Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
MEDIUM 6.5 CVE-2025-56799 Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. N… Reolink No fix yet Fix from $1,6002025-10-21 MEDIUM 6.1 CVE-2025-57521 Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The application loa… Mitigation only Fix from $1,6002025-10-21 HIGH 8.8 CVE-2025-10020 Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script compone… Manageengine Admanager Plus 8.0+ Fix from $1,9502025-10-21 MEDIUM 6.9 CVE-2025-62696 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Foundation Mediawiki Foundation - … Mitigation only Fix from $1,6002025-10-21 MEDIUM 6.5 CVE-2025-57164 Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field. Flowise No fix yet Fix from $1,6002025-10-17 MEDIUM 5.1 CVE-2025-60855 Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious f… Mitigation only Fix from $1,6002025-10-16 MEDIUM 6.5 CVE-2025-61514 An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploading a craft… Patch available Fix from $1,6002025-10-16 MEDIUM 6.5 CVE-2025-58132 Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access. Meeting Software Development Kit 6.3.15 / 6.4.13+ Fix from $1,6002025-10-15 CRITICAL 9.9 CVE-2025-34267EPSS 6% Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node … Flowise 3.0.8+ Fix from $2,3002025-10-14 HIGH 7.2 CVE-2025-37146 A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to … Mitigation only Fix from $1,9502025-10-14 HIGH 7.2 CVE-2025-37134 An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful expl… Arubaos 8.10.0.19 / 8.12.0.6+ Fix from $1,9502025-10-14 MEDIUM 6.2 CVE-2025-37138 An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor op… Arubaos 8.10.0.19 / 8.12.0.6+ Fix from $1,6002025-10-14 HIGH 7.2 CVE-2025-37133 An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful expl… Arubaos 8.10.0.19 / 8.12.0.6+ Fix from $1,9502025-10-14 CRITICAL 9.8 CVE-2025-11665EPSS 7% A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Updat… Dap 2695 Firmware Mitigation only Fix from $2,3002025-10-13 MEDIUM 6.5 CVE-2025-60838 An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file. Mcms after 6.0.1 Fix from $1,6002025-10-10 MEDIUM 6.5 CVE-2025-60268 An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/c… Jeewms No fix yet Fix from $1,6002025-10-10 CRITICAL 9.3 CVE-2025-59286 Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio… 365 Copilot Chat Mitigation only Fix from $2,3002025-10-09 CRITICAL 9.3 CVE-2025-59252 Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio… 365 Word Copilot Mitigation only Fix from $2,3002025-10-09 CRITICAL 9.3 CVE-2025-59272 Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information… 365 Copilot Chat Mitigation only Fix from $2,3002025-10-09 MEDIUM 6.5 CVE-2025-56426 An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calcul… Bagisto No fix yet Fix from $1,6002025-10-09 HIGH 8.8 CVE-2025-11523 A vulnerability was detected in Tenda AC7 15.03.06.44. This vulnerability affects unknown code of the file /goform/AdvSetLanip. The manipulation of t… Ac7 Firmware No fix yet Fix from $1,9502025-10-09 CRITICAL 9.8 CVE-2025-11491 A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/comma… Desktopcommandermcp after 0.2.13 Fix from $2,3002025-10-08 CRITICAL 9.8 CVE-2025-11490 A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file … Desktopcommandermcp after 0.2.13 Fix from $2,3002025-10-08 HIGH 7.3 CVE-2025-11488 A weakness has been identified in D-Link DIR-852 up to 20251002. This affects an unknown part of the file /HNAP1/. Executing manipulation can lead to… Mitigation only Fix from $1,9502025-10-08 HIGH 8.1 CVE-2025-61787 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Win… Deno 2.5.3+ Fix from $1,9502025-10-08 CRITICAL 9.8 CVE-2025-11407 A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of the file /upgrade_filter.asp. This manipulation … Di 7001mini 8g Firmware Mitigation only Fix from $2,3002025-10-07 HIGH 7.2 CVE-2025-11335 A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected by this vulnerability is the function sub_46409C of the file /msp_info.… Di 7100g C1 Firmware Mitigation only Fix from $1,9502025-10-06 HIGH 7.2 CVE-2025-11331EPSS 17% A vulnerability was found in IdeaCMS up to 1.8. The impacted element is an unknown function of the file app/common/logic/admin/Config.php of the comp… Ideacms after 1.8 Fix from $1,9502025-10-06 HIGH 8.8 CVE-2025-11303EPSS 7% A vulnerability was detected in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/mp. Performing a manipulation of the argu… F9k1015 Firmware No fix yet Fix from $1,9502025-10-05 HIGH 8.8 CVE-2025-11298EPSS 7% A vulnerability was determined in Belkin F9K1015 1.00.10. Impacted is an unknown function of the file /goform/formSetWanStatic. Executing a manipulat… F9k1015 Firmware No fix yet Fix from $1,9502025-10-05