Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2025-66404 MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in th… Mcp Server Kubernetes 2.9.8+ Fix from $1,9502025-12-03 CRITICAL 9.8 CVE-2025-66032 Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible … Claude Code 1.0.93+ Fix from $2,3002025-12-03 HIGH 8.8 CVE-2025-57201EPSS 17% AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB… Dgm1104 Firmware No fix yet Fix from $1,9502025-12-03 HIGH 8.8 CVE-2025-57198 AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Mac… Dgm1104 Firmware No fix yet Fix from $1,9502025-12-03 HIGH 8.8 CVE-2025-57199 AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Net… Dgm1104 Firmware No fix yet Fix from $1,9502025-12-03 MEDIUM 6.5 CVE-2025-57200 AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the tes… Dgm1104 Firmware No fix yet Fix from $1,6002025-12-03 MEDIUM 6.5 CVE-2025-65657 FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote … Feehicms No fix yet Fix from $1,6002025-12-02 HIGH 8.8 CVE-2025-66399EPSS 11% Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configurati… Cacti 1.2.29+ Fix from $1,9502025-12-02 CRITICAL 9.8 CVE-2025-60854 A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in… R15 Firmware after 1.20.01 Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-13800EPSS 10% A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the file /send_order.cgi. The ma… B Qe2w401 Firmware after 250814-r037c Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-13797EPSS 7% A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifimac of the file /send_order.cg… B Qe2w401 Firmware after 250814-r037c Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-13798EPSS 7% A flaw has been found in ADSLR NBR1005GPEV2 250814-r037c. This affects the function ap_macfilter_add of the file /send_order.cgi. Executing manipulat… B Qe2w401 Firmware after 250814-r037c Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-13799EPSS 10% A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_del of the file /send_order.c… B Qe2w401 Firmware after 250814-r037c Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-66219 willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability i… Willitmerge after 0.2.1 Fix from $2,3002025-11-29 MEDIUM 6.8 CVE-2025-63674 An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootlo… A31c Firmware No fix yet Fix from $1,6002025-11-24 HIGH 8.5 CVE-2025-11921 iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue a… Mitigation only Fix from $1,9502025-11-24 CRITICAL 9.8 CVE-2025-13562EPSS 6% A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi. Such manipulation of the arg… Dir 852 Firmware Mitigation only Fix from $2,3002025-11-23 HIGH 8.1 CVE-2025-65946 Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possibl… Roo Code 3.26.7+ Fix from $1,9502025-11-21 CRITICAL 9.8 CVE-2025-13442EPSS 20% A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the function system of the file /go… 750w Firmware after 3.2.2-191225 Fix from $2,3002025-11-20 HIGH 8.8 CVE-2025-37162 A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack.… Arubaos 10.7.2.0+ Fix from $1,9502025-11-18 MEDIUM 6.5 CVE-2025-63749 pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter. Pnetlab No fix yet Fix from $1,6002025-11-18 HIGH 7.2 CVE-2025-37163 A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated at… Airwave 8.3.0.5+ Fix from $1,9502025-11-18 MEDIUM 6.5 CVE-2025-63258 A remote command execution (RCE) vulnerability was discovered in all H3C ERG3/ERG5 series routers and XiaoBei series routers, cloud gateways, and wir… Mitigation only Fix from $1,6002025-11-18 MEDIUM 6.5 CVE-2025-63604 A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code execution through insufficient input… Aws Resources Mcp Server No fix yet Fix from $1,6002025-11-18 MEDIUM 6.5 CVE-2025-63603 A command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) 0.1.6 in the safe_eval() func… Mcp Server For Data Exploration No fix yet Fix from $1,6002025-11-18 HIGH 8.8 CVE-2025-13306EPSS 8% A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /bo… Dwr M920 Firmware No fix yet Fix from $1,9502025-11-18 MEDIUM 6.5 CVE-2025-60702 A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The `setDiagn… A950rg Firmware No fix yet Fix from $1,6002025-11-13 MEDIUM 6.5 CVE-2025-60672 An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetD… Dir 878 Firmware No fix yet Fix from $1,6002025-11-13 MEDIUM 6.5 CVE-2025-60673 An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetD… Dir 878 Firmware No fix yet Fix from $1,6002025-11-13 MEDIUM 5.4 CVE-2025-60675 A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binarie… Dir 823g Firmware No fix yet Fix from $1,6002025-11-13