Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Mcp Kubernetes Server MEDIUM 5.3
CVE-2025-59376

feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g.,…

Fix: after 0.1.11
Fix from $1,600 2025-09-15
Unclassified MEDIUM 6.3
CVE-2025-10441EPSS 12%

A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the function sub_433F7C of the f…

No fix yet
Fix from $1,600 2025-09-15
Ac9 Firmware HIGH 8.8
CVE-2025-10442EPSS 8%

A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manip…

No fix yet
Fix from $1,950 2025-09-15
Unclassified MEDIUM 6.3
CVE-2025-10440EPSS 12%

A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A1/19.12.10A1. Affected by thi…

Mitigation only
Fix from $1,600 2025-09-15
Dir 823x Firmware HIGH 8.8
CVE-2025-10401EPSS 8%

A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown function of the file /goform/diag_ping. Performing m…

Fix: after 250416
Fix from $1,950 2025-09-14
Wl Wn578w2 Firmware CRITICAL 9.8
CVE-2025-10359EPSS 6%

A vulnerability was detected in Wavlink WL-WN578W2 221110. This impacts the function sub_404DBC of the file /cgi-bin/wireless.cgi. The manipulation o…

Mitigation only
Fix from $2,300 2025-09-13
Wl Wn578w2 Firmware CRITICAL 9.8
CVE-2025-10358EPSS 6%

A security vulnerability has been detected in Wavlink WL-WN578W2 221110. This affects the function sub_404850 of the file /cgi-bin/wireless.cgi. The …

Mitigation only
Fix from $2,300 2025-09-13
Rpi Jukebox Rfid CRITICAL 9.8
CVE-2025-10328EPSS 9%

A security vulnerability has been detected in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file…

Fix: after 2.8.0
Fix from $2,300 2025-09-12
Rpi Jukebox Rfid CRITICAL 9.8
CVE-2025-10326EPSS 7%

A security flaw has been discovered in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/api/playlist/single…

Fix: after 2.8.0
Fix from $2,300 2025-09-12
Rpi Jukebox Rfid CRITICAL 9.8
CVE-2025-10327EPSS 10%

A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdo…

Fix: after 2.8.0
Fix from $2,300 2025-09-12
Wl Wn578w2 Firmware CRITICAL 9.8
CVE-2025-10324EPSS 8%

A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects the function sub_401C5C of the file firewall.cgi. This manipulation of the …

Mitigation only
Fix from $2,300 2025-09-12
Wl Wn578w2 Firmware HIGH 8.8
CVE-2025-10325EPSS 7%

A vulnerability was identified in Wavlink WL-WN578W2 221110. This impacts the function sub_401340/sub_401BA4 of the file /cgi-bin/login.cgi. Such man…

No fix yet
Fix from $1,950 2025-09-12
Wl Wn578w2 Firmware CRITICAL 9.8
CVE-2025-10323EPSS 8%

A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wizard_rep.shtml. The manipulati…

Mitigation only
Fix from $2,300 2025-09-12
Unclassified CRITICAL 9.3
CVE-2025-10364EPSS 6%

The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on po…

Mitigation only
Fix from $2,300 2025-09-12
Unclassified MEDIUM 5.7
CVE-2025-27233

Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the sma…

Mitigation only
Fix from $1,600 2025-09-12
Visual Studio Code CRITICAL 9.8
CVE-2025-55319

Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.

Fix: 1.104.0+
Fix from $2,300 2025-09-12
Unclassified HIGH 7.5
CVE-2025-56406

An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE…

Mitigation only
Fix from $1,950 2025-09-10
Unclassified CRITICAL 9.8
CVE-2025-59046

The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branch while it prompts for the br…

Patch available
Fix from $2,300 2025-09-09
Unclassified CRITICAL 9.8
CVE-2025-57633

A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute arbitrary OS commands. The /…

Mitigation only
Fix from $2,300 2025-09-09
Sql Server 2016 HIGH 8.8
CVE-2025-55227

Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges…

Fix: 13.0.6470.1 / 13.0.7065.1+
Fix from $1,950 2025-09-09
Factorytalk Optix HIGH 8.8
CVE-2025-9161

A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito pl…

Fix: 1.6.0+
Fix from $1,950 2025-09-09
Dir 823x Firmware CRITICAL 9.8
CVE-2025-10123

A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_sta…

Fix: after 250416
Fix from $2,300 2025-09-09
Codeceptjs CRITICAL 9.8
CVE-2025-57285

codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates th…

Mitigation only
Fix from $2,300 2025-09-08
Unclassified HIGH 8.4
CVE-2025-7388

It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject …

Mitigation only
Fix from $1,950 2025-09-04
X5000r Firmware CRITICAL 9.8
CVE-2025-9934

A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performin…

Mitigation only
Fix from $2,300 2025-09-04
N600r Firmware CRITICAL 9.8
CVE-2025-9935

A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_4159F8 of the file /web_cste/cgi…

Mitigation only
Fix from $2,300 2025-09-04
Unclassified HIGH 7.5
CVE-2025-58358

Markdownify is a Model Context Protocol server for converting almost anything to Markdown. Versions below 0.0.2 contain a command injection vulnerabi…

Patch available
Fix from $1,950 2025-09-04
Mostartcms MEDIUM 6.5
CVE-2025-55824

ModStartCMS v9.5.0 has an arbitrary file write vulnerability, which allows attackers to write malicious files and execute malicious commands to obtai…

No fix yet
Fix from $1,600 2025-09-02
Beakon MEDIUM 5.3
CVE-2025-55372

An arbitrary file upload vulnerability in Beakon Application before v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.

Fix: 5.4.3+
Fix from $1,600 2025-09-02
Wl Wn535k3 Firmware MEDIUM 6.5
CVE-2025-50755

Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the command parameter. This vulnerabi…

No fix yet
Fix from $1,600 2025-09-02