Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Wg302v2 Firmware MEDIUM 6.3
CVE-2025-4135

A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the function ui_get_input_value. The m…

Fix: after 5.2.9
Fix from $1,600 2025-04-30
Jwnr2000v2 Firmware HIGH 8.8
CVE-2025-4122

A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been rated as critical. Affected by this issue is the function sub_435E04. The manip…

Mitigation only
Fix from $1,950 2025-04-30
Jwnr2000v2 Firmware CRITICAL 9.8
CVE-2025-4121

A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been declared as critical. Affected by this vulnerability is the function cmd_wirele…

Mitigation only
Fix from $2,300 2025-04-30
Park Ticketing Management System MEDIUM 5.3
CVE-2025-45010

A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. Thi…

No fix yet
Fix from $1,600 2025-04-30
Park Ticketing Management System MEDIUM 5.3
CVE-2025-45011

A HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerabilit…

No fix yet
Fix from $1,600 2025-04-30
Park Ticketing Management System MEDIUM 5.3
CVE-2025-45009

A HTML Injection vulnerability was discovered in the normal-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability a…

No fix yet
Fix from $1,600 2025-04-30
Unclassified MEDIUM 6.3
CVE-2025-4076EPSS 17%

A vulnerability classified as critical has been found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function easy_uci_set_option_string_0 of th…

No fix yet
Fix from $1,600 2025-04-29
Firefox MEDIUM 5.1
CVE-2025-4089

Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially…

Fix: 138.0+
Fix from $1,600 2025-04-29
Aworld HIGH 8.1
CVE-2025-4032

A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as critical. This issue affects the…

Fix: after 2025-04-24
Fix from $1,950 2025-04-28
N150rt Firmware HIGH 8.8
CVE-2025-3987EPSS 10%

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /…

No fix yet
Fix from $1,950 2025-04-27
Hibos HIGH 7.2
CVE-2025-3983EPSS 14%

A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown …

No fix yet
Fix from $1,950 2025-04-27
Unclassified CRITICAL 9.2
CVE-2025-43858

YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, a…

Patch available
Fix from $2,300 2025-04-24
A800r Firmware MEDIUM 6.5
CVE-2025-28017

TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.

No fix yet
Fix from $1,600 2025-04-23
Dir 816 Firmware MEDIUM 6.5
CVE-2025-29743

D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.

No fix yet
Fix from $1,600 2025-04-22
Unclassified HIGH 7.3
CVE-2025-43948

Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorti…

Mitigation only
Fix from $1,950 2025-04-22
Mimetex HIGH 7.3
CVE-2024-40445

A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by …

Fix: 1.77+
Fix from $1,950 2025-04-22
Cicadascms HIGH 7.2
CVE-2025-3816EPSS 6%

A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of the file /system/schedule/save…

No fix yet
Fix from $1,950 2025-04-19
X18 Firmware CRITICAL 9.8
CVE-2025-29209

TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub_41105C function of cstecgi .…

No fix yet
Fix from $2,300 2025-04-18
74cms MEDIUM 6.3
CVE-2024-46089

74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.

Fix: 3.33.0+
Fix from $1,600 2025-04-18
Toolbox CRITICAL 9.8
CVE-2025-43012

In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible

Fix: 2.6+
Fix from $2,300 2025-04-17
Web Based Pharmacy Product Management System CRITICAL 9.8
CVE-2025-3729

A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affe…

No fix yet
Fix from $2,300 2025-04-16
Whoogle Search HIGH 7.3
CVE-2024-53305

An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supplying a crafted search query.

Patch available
Fix from $1,950 2025-04-16
Online Id Generator System MEDIUM 5.1
CVE-2024-40070

Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=s…

No fix yet
Fix from $1,600 2025-04-16
Unclassified HIGH 7.3
CVE-2024-36842

An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220301, and Build Number Platfor…

Mitigation only
Fix from $1,950 2025-04-15
Br 6478ac V3 Firmware MEDIUM 6.5
CVE-2025-28142EPSS 10%

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /…

No fix yet
Fix from $1,600 2025-04-15
Br 6478ac V3 Firmware MEDIUM 6.5
CVE-2025-28143EPSS 9%

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at th…

No fix yet
Fix from $1,600 2025-04-15
Br 6478ac V3 Firmware MEDIUM 6.5
CVE-2025-28145EPSS 10%

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafr…

No fix yet
Fix from $1,600 2025-04-15
Unclassified HIGH 8.0
CVE-2025-3545

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as cri…

Mitigation only
Fix from $1,950 2025-04-14
Magic Nx15 Firmware HIGH 8.0
CVE-2025-3546

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as criti…

Fix: after 100r014
Fix from $1,950 2025-04-14
Unclassified HIGH 8.0
CVE-2025-3544

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. Th…

Mitigation only
Fix from $1,950 2025-04-14