Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Dsl 7740c Firmware HIGH 7.2
CVE-2025-29516

D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the backup function.

No fix yet
Fix from $1,950 2025-08-25
Dsl 7740c Firmware MEDIUM 6.8
CVE-2025-29517

D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the traceroute6 function.

No fix yet
Fix from $1,600 2025-08-25
Dcme 720 Firmware CRITICAL 9.8
CVE-2025-9387EPSS 9%

A vulnerability was found in DCN DCME-720 9.1.5.11. This affects an unknown function of the file /usr/local/www/function/audit/newstatistics/ip_block…

Mitigation only
Fix from $2,300 2025-08-24
Smart 2k\+ Plug In Wi Fi Video Doorbell With Chime Firmware CRITICAL 9.8
CVE-2025-55637

Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a command injection vulnerabili…

Mitigation only
Fix from $2,300 2025-08-22
Di 7400g\+ Firmware CRITICAL 9.8
CVE-2025-57105

The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the device. The sub_478D28 functi…

Mitigation only
Fix from $2,300 2025-08-22
Unclassified HIGH 8.7
CVE-2025-41451

Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Series prior to …

Mitigation only
Fix from $1,950 2025-08-22
Unclassified HIGH 7.5
CVE-2025-48978

An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a malicious actor with access to E…

Mitigation only
Fix from $1,950 2025-08-21
Unclassified CRITICAL 9.8
CVE-2025-24285

Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with network a…

Mitigation only
Fix from $2,300 2025-08-21
Mcp Cli HIGH 8.1
CVE-2025-9262EPSS 5%

A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/provider.js of the component o…

No fix yet
Fix from $1,950 2025-08-20
Re6250 Firmware HIGH 8.8
CVE-2025-9244EPSS 8%

A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/…

No fix yet
Fix from $1,950 2025-08-20
Shc HIGH 7.8
CVE-2025-9176

A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment Var…

Fix: after 4.0.3
Fix from $1,950 2025-08-20
Shc HIGH 7.8
CVE-2025-9174

A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the function make of the file src/shc.c of the component Filen…

Fix: after 4.0.3
Fix from $1,950 2025-08-19
Unclassified MEDIUM 6.5
CVE-2025-52337

An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5.0.9.7000 allows attackers to…

Mitigation only
Fix from $1,600 2025-08-19
Unclassified HIGH 7.2
CVE-2025-50891

The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NO…

No fix yet
Fix from $1,950 2025-08-19
Unclassified CRITICAL 9.8
CVE-2025-55294

screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input i…

Patch available
Fix from $2,300 2025-08-19
Wl Nu516u1 Firmware CRITICAL 9.8
CVE-2025-9149EPSS 6%

A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This mani…

Mitigation only
Fix from $2,300 2025-08-19
Unclassified MEDIUM 6.5
CVE-2025-50461

A deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts/model_merger.py script when using the "fsdp" backend. …

Mitigation only
Fix from $1,600 2025-08-19
A3002r Firmware MEDIUM 6.5
CVE-2025-55590

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.

No fix yet
Fix from $1,600 2025-08-18
A3002r Firmware CRITICAL 9.8
CVE-2025-55591EPSS 7%

TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoi…

Mitigation only
Fix from $2,300 2025-08-18
Aiven Db Migrate HIGH 7.2
CVE-2025-55283

aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows elevation to superuse…

Fix: 1.0.7+
Fix from $1,950 2025-08-18
Ac20 Firmware CRITICAL 9.8
CVE-2025-9090EPSS 14%

A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet …

Mitigation only
Fix from $2,300 2025-08-17
Dir 860l Firmware CRITICAL 9.8
CVE-2025-9026

A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cgibin of the component Simple …

Mitigation only
Fix from $2,300 2025-08-15
Unclassified MEDIUM 6.5
CVE-2025-50515

An issue was discovered in phome Empirebak 2010 in ebak2008/upload/class/config.php allowing attackers to execute arbitrary code when the config file…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified MEDIUM 5.4
CVE-2025-50817

A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the mod…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified HIGH 8.8
CVE-2024-53945EPSS 19%

The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An a…

Mitigation only
Fix from $1,950 2025-08-14
Dir 818l Firmware HIGH 8.8
CVE-2025-8956EPSS 18%

A vulnerability was found in D-Link DIR‑818L up to 1.05B01. This issue affects the function getenv of the file /htdocs/cgibin of the component ssdpcg…

No fix yet
Fix from $1,950 2025-08-14
N350r Firmware HIGH 8.8
CVE-2025-8937

A vulnerability has been found in TOTOLINK N350R 1.2.3-B20130826. This vulnerability affects unknown code of the file /boafrm/formSysCmd. The manipul…

Mitigation only
Fix from $1,950 2025-08-14
Hortusfox MEDIUM 6.5
CVE-2025-45317

A zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary code via a crafted ar…

No fix yet
Fix from $1,600 2025-08-13
Visual Studio 2022 HIGH 7.8
CVE-2025-53773

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attack…

Fix: 17.14.12+
Fix from $1,950 2025-08-12
Re6250 Firmware HIGH 8.8
CVE-2025-8830EPSS 8%

A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function su…

No fix yet
Fix from $1,950 2025-08-11