Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2025-70161EPSS 24% EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the … Br 6208ac Firmware Mitigation only Fix from $2,3002026-01-09 HIGH 8.8 CVE-2025-64090 This vulnerability allows authenticated attackers to execute commands via the hostname of the device. Tcis 3 Firmware 9.2.3.3+ Fix from $1,9502026-01-09 CRITICAL 9.8 CVE-2025-64093 Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device. Icx500 Firmware 1.4.3.3+ Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2026-0732EPSS 10% A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the ar… Di 8200g Firmware Mitigation only Fix from $2,3002026-01-09 HIGH 8.8 CVE-2026-21638 A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code exec… Ubb Xg Firmware 1.2.3 / 1.4.2+ Fix from $1,9502026-01-08 HIGH 8.8 CVE-2026-21639 A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code exec… Airmax Ac Firmware 1.2.3 / 2.6.8+ Fix from $1,9502026-01-08 CRITICAL 9.1 CVE-2025-59468 This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password paramet… Veeam Backup \& Replication 13.0.1.1071+ Fix from $2,3002026-01-08 CRITICAL 9.0 CVE-2025-59470 This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order para… Veeam Backup \& Replication 13.0.1.1071+ Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2025-55125 This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file. Veeam Backup \& Replication 13.0.1.1071+ Fix from $2,3002026-01-08 CRITICAL 9.1 CVE-2025-56425 An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.18… Enaio 10.10.0.183 / 11.0.0.183+ Fix from $2,3002026-01-08 HIGH 8.1 CVE-2025-67089 A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_packa… Gl Axt1800 Firmware No fix yet Fix from $1,9502026-01-08 CRITICAL 10.0 CVE-2025-61492 A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via… Terminal Controller Mcp Mitigation only Fix from $2,3002026-01-07 MEDIUM 6.5 CVE-2025-61489 A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplyin… Mcp Shell No fix yet Fix from $1,6002026-01-07 HIGH 7.2 CVE-2025-15472EPSS 20% A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL  of the file uapply.cgi of the component httpd . This ma… Tew 811dru Firmware No fix yet Fix from $1,9502026-01-07 CRITICAL 9.8 CVE-2025-15471EPSS 12% A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation… Tew 713re Firmware Mitigation only Fix from $2,3002026-01-07 HIGH 8.8 CVE-2026-0641 A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cst… Wa300 Firmware No fix yet Fix from $1,9502026-01-06 HIGH 8.8 CVE-2025-64424 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-be… Coolify 4.0.0+ Fix from $1,9502026-01-05 HIGH 8.8 CVE-2025-64419 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters comin… Coolify 4.0.0+ Fix from $1,9502026-01-05 CRITICAL 9.1 CVE-2025-67397 An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP request using a specific payload in… Passy Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.8 CVE-2026-0581EPSS 9% A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorMa… Ac1206 Firmware Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.8 CVE-2025-15391 A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP Request Handler. This manipul… Dir 806a Firmware Mitigation only Fix from $2,3002025-12-31 CRITICAL 9.8 CVE-2025-15357 A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?flag=cmd. The manipulation of th… Di 7400g\+ Firmware Mitigation only Fix from $2,3002025-12-30 HIGH 7.5 CVE-2025-69256 The Serverless Framework is a framework for using AWS Lambda and other managed cloud services to build applications. Starting in version 4.29.0 and p… Serverless 4.29.3+ Fix from $1,9502025-12-30 CRITICAL 9.8 CVE-2025-15257 A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formR… Br 6208ac Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-15256 A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /goform/formStaDrvSetup of the com… Br 6208ac Firmware Mitigation only Fix from $2,3002025-12-30 HIGH 8.8 CVE-2025-15254 A vulnerability was found in Tenda W6-S 1.0.0.4(510). This affects the function TendaAte of the file /goform/ate of the component ATE Service. Perfor… W6 S Firmware No fix yet Fix from $1,9502025-12-30 CRITICAL 9.8 CVE-2025-69201 Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtai… Tugtainer 1.15.1+ Fix from $2,3002025-12-29 HIGH 8.8 CVE-2025-15192 A security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_415328 of the file /boafrm/formL… Dwr M920 Firmware after 1.1.50 Fix from $1,9502025-12-29 HIGH 8.8 CVE-2025-15191 A weakness has been identified in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_4155B4 of the file /boafrm/formLtefotaUpgrad… Dwr M920 Firmware after 1.1.50 Fix from $1,9502025-12-29 HIGH 8.8 CVE-2025-15139EPSS 12% A vulnerability has been found in TRENDnet TEW-822DRE 1.00B21/1.01B06. This affects the function sub_43ACF4  of the file /boafrm/formWsc. Such manipu… Tew 822dre Firmware No fix yet Fix from $1,9502025-12-28