Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Mcp Server Kubernetes HIGH 8.8
CVE-2025-66404

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in th…

Fix: 2.9.8+
Fix from $1,950 2025-12-03
Claude Code CRITICAL 9.8
CVE-2025-66032

Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible …

Fix: 1.0.93+
Fix from $2,300 2025-12-03
Dgm1104 Firmware HIGH 8.8
CVE-2025-57201EPSS 17%

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB…

No fix yet
Fix from $1,950 2025-12-03
Dgm1104 Firmware HIGH 8.8
CVE-2025-57198

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Mac…

No fix yet
Fix from $1,950 2025-12-03
Dgm1104 Firmware HIGH 8.8
CVE-2025-57199

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Net…

No fix yet
Fix from $1,950 2025-12-03
Dgm1104 Firmware MEDIUM 6.5
CVE-2025-57200

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the tes…

No fix yet
Fix from $1,600 2025-12-03
Feehicms MEDIUM 6.5
CVE-2025-65657

FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote …

No fix yet
Fix from $1,600 2025-12-02
Cacti HIGH 8.8
CVE-2025-66399EPSS 11%

Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configurati…

Fix: 1.2.29+
Fix from $1,950 2025-12-02
R15 Firmware CRITICAL 9.8
CVE-2025-60854

A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in…

Fix: after 1.20.01
Fix from $2,300 2025-12-02
B Qe2w401 Firmware CRITICAL 9.8
CVE-2025-13800EPSS 10%

A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the file /send_order.cgi. The ma…

Fix: after 250814-r037c
Fix from $2,300 2025-12-01
B Qe2w401 Firmware CRITICAL 9.8
CVE-2025-13797EPSS 7%

A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifimac of the file /send_order.cg…

Fix: after 250814-r037c
Fix from $2,300 2025-12-01
B Qe2w401 Firmware CRITICAL 9.8
CVE-2025-13798EPSS 7%

A flaw has been found in ADSLR NBR1005GPEV2 250814-r037c. This affects the function ap_macfilter_add of the file /send_order.cgi. Executing manipulat…

Fix: after 250814-r037c
Fix from $2,300 2025-12-01
B Qe2w401 Firmware CRITICAL 9.8
CVE-2025-13799EPSS 10%

A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_del of the file /send_order.c…

Fix: after 250814-r037c
Fix from $2,300 2025-12-01
Willitmerge CRITICAL 9.8
CVE-2025-66219

willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability i…

Fix: after 0.2.1
Fix from $2,300 2025-11-29
A31c Firmware MEDIUM 6.8
CVE-2025-63674

An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootlo…

No fix yet
Fix from $1,600 2025-11-24
Unclassified HIGH 8.5
CVE-2025-11921

iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue a…

Mitigation only
Fix from $1,950 2025-11-24
Dir 852 Firmware CRITICAL 9.8
CVE-2025-13562EPSS 6%

A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi. Such manipulation of the arg…

Mitigation only
Fix from $2,300 2025-11-23
Roo Code HIGH 8.1
CVE-2025-65946

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possibl…

Fix: 3.26.7+
Fix from $1,950 2025-11-21
750w Firmware CRITICAL 9.8
CVE-2025-13442EPSS 20%

A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the function system of the file /go…

Fix: after 3.2.2-191225
Fix from $2,300 2025-11-20
Arubaos HIGH 8.8
CVE-2025-37162

A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack.…

Fix: 10.7.2.0+
Fix from $1,950 2025-11-18
Pnetlab MEDIUM 6.5
CVE-2025-63749

pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter.

No fix yet
Fix from $1,600 2025-11-18
Airwave HIGH 7.2
CVE-2025-37163

A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated at…

Fix: 8.3.0.5+
Fix from $1,950 2025-11-18
Unclassified MEDIUM 6.5
CVE-2025-63258

A remote command execution (RCE) vulnerability was discovered in all H3C ERG3/ERG5 series routers and XiaoBei series routers, cloud gateways, and wir…

Mitigation only
Fix from $1,600 2025-11-18
Aws Resources Mcp Server MEDIUM 6.5
CVE-2025-63604

A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code execution through insufficient input…

No fix yet
Fix from $1,600 2025-11-18
Mcp Server For Data Exploration MEDIUM 6.5
CVE-2025-63603

A command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) 0.1.6 in the safe_eval() func…

No fix yet
Fix from $1,600 2025-11-18
Dwr M920 Firmware HIGH 8.8
CVE-2025-13306EPSS 8%

A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /bo…

No fix yet
Fix from $1,950 2025-11-18
A950rg Firmware MEDIUM 6.5
CVE-2025-60702

A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The `setDiagn…

No fix yet
Fix from $1,600 2025-11-13
Dir 878 Firmware MEDIUM 6.5
CVE-2025-60672

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetD…

No fix yet
Fix from $1,600 2025-11-13
Dir 878 Firmware MEDIUM 6.5
CVE-2025-60673

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetD…

No fix yet
Fix from $1,600 2025-11-13
Dir 823g Firmware MEDIUM 5.4
CVE-2025-60675

A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binarie…

No fix yet
Fix from $1,600 2025-11-13