Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
MEDIUM 5.3 CVE-2025-59376 feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g.,… Mcp Kubernetes Server after 0.1.11 Fix from $1,6002025-09-15 MEDIUM 6.3 CVE-2025-10441EPSS 12% A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the function sub_433F7C of the f… No fix yet Fix from $1,6002025-09-15 HIGH 8.8 CVE-2025-10442EPSS 8% A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manip… Ac9 Firmware No fix yet Fix from $1,9502025-09-15 MEDIUM 6.3 CVE-2025-10440EPSS 12% A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A1/19.12.10A1. Affected by thi… Mitigation only Fix from $1,6002025-09-15 HIGH 8.8 CVE-2025-10401EPSS 8% A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown function of the file /goform/diag_ping. Performing m… Dir 823x Firmware after 250416 Fix from $1,9502025-09-14 CRITICAL 9.8 CVE-2025-10359EPSS 6% A vulnerability was detected in Wavlink WL-WN578W2 221110. This impacts the function sub_404DBC of the file /cgi-bin/wireless.cgi. The manipulation o… Wl Wn578w2 Firmware Mitigation only Fix from $2,3002025-09-13 CRITICAL 9.8 CVE-2025-10358EPSS 6% A security vulnerability has been detected in Wavlink WL-WN578W2 221110. This affects the function sub_404850 of the file /cgi-bin/wireless.cgi. The … Wl Wn578w2 Firmware Mitigation only Fix from $2,3002025-09-13 CRITICAL 9.8 CVE-2025-10328EPSS 9% A security vulnerability has been detected in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file… Rpi Jukebox Rfid after 2.8.0 Fix from $2,3002025-09-12 CRITICAL 9.8 CVE-2025-10326EPSS 7% A security flaw has been discovered in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/api/playlist/single… Rpi Jukebox Rfid after 2.8.0 Fix from $2,3002025-09-12 CRITICAL 9.8 CVE-2025-10327EPSS 10% A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdo… Rpi Jukebox Rfid after 2.8.0 Fix from $2,3002025-09-12 CRITICAL 9.8 CVE-2025-10324EPSS 8% A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects the function sub_401C5C of the file firewall.cgi. This manipulation of the … Wl Wn578w2 Firmware Mitigation only Fix from $2,3002025-09-12 HIGH 8.8 CVE-2025-10325EPSS 7% A vulnerability was identified in Wavlink WL-WN578W2 221110. This impacts the function sub_401340/sub_401BA4 of the file /cgi-bin/login.cgi. Such man… Wl Wn578w2 Firmware No fix yet Fix from $1,9502025-09-12 CRITICAL 9.8 CVE-2025-10323EPSS 8% A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wizard_rep.shtml. The manipulati… Wl Wn578w2 Firmware Mitigation only Fix from $2,3002025-09-12 CRITICAL 9.3 CVE-2025-10364EPSS 6% The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on po… Mitigation only Fix from $2,3002025-09-12 MEDIUM 5.7 CVE-2025-27233 Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the sma… Mitigation only Fix from $1,6002025-09-12 CRITICAL 9.8 CVE-2025-55319 Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network. Visual Studio Code 1.104.0+ Fix from $2,3002025-09-12 HIGH 7.5 CVE-2025-56406 An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE… Mitigation only Fix from $1,9502025-09-10 CRITICAL 9.8 CVE-2025-59046 The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branch while it prompts for the br… Patch available Fix from $2,3002025-09-09 CRITICAL 9.8 CVE-2025-57633 A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute arbitrary OS commands. The /… Mitigation only Fix from $2,3002025-09-09 HIGH 8.8 CVE-2025-55227 Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges… Sql Server 2016 13.0.6470.1 / 13.0.7065.1+ Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-9161 A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito pl… Factorytalk Optix 1.6.0+ Fix from $1,9502025-09-09 CRITICAL 9.8 CVE-2025-10123 A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_sta… Dir 823x Firmware after 250416 Fix from $2,3002025-09-09 CRITICAL 9.8 CVE-2025-57285 codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates th… Codeceptjs Mitigation only Fix from $2,3002025-09-08 HIGH 8.4 CVE-2025-7388 It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject … Mitigation only Fix from $1,9502025-09-04 CRITICAL 9.8 CVE-2025-9934 A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performin… X5000r Firmware Mitigation only Fix from $2,3002025-09-04 CRITICAL 9.8 CVE-2025-9935 A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_4159F8 of the file /web_cste/cgi… N600r Firmware Mitigation only Fix from $2,3002025-09-04 HIGH 7.5 CVE-2025-58358 Markdownify is a Model Context Protocol server for converting almost anything to Markdown. Versions below 0.0.2 contain a command injection vulnerabi… Patch available Fix from $1,9502025-09-04 MEDIUM 6.5 CVE-2025-55824 ModStartCMS v9.5.0 has an arbitrary file write vulnerability, which allows attackers to write malicious files and execute malicious commands to obtai… Mostartcms No fix yet Fix from $1,6002025-09-02 MEDIUM 5.3 CVE-2025-55372 An arbitrary file upload vulnerability in Beakon Application before v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file. Beakon 5.4.3+ Fix from $1,6002025-09-02 MEDIUM 6.5 CVE-2025-50755 Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the command parameter. This vulnerabi… Wl Wn535k3 Firmware No fix yet Fix from $1,6002025-09-02