Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Wl Nu516u1 Firmware HIGH 8.8
CVE-2025-10962EPSS 7%

A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This impacts the function sub_403198 of the file /cgi-bin/wireless.cgi of the compon…

No fix yet
Fix from $1,950 2025-09-25
Wl Nu516u1 Firmware HIGH 8.8
CVE-2025-10963EPSS 7%

A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. Affected is the function sub_4016F0 of the file /cgi-bin/firewall.cgi. The mani…

No fix yet
Fix from $1,950 2025-09-25
Swagger Petstore MEDIUM 6.5
CVE-2025-29155

An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint

No fix yet
Fix from $1,600 2025-09-25
Wl Nu516u1 Firmware HIGH 8.8
CVE-2025-10959EPSS 7%

A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. The affected element is the function sub_401778 of the file /cgi-bin/firewall.cgi. S…

No fix yet
Fix from $1,950 2025-09-25
Wl Nu516u1 Firmware HIGH 8.8
CVE-2025-10960EPSS 7%

A vulnerability was found in Wavlink NU516U1 M16U1_V240425. The impacted element is the function sub_402D1C of the file /cgi-bin/wireless.cgi of the …

No fix yet
Fix from $1,950 2025-09-25
Wl Nu516u1 Firmware HIGH 8.0
CVE-2025-10961EPSS 8%

A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. This affects the function sub_4030C0 of the file /cgi-bin/wireless.cgi of the compon…

No fix yet
Fix from $1,950 2025-09-25
Wl Nu516u1 Firmware HIGH 8.8
CVE-2025-10958EPSS 7%

A flaw has been found in Wavlink NU516U1 M16U1_V240425. Impacted is the function sub_403010 of the file /cgi-bin/wireless.cgi of the component AddMac…

No fix yet
Fix from $1,950 2025-09-25
Git Commiters HIGH 8.8
CVE-2025-59831

git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection …

Fix: 0.1.2+
Fix from $1,950 2025-09-25
Adb Mcp Server CRITICAL 9.8
CVE-2025-59834

ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server…

Fix: after 0.1.0
Fix from $2,300 2025-09-25
Unclassified HIGH 8.8
CVE-2025-20334

A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root privi…

Mitigation only
Fix from $1,950 2025-09-24
Pocketvj Control Panel Firmware MEDIUM 6.5
CVE-2025-45326

An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component.

Mitigation only
Fix from $1,600 2025-09-23
Csz Cms MEDIUM 6.5
CVE-2025-29083

SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Plugin_Manager.…

No fix yet
Fix from $1,600 2025-09-23
Dir 823x Firmware HIGH 8.8
CVE-2025-10814EPSS 6%

A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown functionality of the file /usr/s…

No fix yet
Fix from $1,950 2025-09-22
Unclassified HIGH 8.8
CVE-2025-57685

The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, BL-X26_AC8 v1.2.8, and BL-LTE3…

Mitigation only
Fix from $1,950 2025-09-22
Unclassified HIGH 8.8
CVE-2025-43953EPSS 7%

In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or traceroute field on the TCP/IP …

Mitigation only
Fix from $1,950 2025-09-22
Wl Nu516u1 Firmware HIGH 7.2
CVE-2025-10775EPSS 20%

A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/logi…

No fix yet
Fix from $1,950 2025-09-22
Email Security Gateway MEDIUM 6.1
CVE-2025-59689 KEV

Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.…

Fix: 5.0.31 / 5.1.20+
Fix from $1,600 2025-09-19
Ac6 Firmware MEDIUM 6.5
CVE-2025-57296

Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to the /goform…

No fix yet
Fix from $1,600 2025-09-19
Goanywhere Managed File Transfer CRITICAL 9.8
CVE-2025-10035 KEVEPSS 100%

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to…

Fix: 7.6.3 / 7.8.4+
Fix from $2,300 2025-09-18
Cf Xr11 Firmware HIGH 8.8
CVE-2025-57293

A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function in /usr/bi…

No fix yet
Fix from $1,950 2025-09-18
Dir 645 Firmware CRITICAL 9.8
CVE-2025-10689

A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. Such manipulation of the…

Mitigation only
Fix from $2,300 2025-09-18
Clipbucket MEDIUM 6.5
CVE-2025-55911

An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php and the file parameter

Fix: 5.5.2-90+
Fix from $1,600 2025-09-18
Unclassified HIGH 8.4
CVE-2023-49565

The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sanitization of the HTTP Headers …

Mitigation only
Fix from $1,950 2025-09-18
Dir 823x Firmware HIGH 8.8
CVE-2025-10634EPSS 7%

A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead…

No fix yet
Fix from $1,950 2025-09-18
Dir 852 Firmware HIGH 8.8
CVE-2025-10629EPSS 5%

A vulnerability was determined in D-Link DIR-852 1.00CN B09. This issue affects the function ssdpcgi_main of the file htodcs/cgibin of the component …

No fix yet
Fix from $1,950 2025-09-18
Dir 852 Firmware HIGH 8.8
CVE-2025-10628EPSS 9%

A vulnerability was found in D-Link DIR-852 1.00CN B09. This vulnerability affects unknown code of the file /htdocs/cgibin/hedwig.cgi of the componen…

No fix yet
Fix from $1,950 2025-09-18
Unclassified MEDIUM 6.3
CVE-2025-10619

A vulnerability was detected in sequa-ai sequa-mcp up to 1.0.13. This affects the function redirectToAuthorization of the file src/helpers/node-oauth…

Patch available
Fix from $1,600 2025-09-17
Junie CRITICAL 9.8
CVE-2025-59458

In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243…

Fix: 243.284.50 / 251.284.50+
Fix from $2,300 2025-09-17
Br 6473ax Firmware HIGH 8.0
CVE-2025-56706

Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter in the openwrt_getConfig func…

No fix yet
Fix from $1,950 2025-09-16
X6000r Firmware CRITICAL 9.8
CVE-2025-52053

TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter…

Mitigation only
Fix from $2,300 2025-09-15