Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Hibos CRITICAL 9.8
CVE-2025-2701EPSS 7%

A vulnerability classified as critical was found in AMTT Hotel Broadband Operation System 1.0. This vulnerability affects the function popen of the f…

No fix yet
Fix from $2,300 2025-03-24
E5600 Firmware MEDIUM 6.3
CVE-2025-29223

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function.

Mitigation only
Fix from $1,600 2025-03-21
E5600 Firmware MEDIUM 6.3
CVE-2025-29226

In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the p…

Mitigation only
Fix from $1,600 2025-03-21
E5600 Firmware MEDIUM 6.3
CVE-2025-29227

In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the p…

Mitigation only
Fix from $1,600 2025-03-21
E5600 Firmware HIGH 8.6
CVE-2025-29230

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be trigge…

Mitigation only
Fix from $1,950 2025-03-21
Mattermost Server HIGH 8.8
CVE-2025-25274

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authen…

Fix: 9.11.9 / 10.3.4+
Fix from $1,950 2025-03-21
Autogpt Classic CRITICAL 9.8
CVE-2024-8156

A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untrusted user input `github.head.…

Fix: 0.5.1+
Fix from $2,300 2025-03-20
Smartfabric Os10 HIGH 7.8
CVE-2025-22473

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in …

Fix: 10.5.4.14 / 10.5.5.13+
Fix from $1,950 2025-03-17
Smartfabric Os10 HIGH 7.8
CVE-2025-22472

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in …

Fix: 10.5.4.14 / 10.5.5.13+
Fix from $1,950 2025-03-17
Smartfabric Os10 MEDIUM 6.7
CVE-2024-48015

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in …

Fix: 10.5.4.14 / 10.5.5.13+
Fix from $1,600 2025-03-17
Smartfabric Os10 MEDIUM 6.5
CVE-2024-48017

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in …

Fix: 10.5.4.14 / 10.5.5.13+
Fix from $1,600 2025-03-17
Smartfabric Os10 HIGH 7.8
CVE-2024-48830

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in …

Fix: 10.5.4.14 / 10.5.5.13+
Fix from $1,950 2025-03-17
Pandora Fms CRITICAL 9.8
CVE-2024-12992

Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This issue affects Pandora FMS fro…

Fix: 777.8+
Fix from $2,300 2025-03-17
Pandora Fms HIGH 8.8
CVE-2024-12971EPSS 58%

Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 77…

Fix: 777.8+
Fix from $1,950 2025-03-17
Unclassified MEDIUM 6.3
CVE-2025-2367

A vulnerability has been found in Oiwtech OIW-2431APGN-HP 2.5.3-B20131128 and classified as critical. This vulnerability affects unknown code of the …

Mitigation only
Fix from $1,600 2025-03-17
Fortinac MEDIUM 5.3
CVE-2023-33300EPSS 13%

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allow…

Fix: 7.2.2 / 9.4.4+
Fix from $1,600 2025-03-14
Fortimanager HIGH 8.8
CVE-2024-46662

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiMan…

Fix: 7.4.4+
Fix from $1,950 2025-03-14
GitLab HIGH 7.4
CVE-2024-8402

An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all vers…

Fix: 17.7.7 / 17.8.5+
Fix from $1,950 2025-03-13
Unclassified MEDIUM 5.3
CVE-2024-27763

XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostname" is executed in the presen…

Mitigation only
Fix from $1,600 2025-03-12
Box Firmware HIGH 8.8
CVE-2024-13871

A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). Th…

Mitigation only
Fix from $1,950 2025-03-12
Azure Arc HIGH 7.0
CVE-2025-26627

Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges …

Fix: 1.0.10+
Fix from $1,950 2025-03-11
Azure Command Line Interface HIGH 8.4
CVE-2025-24049

Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized at…

Fix: 2.69.0+
Fix from $1,950 2025-03-11
Plotai CRITICAL 9.8
CVE-2025-1497

A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attack…

Fix: 0.0.7+
Fix from $2,300 2025-03-10
Ex1800t Firmware CRITICAL 9.8
CVE-2025-2095

A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the function setDmzCfg of the file /cg…

No fix yet
Fix from $2,300 2025-03-07
Ex1800t Firmware CRITICAL 9.8
CVE-2025-2096

A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function setRebootScheCfg…

No fix yet
Fix from $2,300 2025-03-07
Ex1800t Firmware CRITICAL 9.8
CVE-2025-2094EPSS 13%

A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. It has been rated as critical. Affected by this issue is the function setWiFiEx…

No fix yet
Fix from $2,300 2025-03-07
Qurouter HIGH 7.2
CVE-2024-53700

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained adm…

Mitigation only
Fix from $1,950 2025-03-07
Thinos HIGH 7.8
CVE-2025-26331

Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low priv…

Fix: after 2411
Fix from $1,950 2025-03-07
Ac15 Firmware CRITICAL 9.8
CVE-2025-25632

Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.

No fix yet
Fix from $2,300 2025-03-05
Education And Training System CRITICAL 9.8
CVE-2025-1946EPSS 5%

A vulnerability was found in hzmanyun Education and Training System 2.1. It has been rated as critical. Affected by this issue is the function export…

No fix yet
Fix from $2,300 2025-03-04