Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Wl Wn535k3 Firmware MEDIUM 6.5
CVE-2025-50757

Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. This vulnerab…

No fix yet
Fix from $1,600 2025-09-02
Wl Wn531p3 Firmware MEDIUM 6.5
CVE-2024-48705

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while reset…

No fix yet
Fix from $1,600 2025-09-02
Unclassified HIGH 7.8
CVE-2025-58178

SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In versions 4 to 5.3.0, a command injec…

Patch available
Fix from $1,950 2025-09-02
Di 7400g\+ Firmware MEDIUM 6.2
CVE-2025-9769EPSS 26%

A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulati…

No fix yet
Fix from $1,600 2025-09-01
Dir 852 Firmware CRITICAL 9.8
CVE-2025-9752EPSS 16%

A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component …

Mitigation only
Fix from $2,300 2025-09-01
Di 500wf Firmware HIGH 7.2
CVE-2025-9745EPSS 10%

A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.a…

No fix yet
Fix from $1,950 2025-08-31
Dir 816l Firmware CRITICAL 9.8
CVE-2025-9727

A weakness has been identified in D-Link DIR-816L 206b01. Affected by this issue is the function soapcgi_main of the file /soap.cgi. This manipulatio…

Mitigation only
Fix from $2,300 2025-08-31
Hybriddesk Station HIGH 8.4
CVE-2025-44015

A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network access, they can then exploit th…

Fix: 4.2.18+
Fix from $1,950 2025-08-29
Qts HIGH 8.8
CVE-2025-30264

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they…

Mitigation only
Fix from $1,950 2025-08-29
Qurouter HIGH 7.2
CVE-2025-29887

A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrator account, they can then expl…

Mitigation only
Fix from $1,950 2025-08-29
Unclassified MEDIUM 6.3
CVE-2025-9654

A security flaw has been discovered in AiondaDotCom mcp-ssh up to 1.0.3. Affected by this issue is some unknown functionality of the file server-simp…

Patch available
Fix from $1,600 2025-08-29
Tlr 2005ksh Firmware CRITICAL 9.8
CVE-2025-9603EPSS 8%

A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file /cgi-bin/internet.cgi?Command…

Mitigation only
Fix from $2,300 2025-08-29
Cf N1 Firmware HIGH 8.8
CVE-2025-9585EPSS 5%

A vulnerability was determined in Comfast CF-N1 2.6.0. This affects the function wifilith_delete_pic_file of the file /usr/bin/webmgnt. This manipula…

No fix yet
Fix from $1,950 2025-08-28
Cf N1 Firmware HIGH 8.8
CVE-2025-9586EPSS 8%

A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. S…

No fix yet
Fix from $1,950 2025-08-28
Cf N1 Firmware CRITICAL 9.8
CVE-2025-9582EPSS 5%

A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argum…

Mitigation only
Fix from $2,300 2025-08-28
Cf N1 Firmware HIGH 8.8
CVE-2025-9583EPSS 5%

A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the file /usr/bin/webmgnt. The m…

No fix yet
Fix from $1,950 2025-08-28
Cf N1 Firmware HIGH 8.8
CVE-2025-9584EPSS 8%

A vulnerability was found in Comfast CF-N1 2.6.0. Affected by this issue is the function update_interface_png of the file /usr/bin/webmgnt. The manip…

No fix yet
Fix from $1,950 2025-08-28
Bl X26 Firmware HIGH 8.8
CVE-2025-9579EPSS 7%

A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/set_hidessid_cfg of the compo…

No fix yet
Fix from $1,950 2025-08-28
Bl X26 Firmware HIGH 8.8
CVE-2025-9580EPSS 7%

A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the compone…

No fix yet
Fix from $1,950 2025-08-28
Cf N1 Firmware CRITICAL 9.8
CVE-2025-9581EPSS 5%

A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of t…

Mitigation only
Fix from $2,300 2025-08-28
Re6250 Firmware HIGH 8.8
CVE-2025-9575EPSS 8%

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. …

No fix yet
Fix from $1,950 2025-08-28
Raspap Webgui CRITICAL 9.8
CVE-2025-50428

In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to i…

Fix: after 3.3.2
Fix from $2,300 2025-08-27
Opnsense CRITICAL 9.1
CVE-2025-50989EPSS 8%

OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). …

Fix: 25.1.8+
Fix from $2,300 2025-08-27
E1700 Firmware HIGH 7.2
CVE-2025-9528EPSS 48%

A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand.…

No fix yet
Fix from $1,950 2025-08-27
Ws7204 A Firmware CRITICAL 9.8
CVE-2025-9424EPSS 18%

A vulnerability was identified in Ruijie WS7204-A 2017.06.15. Affected by this vulnerability is an unknown functionality of the file /itbox_pi/branch…

Mitigation only
Fix from $2,300 2025-08-25
Sparkshop CRITICAL 9.8
CVE-2025-50722

Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php component

Mitigation only
Fix from $2,300 2025-08-25
Dsl 7740c Firmware HIGH 7.2
CVE-2025-29523

D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping6 function.

No fix yet
Fix from $1,950 2025-08-25
Unclassified MEDIUM 6.5
CVE-2025-44179

Hitron CGNF-TWN 3.1.1.43-TWN-pre3 contains a command injection vulnerability in the telnet service. The issue arises due to improper input validation…

Mitigation only
Fix from $1,600 2025-08-25
Dsl 7740c Firmware MEDIUM 6.5
CVE-2025-29522

D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping function.

No fix yet
Fix from $1,600 2025-08-25
Dsl 7740c Firmware MEDIUM 5.3
CVE-2025-29519

A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to execute arbit…

No fix yet
Fix from $1,600 2025-08-25