Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2025-10962EPSS 7% A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This impacts the function sub_403198 of the file /cgi-bin/wireless.cgi of the compon… Wl Nu516u1 Firmware No fix yet Fix from $1,9502025-09-25 HIGH 8.8 CVE-2025-10963EPSS 7% A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. Affected is the function sub_4016F0 of the file /cgi-bin/firewall.cgi. The mani… Wl Nu516u1 Firmware No fix yet Fix from $1,9502025-09-25 MEDIUM 6.5 CVE-2025-29155 An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint Swagger Petstore No fix yet Fix from $1,6002025-09-25 HIGH 8.8 CVE-2025-10959EPSS 7% A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. The affected element is the function sub_401778 of the file /cgi-bin/firewall.cgi. S… Wl Nu516u1 Firmware No fix yet Fix from $1,9502025-09-25 HIGH 8.8 CVE-2025-10960EPSS 7% A vulnerability was found in Wavlink NU516U1 M16U1_V240425. The impacted element is the function sub_402D1C of the file /cgi-bin/wireless.cgi of the … Wl Nu516u1 Firmware No fix yet Fix from $1,9502025-09-25 HIGH 8.0 CVE-2025-10961EPSS 8% A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. This affects the function sub_4030C0 of the file /cgi-bin/wireless.cgi of the compon… Wl Nu516u1 Firmware No fix yet Fix from $1,9502025-09-25 HIGH 8.8 CVE-2025-10958EPSS 7% A flaw has been found in Wavlink NU516U1 M16U1_V240425. Impacted is the function sub_403010 of the file /cgi-bin/wireless.cgi of the component AddMac… Wl Nu516u1 Firmware No fix yet Fix from $1,9502025-09-25 HIGH 8.8 CVE-2025-59831 git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection … Git Commiters 0.1.2+ Fix from $1,9502025-09-25 CRITICAL 9.8 CVE-2025-59834 ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server… Adb Mcp Server after 0.1.0 Fix from $2,3002025-09-25 HIGH 8.8 CVE-2025-20334 A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root privi… Mitigation only Fix from $1,9502025-09-24 MEDIUM 6.5 CVE-2025-45326 An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component. Pocketvj Control Panel Firmware Mitigation only Fix from $1,6002025-09-23 MEDIUM 6.5 CVE-2025-29083 SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Plugin_Manager.… Csz Cms No fix yet Fix from $1,6002025-09-23 HIGH 8.8 CVE-2025-10814EPSS 6% A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown functionality of the file /usr/s… Dir 823x Firmware No fix yet Fix from $1,9502025-09-22 HIGH 8.8 CVE-2025-57685 The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, BL-X26_AC8 v1.2.8, and BL-LTE3… Mitigation only Fix from $1,9502025-09-22 HIGH 8.8 CVE-2025-43953EPSS 7% In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or traceroute field on the TCP/IP … Mitigation only Fix from $1,9502025-09-22 HIGH 7.2 CVE-2025-10775EPSS 20% A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/logi… Wl Nu516u1 Firmware No fix yet Fix from $1,9502025-09-22 MEDIUM 6.1 CVE-2025-59689 KEV Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.… Email Security Gateway 5.0.31 / 5.1.20+ Fix from $1,6002025-09-19 MEDIUM 6.5 CVE-2025-57296 Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to the /goform… Ac6 Firmware No fix yet Fix from $1,6002025-09-19 CRITICAL 9.8 CVE-2025-10035 KEVEPSS 100% A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to… Goanywhere Managed File Transfer 7.6.3 / 7.8.4+ Fix from $2,3002025-09-18 HIGH 8.8 CVE-2025-57293 A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function in /usr/bi… Cf Xr11 Firmware No fix yet Fix from $1,9502025-09-18 CRITICAL 9.8 CVE-2025-10689 A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. Such manipulation of the… Dir 645 Firmware Mitigation only Fix from $2,3002025-09-18 MEDIUM 6.5 CVE-2025-55911 An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php and the file parameter Clipbucket 5.5.2-90+ Fix from $1,6002025-09-18 HIGH 8.4 CVE-2023-49565 The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sanitization of the HTTP Headers … Mitigation only Fix from $1,9502025-09-18 HIGH 8.8 CVE-2025-10634EPSS 7% A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead… Dir 823x Firmware No fix yet Fix from $1,9502025-09-18 HIGH 8.8 CVE-2025-10629EPSS 5% A vulnerability was determined in D-Link DIR-852 1.00CN B09. This issue affects the function ssdpcgi_main of the file htodcs/cgibin of the component … Dir 852 Firmware No fix yet Fix from $1,9502025-09-18 HIGH 8.8 CVE-2025-10628EPSS 9% A vulnerability was found in D-Link DIR-852 1.00CN B09. This vulnerability affects unknown code of the file /htdocs/cgibin/hedwig.cgi of the componen… Dir 852 Firmware No fix yet Fix from $1,9502025-09-18 MEDIUM 6.3 CVE-2025-10619 A vulnerability was detected in sequa-ai sequa-mcp up to 1.0.13. This affects the function redirectToAuthorization of the file src/helpers/node-oauth… Patch available Fix from $1,6002025-09-17 CRITICAL 9.8 CVE-2025-59458 In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243… Junie 243.284.50 / 251.284.50+ Fix from $2,3002025-09-17 HIGH 8.0 CVE-2025-56706 Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter in the openwrt_getConfig func… Br 6473ax Firmware No fix yet Fix from $1,9502025-09-16 CRITICAL 9.8 CVE-2025-52053 TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter… X6000r Firmware Mitigation only Fix from $2,3002025-09-15