Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Dir 818lw Firmware HIGH 7.2
CVE-2025-7553

A vulnerability classified as critical has been found in D-Link DIR-818LW up to 20191215. This affects an unknown part of the component System Time P…

Fix: 20191215+
Fix from $1,950 2025-07-14
T6 Firmware HIGH 8.8
CVE-2025-7525

A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been declared as critical. This vulnerability affects the function setTracerou…

No fix yet
Fix from $1,950 2025-07-13
T6 Firmware HIGH 8.8
CVE-2025-7524

A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been classified as critical. This affects the function setDiagnosisCfg of the …

No fix yet
Fix from $1,950 2025-07-13
O3 Firmware HIGH 8.8
CVE-2025-7414EPSS 13%

A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function fromNetToolGet of the file /go…

No fix yet
Fix from $1,950 2025-07-10
O3 Firmware HIGH 8.8
CVE-2025-7415

A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the function fromTraceroutGet of t…

No fix yet
Fix from $1,950 2025-07-10
D6400 Firmware HIGH 8.8
CVE-2025-7407EPSS 9%

A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. This affects an unknown part of the file diag.cgi. The manip…

No fix yet
Fix from $1,950 2025-07-10
Unclassified HIGH 7.5
CVE-2025-53355

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulnerability exists in the mcp-se…

Patch available
Fix from $1,950 2025-07-08
Dir 645 Firmware HIGH 8.8
CVE-2025-7192

A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ssdpcgi_main of the file /htdoc…

Fix: after 1.05b01
Fix from $1,950 2025-07-08
Unclassified HIGH 7.2
CVE-2025-37102

An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exp…

Mitigation only
Fix from $1,950 2025-07-08
Unclassified HIGH 7.5
CVE-2025-53372

node-code-sandbox-mcp is a Node.js–based Model Context Protocol server that spins up disposable Docker containers to execute arbitrary JavaScript. Pr…

Patch available
Fix from $1,950 2025-07-08
N200re Firmware HIGH 8.8
CVE-2025-7154

A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this is…

No fix yet
Fix from $1,950 2025-07-08
Internet Security HIGH 8.8
CVE-2025-7097

A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This issue affects some unknown pr…

No fix yet
Fix from $1,950 2025-07-06
F9k1122 Firmware HIGH 8.8
CVE-2025-7083EPSS 41%

A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. This affects the function mp of the file /goform/mp of the c…

No fix yet
Fix from $1,950 2025-07-06
F9k1122 Firmware HIGH 8.8
CVE-2025-7081EPSS 17%

A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this vulnerability is the function formSetWanStatic …

No fix yet
Fix from $1,950 2025-07-06
F9k1122 Firmware HIGH 8.8
CVE-2025-7082EPSS 15%

A vulnerability was found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this issue is the function formBSSetSitesurvey of the fil…

No fix yet
Fix from $1,950 2025-07-06
Unclassified MEDIUM 6.4
CVE-2025-24333

Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, which authenticated admin user c…

Mitigation only
Fix from $1,600 2025-07-02
Unclassified CRITICAL 9.1
CVE-2025-53104

gluestack-ui is a library of copy-pasteable components & patterns crafted with Tailwind CSS (NativeWind). Prior to commit e6b4271, a command injectio…

Patch available
Fix from $2,300 2025-07-01
Unclassified HIGH 7.5
CVE-2025-53107EPSS 27%

@cyanheads/git-mcp-server is an MCP server designed to interact with Git repositories. Prior to version 2.1.5, there is a command injection vulnerabi…

Patch available
Fix from $1,950 2025-07-01
Filebrowser MEDIUM 6.6
CVE-2025-52995

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Pr…

Fix: after 2.33.8
Fix from $1,600 2025-06-30
Dir 816 Firmware CRITICAL 9.8
CVE-2025-45931

An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/go…

Mitigation only
Fix from $2,300 2025-06-30
Di 7300g\+ Firmware HIGH 8.8
CVE-2025-6899

A vulnerability, which was classified as critical, was found in D-Link DI-7300G+ and DI-8200G 17.12.20A1/19.12.25A1. This affects an unknown part of …

No fix yet
Fix from $1,950 2025-06-30
Di 7300g\+ Firmware HIGH 8.8
CVE-2025-6898EPSS 11%

A vulnerability, which was classified as critical, has been found in D-Link DI-7300G+ 19.12.25A1. Affected by this issue is some unknown functionalit…

Mitigation only
Fix from $1,950 2025-06-30
Di 7300g\+ Firmware CRITICAL 9.8
CVE-2025-6897

A vulnerability classified as critical was found in D-Link DI-7300G+ 19.12.25A1. Affected by this vulnerability is an unknown functionality of the fi…

Mitigation only
Fix from $2,300 2025-06-30
Di 7300g\+ Firmware HIGH 8.8
CVE-2025-6896

A vulnerability classified as critical has been found in D-Link DI-7300G+ 19.12.25A1. Affected is an unknown function of the file wget_test.asp. The …

No fix yet
Fix from $1,950 2025-06-30
Roo Code HIGH 8.1
CVE-2025-53098

Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stored in the `.roo/mcp.json` fil…

Fix: 3.20.3+
Fix from $1,950 2025-06-27
Openvpn Cms Flask CRITICAL 9.8
CVE-2025-6775

A vulnerability classified as critical has been found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This affects the function create_user of the file …

Fix: 1.2.8+
Fix from $2,300 2025-06-27
Unclassified MEDIUM 5.4
CVE-2025-6522

Unauthenticated users on an adjacent network with the Sight Bulb Pro can run shell commands as root through a vulnerable proprietary TCP protocol a…

Mitigation only
Fix from $1,600 2025-06-27
Pandora Fms CRITICAL 9.8
CVE-2025-5306EPSS 31%

Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through…

Fix: after 778
Fix from $2,300 2025-06-27
Filebrowser HIGH 8.0
CVE-2025-52903

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In…

Patch available
Fix from $1,950 2025-06-26
Filebrowser HIGH 8.0
CVE-2025-52904

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In…

No fix yet
Fix from $1,950 2025-06-26