Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Reolink MEDIUM 6.5
CVE-2025-56799

Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. N…

No fix yet
Fix from $1,600 2025-10-21
Unclassified MEDIUM 6.1
CVE-2025-57521

Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The application loa…

Mitigation only
Fix from $1,600 2025-10-21
Manageengine Admanager Plus HIGH 8.8
CVE-2025-10020

Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script compone…

Fix: 8.0+
Fix from $1,950 2025-10-21
Unclassified MEDIUM 6.9
CVE-2025-62696

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Foundation Mediawiki Foundation - …

Mitigation only
Fix from $1,600 2025-10-21
Flowise MEDIUM 6.5
CVE-2025-57164

Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.

No fix yet
Fix from $1,600 2025-10-17
Unclassified MEDIUM 5.1
CVE-2025-60855

Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious f…

Mitigation only
Fix from $1,600 2025-10-16
Unclassified MEDIUM 6.5
CVE-2025-61514

An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploading a craft…

Patch available
Fix from $1,600 2025-10-16
Meeting Software Development Kit MEDIUM 6.5
CVE-2025-58132

Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.

Fix: 6.3.15 / 6.4.13+
Fix from $1,600 2025-10-15
Flowise CRITICAL 9.9
CVE-2025-34267EPSS 6%

Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node …

Fix: 3.0.8+
Fix from $2,300 2025-10-14
Unclassified HIGH 7.2
CVE-2025-37146

A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to …

Mitigation only
Fix from $1,950 2025-10-14
Arubaos HIGH 7.2
CVE-2025-37134

An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful expl…

Fix: 8.10.0.19 / 8.12.0.6+
Fix from $1,950 2025-10-14
Arubaos MEDIUM 6.2
CVE-2025-37138

An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor op…

Fix: 8.10.0.19 / 8.12.0.6+
Fix from $1,600 2025-10-14
Arubaos HIGH 7.2
CVE-2025-37133

An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful expl…

Fix: 8.10.0.19 / 8.12.0.6+
Fix from $1,950 2025-10-14
Dap 2695 Firmware CRITICAL 9.8
CVE-2025-11665EPSS 7%

A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Updat…

Mitigation only
Fix from $2,300 2025-10-13
Mcms MEDIUM 6.5
CVE-2025-60838

An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.

Fix: after 6.0.1
Fix from $1,600 2025-10-10
Jeewms MEDIUM 6.5
CVE-2025-60268

An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/c…

No fix yet
Fix from $1,600 2025-10-10
365 Copilot Chat CRITICAL 9.3
CVE-2025-59286

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio…

Mitigation only
Fix from $2,300 2025-10-09
365 Word Copilot CRITICAL 9.3
CVE-2025-59252

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio…

Mitigation only
Fix from $2,300 2025-10-09
365 Copilot Chat CRITICAL 9.3
CVE-2025-59272

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information…

Mitigation only
Fix from $2,300 2025-10-09
Bagisto MEDIUM 6.5
CVE-2025-56426

An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calcul…

No fix yet
Fix from $1,600 2025-10-09
Ac7 Firmware HIGH 8.8
CVE-2025-11523

A vulnerability was detected in Tenda AC7 15.03.06.44. This vulnerability affects unknown code of the file /goform/AdvSetLanip. The manipulation of t…

No fix yet
Fix from $1,950 2025-10-09
Desktopcommandermcp CRITICAL 9.8
CVE-2025-11491

A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/comma…

Fix: after 0.2.13
Fix from $2,300 2025-10-08
Desktopcommandermcp CRITICAL 9.8
CVE-2025-11490

A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file …

Fix: after 0.2.13
Fix from $2,300 2025-10-08
Unclassified HIGH 7.3
CVE-2025-11488

A weakness has been identified in D-Link DIR-852 up to 20251002. This affects an unknown part of the file /HNAP1/. Executing manipulation can lead to…

Mitigation only
Fix from $1,950 2025-10-08
Deno HIGH 8.1
CVE-2025-61787

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Win…

Fix: 2.5.3+
Fix from $1,950 2025-10-08
Di 7001mini 8g Firmware CRITICAL 9.8
CVE-2025-11407

A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of the file /upgrade_filter.asp. This manipulation …

Mitigation only
Fix from $2,300 2025-10-07
Di 7100g C1 Firmware HIGH 7.2
CVE-2025-11335

A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected by this vulnerability is the function sub_46409C of the file /msp_info.…

Mitigation only
Fix from $1,950 2025-10-06
Ideacms HIGH 7.2
CVE-2025-11331EPSS 17%

A vulnerability was found in IdeaCMS up to 1.8. The impacted element is an unknown function of the file app/common/logic/admin/Config.php of the comp…

Fix: after 1.8
Fix from $1,950 2025-10-06
F9k1015 Firmware HIGH 8.8
CVE-2025-11303EPSS 7%

A vulnerability was detected in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/mp. Performing a manipulation of the argu…

No fix yet
Fix from $1,950 2025-10-05
F9k1015 Firmware HIGH 8.8
CVE-2025-11298EPSS 7%

A vulnerability was determined in Belkin F9K1015 1.00.10. Impacted is an unknown function of the file /goform/formSetWanStatic. Executing a manipulat…

No fix yet
Fix from $1,950 2025-10-05