
Fix from $1,600 2025-12-11
Cybersecurity Ai CRITICAL 9.6
CVE-2025-67511

Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below…

Fix: after 0.5.9
Fix from $2,300 2025-12-11
Hub M2 Firmware HIGH 7.3
CVE-2025-65292

Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to…

No fix yet
Fix from $1,950 2025-12-10
Camera Hub G3 Firmware MEDIUM 6.6
CVE-2025-65293

Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malici…

No fix yet
Fix from $1,600 2025-12-10
Github Copilot HIGH 7.8
CVE-2025-64671

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locall…

Fix: 1.5.60-243+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-54100

Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute …

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Simatic Cn 4100 Firmware HIGH 8.8
CVE-2025-40937

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in…

Fix: 4.0.1+
Fix from $1,950 2025-12-09
Ruggedcom Rox Ii Firmware HIGH 8.8
CVE-2024-56836

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX …

Fix: 2.17.0+
Fix from $1,950 2025-12-09
Ruggedcom Rox Ii Firmware HIGH 7.2
CVE-2024-56837

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX …

Fix: 2.17.0+
Fix from $1,950 2025-12-09
Unclassified MEDIUM 5.6
CVE-2025-14276

A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden. Impacted is an unknown function of the file /ajax/php/leaf_search.php. Thi…

Mitigation only
Fix from $1,600 2025-12-08
Rg Ap720 L Firmware HIGH 7.2
CVE-2025-65363EPSS 7%

Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as ro…

Fix: after 11.1
Fix from $1,950 2025-12-08
Dcs 930l Firmware HIGH 8.8
CVE-2025-14225EPSS 9%

A vulnerability was determined in D-Link DCS-930L 1.15.04. This affects an unknown part of the file /setSystemAdmin of the component alphapd. Executi…

No fix yet
Fix from $1,950 2025-12-08
Dir 823x Firmware MEDIUM 6.3
CVE-2025-14208

A security flaw has been discovered in D-Link DIR-823X up to 20250416. This affects the function sub_415028 of the file /goform/set_wan_settings. The…

No fix yet
Fix from $1,600 2025-12-08
Unclassified MEDIUM 6.3
CVE-2025-14204

A vulnerability has been found in TykoDev cherry-studio-TykoFork 0.1. This issue affects the function redirectToAuthorization of the file /.well-know…

Mitigation only
Fix from $1,600 2025-12-07
Unclassified HIGH 7.2
CVE-2025-14188

A security vulnerability has been detected in UGREEN DH2100+ up to 5.3.0.251125. This impacts the function handler_file_backup_create of the file /v1…

Mitigation only
Fix from $1,950 2025-12-07
Unclassified MEDIUM 6.3
CVE-2025-14184

A vulnerability was determined in SGAI Space1 NAS N1211DS up to 1.0.915. Impacted is the function RENAME_FILE/OPERATE_FILE/NGNIX_UPLOAD of the file /…

Mitigation only
Fix from $1,600 2025-12-07
Q2c Nas Firmware HIGH 8.8
CVE-2025-14107EPSS 12%

A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this vulnerability is the function zfilev2_api.SafeStatus of the…

Fix: after 1.1.0210050
Fix from $1,950 2025-12-05
Q2c Nas Firmware HIGH 8.8
CVE-2025-14108EPSS 10%

A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.OpenSafe of the file /v2/file/…

Fix: after 1.1.0210050
Fix from $1,950 2025-12-05
Q2c Nas Firmware HIGH 8.8
CVE-2025-14106EPSS 12%

A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of the file /v2/file/safe/close of…

Fix: after 1.1.0210050
Fix from $1,950 2025-12-05
Br 6478ac V3 Firmware CRITICAL 9.8
CVE-2025-14093EPSS 20%

A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The …

Mitigation only
Fix from $2,300 2025-12-05
Br 6478ac V3 Firmware CRITICAL 9.8
CVE-2025-14094EPSS 21%

A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulatio…

Mitigation only
Fix from $2,300 2025-12-05
X210 Firmware MEDIUM 5.1
CVE-2025-64052

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arbitrary system commands.

No fix yet
Fix from $1,600 2025-12-05
Br 6478ac V3 Firmware HIGH 7.2
CVE-2025-14092EPSS 17%

A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the function sub_416898 of the file /boafrm/formDebugDia…

No fix yet
Fix from $1,950 2025-12-05
Unclassified MEDIUM 6.3
CVE-2025-1910

The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to N…

Mitigation only
Fix from $1,600 2025-12-04