Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2025-11292EPSS 7% A weakness has been identified in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/formBSSetSitesurvey. Executing a manipu… F9k1015 Firmware No fix yet Fix from $1,9502025-10-05 HIGH 8.8 CVE-2025-11285EPSS 8% A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the file src/controllers/serverC… Mcphub after 0.9.10 Fix from $1,9502025-10-05 CRITICAL 9.8 CVE-2025-59741 Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command… E Tms Mitigation only Fix from $2,3002025-10-02 CRITICAL 9.8 CVE-2025-59735 Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command… E Tms Mitigation only Fix from $2,3002025-10-02 CRITICAL 9.8 CVE-2025-59736 Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command… E Tms Mitigation only Fix from $2,3002025-10-02 CRITICAL 9.8 CVE-2025-59737 Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command… E Tms Mitigation only Fix from $2,3002025-10-02 CRITICAL 9.8 CVE-2025-59738 Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command… E Tms Mitigation only Fix from $2,3002025-10-02 CRITICAL 9.8 CVE-2025-59739 Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command… E Tms Mitigation only Fix from $2,3002025-10-02 CRITICAL 9.8 CVE-2025-59740 Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command… E Tms Mitigation only Fix from $2,3002025-10-02 MEDIUM 6.8 CVE-2025-59337 Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be embedded in a backup dump an… Discourse 3.5.1 / 3.6.0+ Fix from $1,6002025-10-01 CRITICAL 9.8 CVE-2025-61044 TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentC… X18 Firmware Mitigation only Fix from $2,3002025-10-01 CRITICAL 9.8 CVE-2025-61045 TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg fun… X18 Firmware Mitigation only Fix from $2,3002025-10-01 CRITICAL 9.3 CVE-2025-61584 serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 ha… Patch available Fix from $2,3002025-09-30 HIGH 8.5 CVE-2025-41250 VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to… Mitigation only Fix from $1,9502025-09-29 HIGH 8.8 CVE-2025-11138 A vulnerability was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation… Wenkucms No fix yet Fix from $1,9502025-09-29 HIGH 8.8 CVE-2025-11121 A security vulnerability has been detected in Tenda AC18 15.03.05.19. The impacted element is an unknown function of the file /goform/AdvSetLanip. Th… Ac18 Firmware No fix yet Fix from $1,9502025-09-28 HIGH 8.8 CVE-2025-11100 A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulatio… Dir 823x Firmware No fix yet Fix from $1,9502025-09-28 HIGH 8.8 CVE-2025-11098 A vulnerability was found in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_wifi_blacklists. The manipul… Dir 823x Firmware No fix yet Fix from $1,9502025-09-28 HIGH 8.8 CVE-2025-11099 A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_del of the file /goform/delete_prohibiting. This m… Dir 823x Firmware No fix yet Fix from $1,9502025-09-28 HIGH 8.8 CVE-2025-11097 A vulnerability has been found in D-Link DIR-823X 250416. Impacted is an unknown function of the file /goform/set_device_name. The manipulation of th… Dir 823x Firmware No fix yet Fix from $1,9502025-09-28 HIGH 8.8 CVE-2025-11096 A flaw has been found in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/diag_traceroute. Executing manipulati… Dir 823x Firmware No fix yet Fix from $1,9502025-09-28 HIGH 8.8 CVE-2025-11095 A vulnerability was detected in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/delete_offline_device. Performing… Dir 823x Firmware No fix yet Fix from $1,9502025-09-28 HIGH 8.8 CVE-2025-11092 A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_switch_settings. … Dir 823x Firmware No fix yet Fix from $1,9502025-09-28 HIGH 7.3 CVE-2025-11045 A vulnerability was identified in WAYOS LQ_04, LQ_05, LQ_06, LQ_07 and LQ_09 22.03.17. This affects an unknown function of the file /usb_paswd.asp. T… Mitigation only Fix from $1,9502025-09-26 HIGH 8.8 CVE-2025-55848 An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parame… Dir 823x Firmware No fix yet Fix from $1,9502025-09-26 MEDIUM 6.5 CVE-2025-56769 An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invoca… Hutool 5.8.40+ Fix from $1,6002025-09-25 HIGH 8.4 CVE-2025-59815 This vulnerability allows malicious actors to execute arbitrary commands on the underlying system of the Zenitel ICX500 and ICX510 Gateway, granting … Mitigation only Fix from $1,9502025-09-25 HIGH 8.4 CVE-2025-59817 This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, success… Mitigation only Fix from $1,9502025-09-25 HIGH 8.8 CVE-2025-10964EPSS 7% A weakness has been identified in Wavlink NU516U1. Affected by this vulnerability is the function sub_401B30 of the file /cgi-bin/firewall.cgi. This … Wl Nu516u1 Firmware No fix yet Fix from $1,9502025-09-25 MEDIUM 6.5 CVE-2025-29157 An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-… Swagger Petstore No fix yet Fix from $1,6002025-09-25