Vulnerability index

Browse CVEs

3,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Anythingllm HIGH 8.8
CVE-2026-48116

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the file…

Fix: 1.13.0+
Fix from $1,950 2026-05-28
Ir315 Firmware CRITICAL 9.8
CVE-2026-38702

A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmw…

Fix: 1.0.121 / 3.5.112+
Fix from $2,300 2026-05-28
Ir315 Firmware CRITICAL 9.8
CVE-2026-38703

A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmw…

Fix: 1.0.121 / 3.5.112+
Fix from $2,300 2026-05-28
Ir315 Firmware CRITICAL 9.8
CVE-2026-38704

A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firm…

Fix: 1.0.121 / 3.5.112+
Fix from $2,300 2026-05-28
Ir315 Firmware CRITICAL 9.8
CVE-2026-38707

A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware…

Fix: 1.0.121 / 3.5.112+
Fix from $2,300 2026-05-28
Archer Be450 Firmware HIGH 7.2
CVE-2026-5509

An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary…

Fix: 1.3.0+
Fix from $1,950 2026-05-27
Unclassified HIGH 7.8
CVE-2025-69600

Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execute commands via getconfig, upl…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.8
CVE-2026-38945

Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that mat…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.3
CVE-2026-36540

Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi endpoint. The password and new_p…

Mitigation only
Fix from $1,950 2026-05-27
Fastnetmon HIGH 8.1
CVE-2026-48694

FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_…

Fix: after 1.2.9
Fix from $1,950 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9565

A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/age…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified HIGH 8.8
CVE-2026-46368EPSS 7%

luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt commu…

No fix yet
Fix from $1,950 2026-05-26
Unclassified HIGH 7.8
CVE-2026-40034

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to …

Patch available
Fix from $1,950 2026-05-26
Unclassified CRITICAL 9.8
CVE-2026-9543

A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of th…

Mitigation only
Fix from $2,300 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9532EPSS 11%

A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bi…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9533EPSS 11%

A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi o…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9534EPSS 11%

A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Se…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9531EPSS 11%

A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the compo…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9515EPSS 11%

A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi …

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9512

A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstec…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified MEDIUM 6.3
CVE-2026-9513

A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of th…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified MEDIUM 6.3
CVE-2026-9514EPSS 11%

A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi o…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified MEDIUM 6.3
CVE-2026-9511

A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the compon…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified CRITICAL 9.8
CVE-2026-9478

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of…

Mitigation only
Fix from $2,300 2026-05-25
Unclassified CRITICAL 9.8
CVE-2026-9477

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/…

Mitigation only
Fix from $2,300 2026-05-25
Unclassified CRITICAL 9.8
CVE-2026-9475

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of t…

Mitigation only
Fix from $2,300 2026-05-25
Unclassified CRITICAL 9.8
CVE-2026-9476

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/c…

Mitigation only
Fix from $2,300 2026-05-25
Unclassified CRITICAL 9.8
CVE-2026-9457

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function UploadFirmwareFile of the file /cgi-bin/…

Mitigation only
Fix from $2,300 2026-05-25
Unclassified CRITICAL 9.8
CVE-2026-9458

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.c…

Mitigation only
Fix from $2,300 2026-05-25
Unclassified HIGH 7.3
CVE-2026-9453

A vulnerability was detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. This affects the function which of the file /src…

Mitigation only
Fix from $1,950 2026-05-25