Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
MEDIUM 6.5 CVE-2025-60676 An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetN… Dir 878 Firmware No fix yet Fix from $1,6002025-11-13 HIGH 8.8 CVE-2025-63406 An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and… Group Office 6.8.136 / 25.0.47+ Fix from $1,9502025-11-13 MEDIUM 6.5 CVE-2025-60700 A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The … Dir 882 Firmware No fix yet Fix from $1,6002025-11-13 MEDIUM 6.5 CVE-2025-60701 A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_43… Dir 882 Firmware No fix yet Fix from $1,6002025-11-13 HIGH 7.3 CVE-2025-60697 A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_44… Dir 882 Firmware No fix yet Fix from $1,9502025-11-13 HIGH 7.3 CVE-2025-60698 A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_43… Dir 882 Firmware No fix yet Fix from $1,9502025-11-13 MEDIUM 5.4 CVE-2025-60671 A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binarie… Dir 823g Firmware No fix yet Fix from $1,6002025-11-13 MEDIUM 6.5 CVE-2025-60682 A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifical… A720r Firmware No fix yet Fix from $1,6002025-11-13 MEDIUM 6.5 CVE-2025-60683 A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specifically in the … A720r Firmware No fix yet Fix from $1,6002025-11-13 MEDIUM 6.5 CVE-2025-60687EPSS 7% An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130 within the cstecgi.cgi bina… Lr1200gb Firmware No fix yet Fix from $1,6002025-11-13 MEDIUM 5.4 CVE-2025-60689EPSS 8% An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v… E1200 Firmware No fix yet Fix from $1,6002025-11-13 HIGH 8.8 CVE-2025-46427 Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Inject… Smartfabric Os10 10.6.1.0+ Fix from $1,9502025-11-12 HIGH 8.8 CVE-2025-46428 Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injec… Smartfabric Os10 10.6.1.0+ Fix from $1,9502025-11-12 HIGH 8.8 CVE-2025-62222 Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthoriz… Github Copilot Chat 0.32.5+ Fix from $1,9502025-11-11 MEDIUM 6.7 CVE-2025-62214 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code lo… Visual Studio 2022 17.14.17+ Fix from $1,6002025-11-11 HIGH 7.7 CVE-2024-57695 An issue in Agnitum Outpost Security Suite 7.5.3 (3942.608.1810) and 7.6 (3984.693.1842) allows a local attacker to execute arbitrary code via the lo… Outpost Security Suite No fix yet Fix from $1,9502025-11-11 HIGH 8.8 CVE-2025-9223 Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the impro… Mitigation only Fix from $1,9502025-11-11 MEDIUM 6.5 CVE-2025-63296 KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: during startup… Kerui K259 Firmware No fix yet Fix from $1,6002025-11-10 HIGH 7.1 CVE-2025-12155 A Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows an attacker with Developer p… Mitigation only Fix from $1,9502025-11-10 CRITICAL 9.8 CVE-2025-12916EPSS 5% A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort… Operation And Maintenance Security Management System 3.0.11+ Fix from $2,3002025-11-09 MEDIUM 6.7 CVE-2025-46365 Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command … Cloudlink 8.1.1+ Fix from $1,6002025-11-05 MEDIUM 6.5 CVE-2024-51317 An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function Netsurf No fix yet Fix from $1,6002025-11-03 HIGH 7.5 CVE-2025-61141 sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes the EDITOR environment variab… Mitigation only Fix from $1,9502025-10-30 HIGH 8.2 CVE-2025-60595 SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution. No fix yet Fix from $1,9502025-10-29 MEDIUM 6.3 CVE-2025-1549 A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands… Mitigation only Fix from $1,6002025-10-29 CRITICAL 9.8 CVE-2025-12313 A vulnerability has been found in D-Link DI-7001 MINI 19.09.19A1/24.04.18B1. The affected element is an unknown function of the file /msp_info.htm. S… Di 7001mini 8g Firmware Mitigation only Fix from $2,3002025-10-27 CRITICAL 9.8 CVE-2025-12296EPSS 7% A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 of the component Firmware Upd… Dap 2695 Firmware Mitigation only Fix from $2,3002025-10-27 HIGH 8.2 CVE-2025-60801 jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function. Jsherp 2025-08-14+ Fix from $1,9502025-10-24 CRITICAL 9.9 CVE-2025-58428 The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remot… Mitigation only Fix from $2,3002025-10-23 HIGH 8.4 CVE-2025-54964 An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary execu… Socet Gxp 4.6.0.2+ Fix from $1,9502025-10-23