Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Unclassified HIGH 7.3
CVE-2025-1338EPSS 51%

A vulnerability was found in NUUO Camera up to 20250203. It has been declared as critical. This vulnerability affects the function print_file of the …

Mitigation only
Fix from $1,950 2025-02-16
Unclassified HIGH 8.8
CVE-2025-0593

The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by using lower-level functions to interact with the dev…

Mitigation only
Fix from $1,950 2025-02-14
Unclassified CRITICAL 9.9
CVE-2025-22630

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Marketing Fire Widget Options widget-options all…

Mitigation only
Fix from $2,300 2025-02-14
Unclassified HIGH 7.2
CVE-2025-22962

A critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters when deb…

Mitigation only
Fix from $1,950 2025-02-13
Mojave Inverter Oghi8048a Firmware CRITICAL 9.8
CVE-2025-24861

An attacker may inject commands via specially-crafted post requests.

No fix yet
Fix from $2,300 2025-02-13
Unclassified MEDIUM 6.3
CVE-2025-1229

A vulnerability classified as critical was found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378ddd6. Affected by this vulnerability …

Mitigation only
Fix from $1,600 2025-02-12
Dir 853 Firmware HIGH 7.2
CVE-2025-25743

D-Link DIR-853 A1 FW1.20B07 was discovered to contain a command injection vulnerability in the SetVirtualServerSettings module.

No fix yet
Fix from $1,950 2025-02-12
Telerik Ui For Winui HIGH 7.8
CVE-2024-12251

In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperli…

Fix: 3.0.0+
Fix from $1,950 2025-02-12
Unclassified HIGH 7.9
CVE-2024-33469

An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate method of Da…

Mitigation only
Fix from $1,950 2025-02-11
Unclassified HIGH 7.3
CVE-2025-23094

The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R…

Mitigation only
Fix from $1,950 2025-02-06
Unclassified CRITICAL 9.4
CVE-2023-5878

Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a co…

Mitigation only
Fix from $2,300 2025-02-06
Big Ip Access Policy Manager HIGH 8.7
CVE-2025-23239

When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisc…

Mitigation only
Fix from $1,950 2025-02-05
Asyncos HIGH 7.2
CVE-2025-20184

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could a…

Mitigation only
Fix from $1,950 2025-02-05
Co2scope CRITICAL 9.8
CVE-2024-55062

Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to …

Fix: after 8.6.0
Fix from $2,300 2025-01-31
Home Flex Nema 14 50 Plug Firmware HIGH 8.8
CVE-2024-23971

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. …

Mitigation only
Fix from $1,950 2025-01-31
Unclassified MEDIUM 6.5
CVE-2024-53615

A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attacke…

Mitigation only
Fix from $1,600 2025-01-30
Escan Anti Virus HIGH 8.1
CVE-2025-0798EPSS 7%

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of…

No fix yet
Fix from $1,950 2025-01-29
Safari HIGH 8.8
CVE-2025-24150

A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copy…

Fix: 15.3 / 18.3+
Fix from $1,950 2025-01-27
Unclassified CRITICAL 10.0
CVE-2024-48841

Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older.

Mitigation only
Fix from $2,300 2025-01-27
Br 6476ac Firmware HIGH 8.8
CVE-2024-48419EPSS 5%

Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be trigge…

No fix yet
Fix from $1,950 2025-01-27
Tew 632brp Firmware CRITICAL 9.8
CVE-2024-57590

TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to…

Mitigation only
Fix from $2,300 2025-01-27
Goat G1 2000 Firmware CRITICAL 9.6
CVE-2024-52325

ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.

Fix: 1.2.120 / 1.36.187+
Fix from $2,300 2025-01-23
Ambari HIGH 8.8
CVE-2025-23196

A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell co…

Fix: 2.7.9+
Fix from $1,950 2025-01-21
E8450 Firmware HIGH 8.0
CVE-2024-57536

Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status.

No fix yet
Fix from $1,950 2025-01-21
E8450 Firmware HIGH 8.2
CVE-2024-57539

Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail.

No fix yet
Fix from $1,950 2025-01-21
Spagobi CRITICAL 9.1
CVE-2024-54794EPSS 13%

The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.

No fix yet
Fix from $2,300 2025-01-21
A810r Firmware HIGH 8.1
CVE-2024-57036

TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability a…

No fix yet
Fix from $1,950 2025-01-21
Sterling Secure Proxy CRITICAL 9.1
CVE-2024-41783

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlyi…

Fix: 6.0.3.1+
Fix from $2,300 2025-01-19
Ac8 Firmware HIGH 7.2
CVE-2025-0528EPSS 6%

A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown fun…

No fix yet
Fix from $1,950 2025-01-17
Unclassified HIGH 8.7
CVE-2024-54660

A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can in…

Mitigation only
Fix from $1,950 2025-01-16