Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 7.2 CVE-2026-2063 A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/set_ac_server of the compo… Dir 823x Firmware No fix yet Fix from $1,9502026-02-06 HIGH 7.2 CVE-2026-2061 A vulnerability was determined in D-Link DIR-823X 250416. Affected by this issue is the function sub_424D20 of the file /goform/set_ipv6. Executing a… Dir 823x Firmware No fix yet Fix from $1,9502026-02-06 HIGH 7.2 CVE-2026-2000EPSS 17% A vulnerability was found in DCN DCME-320 up to 20260121. Impacted is the function apply_config of the file /function/system/basic/bridge_cfg.php of … Dcme 320 Firmware after 20260121 Fix from $1,9502026-02-06 CRITICAL 9.8 CVE-2025-59818 This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file. Tcis 3 Firmware 9.2.3.3+ Fix from $2,3002026-02-04 HIGH 7.3 CVE-2026-1802 A security flaw has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function macAddrClone of the file luci\controller\api\zrMac… Mitigation only Fix from $1,9502026-02-03 HIGH 8.1 CVE-2025-24293 # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transfo… Mitigation only Fix from $1,9502026-01-30 HIGH 7.3 CVE-2026-1689 A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function checkUserFromLanOrWan of the fil… Hg10 Firmware No fix yet Fix from $1,9502026-01-30 HIGH 7.3 CVE-2026-1687 A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. Impacted is an unknown function of the file /boaform/formSamba of t… Hg10 Firmware No fix yet Fix from $1,9502026-01-30 HIGH 7.2 CVE-2026-22623 Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can execute arbitrary commands o… Mitigation only Fix from $1,9502026-01-30 CRITICAL 9.5 CVE-2025-26385 Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability… Mitigation only Fix from $2,3002026-01-30 HIGH 8.8 CVE-2026-1638 A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZSetCfg of the file /goform/mD… Ac21 Firmware Mitigation only Fix from $1,9502026-01-30 HIGH 7.8 CVE-2026-24905 Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig… Inspektor Gadget 0.48.1+ Fix from $1,9502026-01-29 HIGH 8.8 CVE-2026-1625 A vulnerability was detected in D-Link DWR-M961 1.1.47. The impacted element is the function sub_4250E0 of the file /boafrm/formSmsManage of the comp… Dwr M961 Firmware Mitigation only Fix from $1,9502026-01-29 HIGH 8.8 CVE-2026-1624 A security vulnerability has been detected in D-Link DWR-M961 1.1.47. The affected element is an unknown function of the file /boafrm/formLtefotaUpgr… Dwr M961 Firmware Mitigation only Fix from $1,9502026-01-29 MEDIUM 6.3 CVE-2026-1623 A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulati… A7000r Firmware No fix yet Fix from $1,6002026-01-29 MEDIUM 6.3 CVE-2026-1601 A weakness has been identified in Totolink A7000R 4.1cu.4154. The impacted element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi… A7000r Firmware No fix yet Fix from $1,6002026-01-29 HIGH 8.8 CVE-2026-1596 A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. Th… Dwr M961 Firmware Mitigation only Fix from $1,9502026-01-29 HIGH 8.8 CVE-2026-1548 A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. This man… A7000r Firmware No fix yet Fix from $1,9502026-01-28 HIGH 8.8 CVE-2026-1544 A security flaw has been discovered in D-Link DIR-823X 250416. Impacted is the function sub_41E2A0 of the file /goform/set_mode. Performing a manipul… Dir 823x Firmware No fix yet Fix from $1,9502026-01-28 CRITICAL 9.8 CVE-2026-1547 A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipul… A7000r Firmware Mitigation only Fix from $2,3002026-01-28 HIGH 7.7 CVE-2022-40619 FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devi… Rbr20 Firmware 1.0.5.42 / 1.0.11.134+ Fix from $1,9502026-01-28 HIGH 8.8 CVE-2026-24685 OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability … Openproject 16.6.6 / 17.0.2+ Fix from $1,9502026-01-28 HIGH 7.2 CVE-2026-1506EPSS 5% A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php of the component MAC Filter Co… Dir 615 Firmware No fix yet Fix from $1,9502026-01-28 HIGH 7.2 CVE-2026-1505 A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes.php of the component URL Fil… Dir 615 Firmware No fix yet Fix from $1,9502026-01-28 HIGH 7.2 CVE-2026-1448EPSS 5% A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component We… Dir 615 Firmware after 4.10 Fix from $1,9502026-01-27 HIGH 8.8 CVE-2025-14756 Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to e… Archer Mr600 Firmware 1.1.0+ Fix from $1,9502026-01-26 CRITICAL 9.9 CVE-2016-15057 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum… Continuum Mitigation only Fix from $2,3002026-01-26 HIGH 7.2 CVE-2026-1419EPSS 15% A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode of the component Web Form Hand… Dcs 700l Firmware No fix yet Fix from $1,9502026-01-26 CRITICAL 9.8 CVE-2026-1414 A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This impacts the function getInformation… Operation And Maintenance Security Management System after 3.0.12 Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2026-1413 A vulnerability was found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function portValidate of the… Operation And Maintenance Security Management System after 3.0.12 Fix from $2,3002026-01-26