Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2025-15137EPSS 11% A vulnerability was detected in TRENDnet TEW-800MB 1.0.1.0. Affected by this vulnerability is the function sub_F934  of the file NTPSyncWithHost.cgi.… Tew 800mb Firmware No fix yet Fix from $1,9502025-12-28 HIGH 8.8 CVE-2025-15136EPSS 10% A security vulnerability has been detected in TRENDnet TEW-800MB 1.0.1.0. Affected is the function do_setWizard_asp of the file /goform/wizardset of … Tew 800mb Firmware No fix yet Fix from $1,9502025-12-28 HIGH 8.8 CVE-2025-15133EPSS 7% A vulnerability was identified in ZSPACE Z4Pro+ 1.0.0440024. The impacted element is the function zfilev2_api_CloseSafe of the file /v2/file/safe/clo… Z4pro\+ Firmware No fix yet Fix from $1,9502025-12-28 HIGH 8.8 CVE-2025-15132EPSS 7% A vulnerability was determined in ZSPACE Z4Pro+ 1.0.0440024. The affected element is the function zfilev2_api_open of the file /v2/file/safe/open of … Z4pro\+ Firmware after 1.0.0440024 Fix from $1,9502025-12-28 HIGH 8.8 CVE-2025-15131EPSS 7% A vulnerability was found in ZSPACE Z4Pro+ 1.0.0440024. Impacted is the function zfilev2_api_SafeStatus of the file /v2/file/safe/status of the compo… Z4pro\+ Firmware after 1.0.0440024 Fix from $1,9502025-12-28 HIGH 8.8 CVE-2025-66738 An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping func… Sip T21\(p\)e2 Firmware No fix yet Fix from $1,9502025-12-26 MEDIUM 5.1 CVE-2025-65885 An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight v6.7), No… Delight Custom Firmware Mitigation only Fix from $1,6002025-12-26 MEDIUM 6.3 CVE-2025-15081 A vulnerability has been found in JD Cloud BE6500 4.4.1.r4308. This issue affects the function sub_4780 of the file /jdcapi. Such manipulation of the… Mitigation only Fix from $1,6002025-12-25 CRITICAL 9.8 CVE-2025-15048EPSS 12% A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request… Wh450 Firmware Mitigation only Fix from $2,3002025-12-23 HIGH 8.4 CVE-2025-25364 A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to execute arbitra… Speedify after 15.0.0 Fix from $1,9502025-12-23 CRITICAL 9.8 CVE-2025-29228 Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter. E5600 Firmware Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-29229 linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus. E5600 Firmware Mitigation only Fix from $2,3002025-12-23 MEDIUM 6.5 CVE-2025-45493 Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function. Ex8000 Firmware Mitigation only Fix from $1,6002025-12-23 CRITICAL 9.8 CVE-2025-50526 Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function. Ex8000 Firmware Mitigation only Fix from $2,3002025-12-23 MEDIUM 6.5 CVE-2025-67436 Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell … Pluxml No fix yet Fix from $1,6002025-12-22 HIGH 7.2 CVE-2025-14884EPSS 11% A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the component Firmware Update Servic… Dir 605 Firmware No fix yet Fix from $1,9502025-12-18 HIGH 7.3 CVE-2025-68432 Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Language Server Protocol (LSP) … Zed 0.218.2+ Fix from $1,9502025-12-17 HIGH 7.3 CVE-2025-68433 Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Model Context Protocol (MCP) co… Zed 0.218.2+ Fix from $1,9502025-12-17 HIGH 7.8 CVE-2024-46060 Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. Duri… Anaconda3 2024.06-1+ Fix from $1,9502025-12-17 HIGH 7.8 CVE-2024-46062 Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. Dur… Miniconda3 23.11.0-1+ Fix from $1,9502025-12-17 MEDIUM 6.5 CVE-2025-55893 TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName. N200re Firmware No fix yet Fix from $1,6002025-12-15 MEDIUM 6.5 CVE-2025-55901 TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_time parameter. A3300r Firmware No fix yet Fix from $1,6002025-12-15 CRITICAL 9.8 CVE-2025-14707EPSS 19% A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the c… N3 Firmware after 2.0.25 Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2025-14706EPSS 19% A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/http_eshell_server of the compo… N3 Firmware after 2.0.25 Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2025-14705EPSS 17% A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESERVER Feature. This manipulati… N3 Firmware after 2.0.25 Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2025-14659 A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the component DHCP Daemon. The man… Dir 868l B1 Firmware after 203b03 Fix from $2,3002025-12-14 HIGH 7.2 CVE-2025-14648EPSS 7% A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown functionality of the file /src/admin/… Dedebiz after 6.5.9 Fix from $1,9502025-12-14 CRITICAL 9.8 CVE-2025-14586 A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecg… X5000r Firmware Mitigation only Fix from $2,3002025-12-13 CRITICAL 9.8 CVE-2025-67728 Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Publi… Fireshare 1.3.0+ Fix from $2,3002025-12-12 HIGH 8.4 CVE-2025-67508 gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. When using non‑POSIX shells suc… Gardenctl 2.12.0+ Fix from $1,9502025-12-12