Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
X15 Firmware CRITICAL 9.8
CVE-2025-8244

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boaf…

Mitigation only
Fix from $2,300 2025-07-27
Unclassified CRITICAL 9.1
CVE-2025-54416

tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In versio…

Patch available
Fix from $2,300 2025-07-26
Unclassified CRITICAL 9.4
CVE-2025-29628

A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobil…

Mitigation only
Fix from $2,300 2025-07-25
Roo Code HIGH 7.8
CVE-2025-54377

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode does not validate line breaks …

Fix: 3.23.19+
Fix from $1,950 2025-07-23
Superagi MEDIUM 6.5
CVE-2025-51472

Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via …

Patch available
Fix from $1,600 2025-07-22
Db Gpt MEDIUM 6.5
CVE-2025-51459

File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via …

Patch available
Fix from $1,600 2025-07-22
T6 Firmware HIGH 8.8
CVE-2025-7952EPSS 16%

A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. This vulnerability affects the function ckeckKeepAlive of the file wirel…

No fix yet
Fix from $1,950 2025-07-22
Unclassified HIGH 7.5
CVE-2025-53832EPSS 8%

Lara Translate MCP Server is a Model Context Protocol (MCP) Server for Lara Translate API. Versions 0.0.11 and below contain a command injection vuln…

Patch available
Fix from $1,950 2025-07-21
Dir 817l Firmware HIGH 8.8
CVE-2025-7932EPSS 5%

A vulnerability classified as critical has been found in D-Link DIR‑817L up to 1.04B01. This affects the function lxmldbc_system of the file ssdpcgi.…

Fix: 1.04b01+
Fix from $1,950 2025-07-21
Ruckus Unleashed CRITICAL 9.1
CVE-2025-46122

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `…

Fix: 10.5.1.0.279 / 200.15.6.212.14+
Fix from $2,300 2025-07-21
Control Center HIGH 7.8
CVE-2025-7883

A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41. Affected is an unknown function of the file \AiStoneS…

Mitigation only
Fix from $1,950 2025-07-20
Dir 816l Firmware HIGH 8.8
CVE-2025-7836EPSS 6%

A vulnerability has been found in D-Link DIR-816L up to 2.06B01 and classified as critical. Affected by this vulnerability is the function lxmldbc_sy…

Fix: 2.06b01+
Fix from $1,950 2025-07-19
Unclassified HIGH 7.5
CVE-2025-54073EPSS 8%

mcp-package-docs is an MCP (Model Context Protocol) server that provides LLMs with efficient access to package documentation across multiple programm…

Patch available
Fix from $1,950 2025-07-18
Xxl Job HIGH 8.8
CVE-2025-7788EPSS 5%

A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability is the function commandJobHa…

Fix: after 3.1.1
Fix from $1,950 2025-07-18
A3300r Firmware CRITICAL 9.8
CVE-2025-52046EPSS 5%

Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc parame…

Mitigation only
Fix from $2,300 2025-07-17
Unclassified HIGH 8.8
CVE-2023-47356

Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via the log_type parameter at /log/…

Mitigation only
Fix from $1,950 2025-07-17
Unclassified CRITICAL 9.8
CVE-2025-52688EPSS 24%

Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading…

No fix yet
Fix from $2,300 2025-07-16
Unclassified HIGH 8.1
CVE-2025-52690EPSS 10%

Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially leading to the loss of confid…

Mitigation only
Fix from $1,950 2025-07-16
Gpt Sovits Webui CRITICAL 9.8
CVE-2025-49834

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webu…

Fix: after 20250228v3
Fix from $2,300 2025-07-15
Gpt Sovits Webui CRITICAL 9.8
CVE-2025-49835

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webu…

Fix: after 20250228v3
Fix from $2,300 2025-07-15
Gpt Sovits Webui CRITICAL 9.8
CVE-2025-49836

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webu…

Fix: after 20250228v3
Fix from $2,300 2025-07-15
Gpt Sovits Webui CRITICAL 9.8
CVE-2025-49833

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in the …

Fix: after 20250228v3
Fix from $2,300 2025-07-15
Unclassified MEDIUM 5.4
CVE-2025-52377EPSS 9%

Command injection vulnerability in Nexxt Solutions NCM-X1800 Mesh Router versions UV1.2.7 and below, allowing authenticated attackers to execute arbi…

Mitigation only
Fix from $1,600 2025-07-15
Unclassified CRITICAL 9.6
CVE-2025-3621

Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.  * vulnerabilit…

Mitigation only
Fix from $2,300 2025-07-15
Foxcms MEDIUM 5.6
CVE-2025-51650

An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary code via up…

Fix: after 1.2.6
Fix from $1,600 2025-07-14
T6 Firmware HIGH 8.8
CVE-2025-7615

A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. Affected by this vulnerability is the function clearPairCfg of the file …

No fix yet
Fix from $1,950 2025-07-14
T6 Firmware HIGH 8.8
CVE-2025-7613

A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been rated as critical. This issue affects the function CloudSrvVersionCheck of the file…

No fix yet
Fix from $1,950 2025-07-14
T6 Firmware HIGH 8.8
CVE-2025-7614

A vulnerability classified as critical has been found in TOTOLINK T6 4.1.5cu.748. Affected is the function delDevice of the file /cgi-bin/cstecgi.cgi…

No fix yet
Fix from $1,950 2025-07-14
Wn535k3 Firmware CRITICAL 9.8
CVE-2025-50756

Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newpass parameter. This vulnerabi…

Mitigation only
Fix from $2,300 2025-07-14
Unclassified MEDIUM 5.0
CVE-2025-7578

A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been declared as critical. This vulnerability affects t…

Mitigation only
Fix from $1,600 2025-07-14