Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 7.2 CVE-2025-29516 D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the backup function. Dsl 7740c Firmware No fix yet Fix from $1,9502025-08-25 MEDIUM 6.8 CVE-2025-29517 D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the traceroute6 function. Dsl 7740c Firmware No fix yet Fix from $1,6002025-08-25 CRITICAL 9.8 CVE-2025-9387EPSS 9% A vulnerability was found in DCN DCME-720 9.1.5.11. This affects an unknown function of the file /usr/local/www/function/audit/newstatistics/ip_block… Dcme 720 Firmware Mitigation only Fix from $2,3002025-08-24 CRITICAL 9.8 CVE-2025-55637 Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a command injection vulnerabili… Smart 2k\+ Plug In Wi Fi Video Doorbell With Chime Firmware Mitigation only Fix from $2,3002025-08-22 CRITICAL 9.8 CVE-2025-57105 The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the device. The sub_478D28 functi… Di 7400g\+ Firmware Mitigation only Fix from $2,3002025-08-22 HIGH 8.7 CVE-2025-41451 Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Series prior to … Mitigation only Fix from $1,9502025-08-22 HIGH 7.5 CVE-2025-48978 An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a malicious actor with access to E… Mitigation only Fix from $1,9502025-08-21 CRITICAL 9.8 CVE-2025-24285 Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with network a… Mitigation only Fix from $2,3002025-08-21 HIGH 8.1 CVE-2025-9262EPSS 5% A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/provider.js of the component o… Mcp Cli No fix yet Fix from $1,9502025-08-20 HIGH 8.8 CVE-2025-9244EPSS 8% A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/… Re6250 Firmware No fix yet Fix from $1,9502025-08-20 HIGH 7.8 CVE-2025-9176 A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment Var… Shc after 4.0.3 Fix from $1,9502025-08-20 HIGH 7.8 CVE-2025-9174 A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the function make of the file src/shc.c of the component Filen… Shc after 4.0.3 Fix from $1,9502025-08-19 MEDIUM 6.5 CVE-2025-52337 An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5.0.9.7000 allows attackers to… Mitigation only Fix from $1,6002025-08-19 HIGH 7.2 CVE-2025-50891 The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NO… No fix yet Fix from $1,9502025-08-19 CRITICAL 9.8 CVE-2025-55294 screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input i… Patch available Fix from $2,3002025-08-19 CRITICAL 9.8 CVE-2025-9149EPSS 6% A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This mani… Wl Nu516u1 Firmware Mitigation only Fix from $2,3002025-08-19 MEDIUM 6.5 CVE-2025-50461 A deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts/model_merger.py script when using the "fsdp" backend. … Mitigation only Fix from $1,6002025-08-19 MEDIUM 6.5 CVE-2025-55590 TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html. A3002r Firmware No fix yet Fix from $1,6002025-08-18 CRITICAL 9.8 CVE-2025-55591EPSS 7% TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoi… A3002r Firmware Mitigation only Fix from $2,3002025-08-18 HIGH 7.2 CVE-2025-55283 aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows elevation to superuse… Aiven Db Migrate 1.0.7+ Fix from $1,9502025-08-18 CRITICAL 9.8 CVE-2025-9090EPSS 14% A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet … Ac20 Firmware Mitigation only Fix from $2,3002025-08-17 CRITICAL 9.8 CVE-2025-9026 A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cgibin of the component Simple … Dir 860l Firmware Mitigation only Fix from $2,3002025-08-15 MEDIUM 6.5 CVE-2025-50515 An issue was discovered in phome Empirebak 2010 in ebak2008/upload/class/config.php allowing attackers to execute arbitrary code when the config file… Mitigation only Fix from $1,6002025-08-14 MEDIUM 5.4 CVE-2025-50817 A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the mod… Mitigation only Fix from $1,6002025-08-14 HIGH 8.8 CVE-2024-53945EPSS 19% The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An a… Mitigation only Fix from $1,9502025-08-14 HIGH 8.8 CVE-2025-8956EPSS 18% A vulnerability was found in D-Link DIR‑818L up to 1.05B01. This issue affects the function getenv of the file /htdocs/cgibin of the component ssdpcg… Dir 818l Firmware No fix yet Fix from $1,9502025-08-14 HIGH 8.8 CVE-2025-8937 A vulnerability has been found in TOTOLINK N350R 1.2.3-B20130826. This vulnerability affects unknown code of the file /boafrm/formSysCmd. The manipul… N350r Firmware Mitigation only Fix from $1,9502025-08-14 MEDIUM 6.5 CVE-2025-45317 A zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary code via a crafted ar… Hortusfox No fix yet Fix from $1,6002025-08-13 HIGH 7.8 CVE-2025-53773 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attack… Visual Studio 2022 17.14.12+ Fix from $1,9502025-08-12 HIGH 8.8 CVE-2025-8830EPSS 8% A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function su… Re6250 Firmware No fix yet Fix from $1,9502025-08-11