Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Dir 878 Firmware MEDIUM 6.5
CVE-2025-60676

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetN…

No fix yet
Fix from $1,600 2025-11-13
Group Office HIGH 8.8
CVE-2025-63406

An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and…

Fix: 6.8.136 / 25.0.47+
Fix from $1,950 2025-11-13
Dir 882 Firmware MEDIUM 6.5
CVE-2025-60700

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The …

No fix yet
Fix from $1,600 2025-11-13
Dir 882 Firmware MEDIUM 6.5
CVE-2025-60701

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_43…

No fix yet
Fix from $1,600 2025-11-13
Dir 882 Firmware HIGH 7.3
CVE-2025-60697

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_44…

No fix yet
Fix from $1,950 2025-11-13
Dir 882 Firmware HIGH 7.3
CVE-2025-60698

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_43…

No fix yet
Fix from $1,950 2025-11-13
Dir 823g Firmware MEDIUM 5.4
CVE-2025-60671

A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binarie…

No fix yet
Fix from $1,600 2025-11-13
A720r Firmware MEDIUM 6.5
CVE-2025-60682

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifical…

No fix yet
Fix from $1,600 2025-11-13
A720r Firmware MEDIUM 6.5
CVE-2025-60683

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specifically in the …

No fix yet
Fix from $1,600 2025-11-13
Lr1200gb Firmware MEDIUM 6.5
CVE-2025-60687EPSS 7%

An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130 within the cstecgi.cgi bina…

No fix yet
Fix from $1,600 2025-11-13
E1200 Firmware MEDIUM 5.4
CVE-2025-60689EPSS 8%

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v…

No fix yet
Fix from $1,600 2025-11-13
Smartfabric Os10 HIGH 8.8
CVE-2025-46427

Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Inject…

Fix: 10.6.1.0+
Fix from $1,950 2025-11-12
Smartfabric Os10 HIGH 8.8
CVE-2025-46428

Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injec…

Fix: 10.6.1.0+
Fix from $1,950 2025-11-12
Github Copilot Chat HIGH 8.8
CVE-2025-62222

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthoriz…

Fix: 0.32.5+
Fix from $1,950 2025-11-11
Visual Studio 2022 MEDIUM 6.7
CVE-2025-62214

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code lo…

Fix: 17.14.17+
Fix from $1,600 2025-11-11
Outpost Security Suite HIGH 7.7
CVE-2024-57695

An issue in Agnitum Outpost Security Suite 7.5.3 (3942.608.1810) and 7.6 (3984.693.1842) allows a local attacker to execute arbitrary code via the lo…

No fix yet
Fix from $1,950 2025-11-11
Unclassified HIGH 8.8
CVE-2025-9223

Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the impro…

Mitigation only
Fix from $1,950 2025-11-11
Kerui K259 Firmware MEDIUM 6.5
CVE-2025-63296

KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: during startup…

No fix yet
Fix from $1,600 2025-11-10
Unclassified HIGH 7.1
CVE-2025-12155

A Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows an attacker with Developer p…

Mitigation only
Fix from $1,950 2025-11-10
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2025-12916EPSS 5%

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort…

Fix: 3.0.11+
Fix from $2,300 2025-11-09
Cloudlink MEDIUM 6.7
CVE-2025-46365

Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command …

Fix: 8.1.1+
Fix from $1,600 2025-11-05
Netsurf MEDIUM 6.5
CVE-2024-51317

An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function

No fix yet
Fix from $1,600 2025-11-03
Unclassified HIGH 7.5
CVE-2025-61141

sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes the EDITOR environment variab…

Mitigation only
Fix from $1,950 2025-10-30
Unclassified HIGH 8.2
CVE-2025-60595

SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution.

No fix yet
Fix from $1,950 2025-10-29
Unclassified MEDIUM 6.3
CVE-2025-1549

A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands…

Mitigation only
Fix from $1,600 2025-10-29
Di 7001mini 8g Firmware CRITICAL 9.8
CVE-2025-12313

A vulnerability has been found in D-Link DI-7001 MINI 19.09.19A1/24.04.18B1. The affected element is an unknown function of the file /msp_info.htm. S…

Mitigation only
Fix from $2,300 2025-10-27
Dap 2695 Firmware CRITICAL 9.8
CVE-2025-12296EPSS 7%

A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 of the component Firmware Upd…

Mitigation only
Fix from $2,300 2025-10-27
Jsherp HIGH 8.2
CVE-2025-60801

jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.

Fix: 2025-08-14+
Fix from $1,950 2025-10-24
Unclassified CRITICAL 9.9
CVE-2025-58428

The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remot…

Mitigation only
Fix from $2,300 2025-10-23
Socet Gxp HIGH 8.4
CVE-2025-54964

An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary execu…

Fix: 4.6.0.2+
Fix from $1,950 2025-10-23