Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
F9k1015 Firmware HIGH 8.8
CVE-2025-11292EPSS 7%

A weakness has been identified in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/formBSSetSitesurvey. Executing a manipu…

No fix yet
Fix from $1,950 2025-10-05
Mcphub HIGH 8.8
CVE-2025-11285EPSS 8%

A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the file src/controllers/serverC…

Fix: after 0.9.10
Fix from $1,950 2025-10-05
E Tms CRITICAL 9.8
CVE-2025-59741

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
E Tms CRITICAL 9.8
CVE-2025-59735

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
E Tms CRITICAL 9.8
CVE-2025-59736

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
E Tms CRITICAL 9.8
CVE-2025-59737

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
E Tms CRITICAL 9.8
CVE-2025-59738

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
E Tms CRITICAL 9.8
CVE-2025-59739

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
E Tms CRITICAL 9.8
CVE-2025-59740

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
Discourse MEDIUM 6.8
CVE-2025-59337

Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be embedded in a backup dump an…

Fix: 3.5.1 / 3.6.0+
Fix from $1,600 2025-10-01
X18 Firmware CRITICAL 9.8
CVE-2025-61044

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentC…

Mitigation only
Fix from $2,300 2025-10-01
X18 Firmware CRITICAL 9.8
CVE-2025-61045

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg fun…

Mitigation only
Fix from $2,300 2025-10-01
Unclassified CRITICAL 9.3
CVE-2025-61584

serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 ha…

Patch available
Fix from $2,300 2025-09-30
Unclassified HIGH 8.5
CVE-2025-41250

VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to…

Mitigation only
Fix from $1,950 2025-09-29
Wenkucms HIGH 8.8
CVE-2025-11138

A vulnerability was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation…

No fix yet
Fix from $1,950 2025-09-29
Ac18 Firmware HIGH 8.8
CVE-2025-11121

A security vulnerability has been detected in Tenda AC18 15.03.05.19. The impacted element is an unknown function of the file /goform/AdvSetLanip. Th…

No fix yet
Fix from $1,950 2025-09-28
Dir 823x Firmware HIGH 8.8
CVE-2025-11100

A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulatio…

No fix yet
Fix from $1,950 2025-09-28
Dir 823x Firmware HIGH 8.8
CVE-2025-11098

A vulnerability was found in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_wifi_blacklists. The manipul…

No fix yet
Fix from $1,950 2025-09-28
Dir 823x Firmware HIGH 8.8
CVE-2025-11099

A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_del of the file /goform/delete_prohibiting. This m…

No fix yet
Fix from $1,950 2025-09-28
Dir 823x Firmware HIGH 8.8
CVE-2025-11097

A vulnerability has been found in D-Link DIR-823X 250416. Impacted is an unknown function of the file /goform/set_device_name. The manipulation of th…

No fix yet
Fix from $1,950 2025-09-28
Dir 823x Firmware HIGH 8.8
CVE-2025-11096

A flaw has been found in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/diag_traceroute. Executing manipulati…

No fix yet
Fix from $1,950 2025-09-28
Dir 823x Firmware HIGH 8.8
CVE-2025-11095

A vulnerability was detected in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/delete_offline_device. Performing…

No fix yet
Fix from $1,950 2025-09-28
Dir 823x Firmware HIGH 8.8
CVE-2025-11092

A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_switch_settings. …

No fix yet
Fix from $1,950 2025-09-28
Unclassified HIGH 7.3
CVE-2025-11045

A vulnerability was identified in WAYOS LQ_04, LQ_05, LQ_06, LQ_07 and LQ_09 22.03.17. This affects an unknown function of the file /usb_paswd.asp. T…

Mitigation only
Fix from $1,950 2025-09-26
Dir 823x Firmware HIGH 8.8
CVE-2025-55848

An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parame…

No fix yet
Fix from $1,950 2025-09-26
Hutool MEDIUM 6.5
CVE-2025-56769

An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invoca…

Fix: 5.8.40+
Fix from $1,600 2025-09-25
Unclassified HIGH 8.4
CVE-2025-59815

This vulnerability allows malicious actors to execute arbitrary commands on the underlying system of the Zenitel ICX500 and ICX510 Gateway, granting …

Mitigation only
Fix from $1,950 2025-09-25
Unclassified HIGH 8.4
CVE-2025-59817

This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, success…

Mitigation only
Fix from $1,950 2025-09-25
Wl Nu516u1 Firmware HIGH 8.8
CVE-2025-10964EPSS 7%

A weakness has been identified in Wavlink NU516U1. Affected by this vulnerability is the function sub_401B30 of the file /cgi-bin/firewall.cgi. This …

No fix yet
Fix from $1,950 2025-09-25
Swagger Petstore MEDIUM 6.5
CVE-2025-29157

An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-…

No fix yet
Fix from $1,600 2025-09-25