Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Re6250 Firmware HIGH 8.8
CVE-2025-8829EPSS 8%

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the fun…

No fix yet
Fix from $1,950 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8828EPSS 8%

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function ipv6cmd of the f…

No fix yet
Fix from $1,950 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8827EPSS 8%

A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function um_inspect_cro…

No fix yet
Fix from $1,950 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8825EPSS 8%

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function RP_setBasicAuto…

No fix yet
Fix from $1,950 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8823EPSS 8%

A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function…

No fix yet
Fix from $1,950 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8821EPSS 8%

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function RP_setBas…

No fix yet
Fix from $1,950 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8818EPSS 8%

A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function se…

No fix yet
Fix from $1,950 2025-08-10
Spring Shiro Training CRITICAL 9.8
CVE-2025-8752

A vulnerability was found in wangzhixuan spring-shiro-training up to 94812c1fd8f7fe796c931f4984ff1aa0671ab562. It has been declared as critical. This…

Mitigation only
Fix from $2,300 2025-08-09
365 Copilot Chat HIGH 7.5
CVE-2025-53774

Microsoft 365 Copilot BizChat Information Disclosure Vulnerability

No fix yet
Fix from $1,950 2025-08-07
365 Copilot Chat HIGH 7.5
CVE-2025-53787

Microsoft 365 Copilot BizChat Information Disclosure Vulnerability

No fix yet
Fix from $1,950 2025-08-07
Unclassified MEDIUM 6.3
CVE-2025-8697

A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function StdioServerParameters of the comp…

Mitigation only
Fix from $1,600 2025-08-07
Directory Manager MEDIUM 5.4
CVE-2025-54393

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain admin…

Fix: 11.1.25162.02+
Fix from $1,600 2025-08-07
Unclassified MEDIUM 6.5
CVE-2025-47188EPSS 49%

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit throug…

Mitigation only
Fix from $1,600 2025-08-07
Unclassified HIGH 8.7
CVE-2025-7769EPSS 16%

Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allo…

Mitigation only
Fix from $1,950 2025-08-06
Unclassified MEDIUM 6.3
CVE-2025-8667

A vulnerability, which was classified as critical, was found in SkyworkAI DeepResearchAgent up to 08eb7f8eb9505d0094d75bb97ff7dacc3fa3bbf2. Affected …

Mitigation only
Fix from $1,600 2025-08-06
Unclassified MEDIUM 6.3
CVE-2025-8665

A vulnerability, which was classified as critical, has been found in agno-agi agno up to 1.7.5. This issue affects the function MCPTools/MultiMCPTool…

Mitigation only
Fix from $1,600 2025-08-06
U Boot MEDIUM 6.5
CVE-2025-45512

A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmwa…

No fix yet
Fix from $1,600 2025-08-05
Twistedweb MEDIUM 6.5
CVE-2025-50688

A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload functionality. An attac…

No fix yet
Fix from $1,600 2025-08-05
Unclassified HIGH 7.5
CVE-2025-27211

An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a malicious actor with access to E…

Mitigation only
Fix from $1,950 2025-08-04
Unclassified CRITICAL 9.8
CVE-2025-27212

An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access managem…

Mitigation only
Fix from $2,300 2025-08-04
Devtools Integration HIGH 8.8
CVE-2025-54782EPSS 48%

Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulne…

Fix: 0.2.1+
Fix from $1,950 2025-08-02
Cursor HIGH 8.8
CVE-2025-54131

Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in auto-run mode with a backtick …

Fix: 1.3+
Fix from $1,950 2025-08-01
1panel CRITICAL 9.8
CVE-2025-54424

1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. In versions 2.0.5 and below…

Fix: 2.0.6+
Fix from $2,300 2025-08-01
Unclassified HIGH 7.8
CVE-2025-54564

uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allows command execution as the no…

Mitigation only
Fix from $1,950 2025-08-01
Rx 1500 Firmware CRITICAL 9.8
CVE-2025-26063

An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload int…

Mitigation only
Fix from $2,300 2025-07-31
Prestashop MEDIUM 6.5
CVE-2025-25691

A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted PO…

No fix yet
Fix from $1,600 2025-07-30
Prestashop MEDIUM 6.5
CVE-2025-25692

A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST r…

No fix yet
Fix from $1,600 2025-07-30
Ptc310uv2 Firmware MEDIUM 6.5
CVE-2025-45619

An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction function

No fix yet
Fix from $1,600 2025-07-30
X6000r Firmware MEDIUM 6.5
CVE-2025-52284

Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the tz parameter. This …

No fix yet
Fix from $1,600 2025-07-29
Vaelsys CRITICAL 9.8
CVE-2025-8259

A vulnerability was identified in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. Affected by this issue is the function execute_DataObjectProc of the file /gri…

Mitigation only
Fix from $2,300 2025-07-28