Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Dir 605l Firmware CRITICAL 9.8
CVE-2025-4445EPSS 6%

A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01. Affected is the function wake_on_lan. The manipulation of the argum…

Mitigation only
Fix from $2,300 2025-05-09
A950rg Firmware CRITICAL 9.8
CVE-2025-45798

A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg interface w…

No fix yet
Fix from $2,300 2025-05-08
Unclassified MEDIUM 6.5
CVE-2025-44023

An issue in dlink DNS-320 v.1.00 and DNS-320LW v.1.01.0914.20212 allows an attacker to execute arbitrary via the account_mgr.cgi->cgi_chg_admin_pw co…

Mitigation only
Fix from $1,600 2025-05-08
Event Booking Calendar MEDIUM 6.5
CVE-2023-51295

PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plu…

No fix yet
Fix from $1,600 2025-05-08
Big Ip Access Policy Manager HIGH 8.7
CVE-2025-31644EPSS 24%

When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which m…

Fix: 15.1.10.7 / 16.1.6+
Fix from $1,950 2025-05-07
Unclassified MEDIUM 6.5
CVE-2025-29154

HTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the .galera.app/ted/solicita…

No fix yet
Fix from $1,600 2025-05-07
Unclassified CRITICAL 9.4
CVE-2025-46816

goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without arguments makes it possible fo…

Patch available
Fix from $2,300 2025-05-06
Unclassified MEDIUM 6.5
CVE-2025-26262

An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate privileges and execute arbit…

Mitigation only
Fix from $1,600 2025-05-06
Storage Manager HIGH 8.0
CVE-2025-22476

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command…

Fix: 2020+
Fix from $1,950 2025-05-06
E5600 Firmware CRITICAL 9.8
CVE-2025-45490

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parame…

No fix yet
Fix from $2,300 2025-05-06
E5600 Firmware CRITICAL 9.8
CVE-2025-45491

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parame…

No fix yet
Fix from $2,300 2025-05-06
Ex8000 Firmware CRITICAL 9.8
CVE-2025-45492

Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the Iface parameter in the action_wireless function.

No fix yet
Fix from $2,300 2025-05-06
E5600 Firmware CRITICAL 9.8
CVE-2025-45487EPSS 11%

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.

No fix yet
Fix from $2,300 2025-05-06
E5600 Firmware CRITICAL 9.8
CVE-2025-45488EPSS 11%

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex paramete…

No fix yet
Fix from $2,300 2025-05-06
E5600 Firmware CRITICAL 9.8
CVE-2025-45489

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parame…

No fix yet
Fix from $2,300 2025-05-06
Rx3 Firmware CRITICAL 9.8
CVE-2025-4357EPSS 15%

A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown processing of the file /gofo…

No fix yet
Fix from $2,300 2025-05-06
Dir 600l Firmware CRITICAL 9.8
CVE-2025-4349

A vulnerability classified as critical has been found in D-Link DIR-600L up to 2.07B01. This affects the function formSysCmd. The manipulation of the…

Fix: after 2.07b01
Fix from $2,300 2025-05-06
Dir 600l Firmware CRITICAL 9.8
CVE-2025-4350

A vulnerability classified as critical was found in D-Link DIR-600L up to 2.07B01. This vulnerability affects the function wake_on_lan. The manipulat…

Fix: after 2.07b01
Fix from $2,300 2025-05-06
Dir 880l Firmware CRITICAL 9.8
CVE-2025-4341EPSS 20%

A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb01. Affected by this vulnerability is the function sub_16570 of the f…

Fix: after 104WWb01
Fix from $2,300 2025-05-06
Dir 806 Firmware CRITICAL 9.8
CVE-2025-4340

A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected is the function sub_175C8 of t…

Fix: after 100cnb11
Fix from $2,300 2025-05-06
Retrieval Based Voice Conversion Webui CRITICAL 9.8
CVE-2025-43844

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection…

Fix: after 2.2.231006
Fix from $2,300 2025-05-05
Retrieval Based Voice Conversion Webui CRITICAL 9.8
CVE-2025-43843

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection…

Fix: after 2.2.231006
Fix from $2,300 2025-05-05
Retrieval Based Voice Conversion Webui CRITICAL 9.8
CVE-2025-43842

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection…

Fix: after 2.2.231006
Fix from $2,300 2025-05-05
Rax50 Firmware CRITICAL 9.8
CVE-2024-57231

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_…

No fix yet
Fix from $2,300 2025-05-05
Rax50 Firmware CRITICAL 9.8
CVE-2024-57232

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen…

No fix yet
Fix from $2,300 2025-05-05
Rax50 Firmware CRITICAL 9.8
CVE-2024-57233

NETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable fu…

No fix yet
Fix from $2,300 2025-05-05
Rax50 Firmware CRITICAL 9.8
CVE-2024-57234

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_…

No fix yet
Fix from $2,300 2025-05-05
Rax50 Firmware CRITICAL 9.8
CVE-2024-57235

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable fun…

No fix yet
Fix from $2,300 2025-05-05
Rax50 Firmware CRITICAL 9.8
CVE-2024-57229

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi f…

No fix yet
Fix from $2,300 2025-05-05
Rax50 Firmware CRITICAL 9.8
CVE-2024-57230

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_…

No fix yet
Fix from $2,300 2025-05-05