Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Unclassified MEDIUM 6.3
CVE-2025-5147

A vulnerability was found in Netcore NBR1005GPEV2, NBR200V2 and B6V2 up to 20250508 and classified as critical. This issue affects the function tools…

Mitigation only
Fix from $1,600 2025-05-25
Unclassified MEDIUM 6.3
CVE-2025-5146

A vulnerability has been found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2 and NBR200V2 up to 20250508 and classified as critical…

Mitigation only
Fix from $1,600 2025-05-25
Unclassified MEDIUM 6.3
CVE-2025-5145

A vulnerability, which was classified as critical, was found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2, NBR200V2 and POWER13 up…

Mitigation only
Fix from $1,600 2025-05-25
Qualitor HIGH 8.1
CVE-2025-5139

A vulnerability was found in Qualitor 8.20/8.24. It has been rated as critical. Affected by this issue is some unknown functionality of the file /htm…

No fix yet
Fix from $1,950 2025-05-25
Flir Ax8 Firmware HIGH 8.8
CVE-2025-5126

A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16. This vulnerability affects the function setDataTime of the file \usr\www\application\mo…

Fix: after 1.46.16
Fix from $1,950 2025-05-24
Dir 605l Firmware MEDIUM 6.5
CVE-2025-46176

Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary commands …

Mitigation only
Fix from $1,600 2025-05-23
Unclassified HIGH 7.3
CVE-2025-5106

A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the file /app/fax/fax_view.php o…

Mitigation only
Fix from $1,950 2025-05-23
Netmri HIGH 7.2
CVE-2025-32813EPSS 47%

An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.

Fix: 7.6.1+
Fix from $1,950 2025-05-22
Killwxapkg HIGH 8.1
CVE-2025-5030

A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affects the function processFile of…

Fix: after 2.4.1
Fix from $1,950 2025-05-21
Duo MEDIUM 5.4
CVE-2025-20258

A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitrary commands into emails that…

Mitigation only
Fix from $1,600 2025-05-21
Meteobridge Vm HIGH 8.8
CVE-2025-4008 KEVEPSS 94%

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system thro…

Fix: 6.2+
Fix from $1,950 2025-05-21
Fgw3000 Ah Firmware CRITICAL 9.8
CVE-2025-4999EPSS 8%

A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000 and classified as critical. Affected by this issue is the function…

Fix: after 1.0.17.000000
Fix from $2,300 2025-05-20
Fgw3000 Ah Firmware CRITICAL 9.8
CVE-2025-5000EPSS 7%

A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000. It has been classified as critical. This affects the function con…

Fix: after 1.0.17.000000
Fix from $2,300 2025-05-20
Di 8100g Firmware CRITICAL 9.8
CVE-2025-44084EPSS 18%

D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggeri…

Mitigation only
Fix from $2,300 2025-05-20
Chatgpt MEDIUM 6.5
CVE-2025-43714

The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block…

Fix: after 2025-03-30
Fix from $1,600 2025-05-19
Dc Netscope HIGH 8.8
CVE-2024-55063

Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execute arbitrary code via the (1) …

Fix: after 8.7.0
Fix from $1,950 2025-05-19
N300rh Firmware CRITICAL 9.8
CVE-2025-4851

A vulnerability classified as critical was found in TOTOLINK N300RH 6.1c.1390_B20191101. This vulnerability affects the function setUploadUserData of…

Mitigation only
Fix from $2,300 2025-05-18
N300rh Firmware CRITICAL 9.8
CVE-2025-4849

A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been rated as critical. Affected by this issue is the function CloudACMunual…

Mitigation only
Fix from $2,300 2025-05-18
N300rh Firmware MEDIUM 6.3
CVE-2025-4850

A vulnerability classified as critical has been found in TOTOLINK N300RH 6.1c.1390_B20191101. This affects the function setUnloadUserData of the file…

Mitigation only
Fix from $1,600 2025-05-18
Unclassified MEDIUM 6.3
CVE-2025-4747

A vulnerability was found in Bohua NetDragon Firewall 1.0 and classified as critical. This issue affects some unknown processing of the file /systems…

Mitigation only
Fix from $1,600 2025-05-16
A3002r Firmware MEDIUM 6.3
CVE-2025-4729

A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an…

Mitigation only
Fix from $1,600 2025-05-16
Visual Studio 2019 HIGH 7.8
CVE-2025-32702

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code …

Fix: 16.11.47 / 17.8.21+
Fix from $1,950 2025-05-13
Thingsboard MEDIUM 6.5
CVE-2024-55466

An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows at…

Fix: after 3.8.1
Fix from $1,600 2025-05-12
Fh451 Firmware MEDIUM 6.5
CVE-2025-44176EPSS 10%

Tenda FH451 V1.0.0.9 is vulnerable to Remote Code Execution in the formSafeEmailFilter function.

No fix yet
Fix from $1,600 2025-05-12
Unclassified HIGH 8.8
CVE-2025-29509

Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conversation, due to opening exter…

Mitigation only
Fix from $1,950 2025-05-09
Unclassified CRITICAL 9.8
CVE-2024-11861

EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.

Mitigation only
Fix from $2,300 2025-05-09
Unclassified CRITICAL 9.8
CVE-2024-12442

EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access.

Mitigation only
Fix from $2,300 2025-05-09
Dir 619l Firmware CRITICAL 9.8
CVE-2025-4453EPSS 7%

A vulnerability was found in D-Link DIR-619L 2.04B04. It has been classified as critical. This affects the function formSysCmd. The manipulation of t…

Mitigation only
Fix from $2,300 2025-05-09
Dir 619l Firmware CRITICAL 9.8
CVE-2025-4454EPSS 7%

A vulnerability was found in D-Link DIR-619L 2.04B04. It has been declared as critical. This vulnerability affects the function wake_on_lan. The mani…

Mitigation only
Fix from $2,300 2025-05-09
Dir 605l Firmware CRITICAL 9.8
CVE-2025-4443EPSS 57%

A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub_454F2C. The manipulation of …

Mitigation only
Fix from $2,300 2025-05-09