Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
MEDIUM 6.5 CVE-2025-45619 An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction function Ptc310uv2 Firmware No fix yet Fix from $1,6002025-07-30 MEDIUM 6.5 CVE-2025-52284 Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the tz parameter. This … X6000r Firmware No fix yet Fix from $1,6002025-07-29 CRITICAL 9.8 CVE-2025-8259 A vulnerability was identified in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. Affected by this issue is the function execute_DataObjectProc of the file /gri… Vaelsys Mitigation only Fix from $2,3002025-07-28 CRITICAL 9.8 CVE-2025-8244 A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boaf… X15 Firmware Mitigation only Fix from $2,3002025-07-27 CRITICAL 9.1 CVE-2025-54416 tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In versio… Patch available Fix from $2,3002025-07-26 CRITICAL 9.4 CVE-2025-29628 A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobil… Mitigation only Fix from $2,3002025-07-25 HIGH 7.8 CVE-2025-54377 Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode does not validate line breaks … Roo Code 3.23.19+ Fix from $1,9502025-07-23 MEDIUM 6.5 CVE-2025-51472 Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via … Superagi Patch available Fix from $1,6002025-07-22 MEDIUM 6.5 CVE-2025-51459 File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via … Db Gpt Patch available Fix from $1,6002025-07-22 HIGH 8.8 CVE-2025-7952EPSS 16% A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. This vulnerability affects the function ckeckKeepAlive of the file wirel… T6 Firmware No fix yet Fix from $1,9502025-07-22 HIGH 7.5 CVE-2025-53832EPSS 8% Lara Translate MCP Server is a Model Context Protocol (MCP) Server for Lara Translate API. Versions 0.0.11 and below contain a command injection vuln… Patch available Fix from $1,9502025-07-21 HIGH 8.8 CVE-2025-7932EPSS 5% A vulnerability classified as critical has been found in D-Link DIR‑817L up to 1.04B01. This affects the function lxmldbc_system of the file ssdpcgi.… Dir 817l Firmware 1.04b01+ Fix from $1,9502025-07-21 CRITICAL 9.1 CVE-2025-46122 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `… Ruckus Unleashed 10.5.1.0.279 / 200.15.6.212.14+ Fix from $2,3002025-07-21 HIGH 7.8 CVE-2025-7883 A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41. Affected is an unknown function of the file \AiStoneS… Control Center Mitigation only Fix from $1,9502025-07-20 HIGH 8.8 CVE-2025-7836EPSS 6% A vulnerability has been found in D-Link DIR-816L up to 2.06B01 and classified as critical. Affected by this vulnerability is the function lxmldbc_sy… Dir 816l Firmware 2.06b01+ Fix from $1,9502025-07-19 HIGH 7.5 CVE-2025-54073EPSS 8% mcp-package-docs is an MCP (Model Context Protocol) server that provides LLMs with efficient access to package documentation across multiple programm… Patch available Fix from $1,9502025-07-18 HIGH 8.8 CVE-2025-7788EPSS 5% A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability is the function commandJobHa… Xxl Job after 3.1.1 Fix from $1,9502025-07-18 CRITICAL 9.8 CVE-2025-52046EPSS 5% Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc parame… A3300r Firmware Mitigation only Fix from $2,3002025-07-17 HIGH 8.8 CVE-2023-47356 Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via the log_type parameter at /log/… Mitigation only Fix from $1,9502025-07-17 CRITICAL 9.8 CVE-2025-52688EPSS 24% Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading… No fix yet Fix from $2,3002025-07-16 HIGH 8.1 CVE-2025-52690EPSS 10% Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially leading to the loss of confid… Mitigation only Fix from $1,9502025-07-16 CRITICAL 9.8 CVE-2025-49834 GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webu… Gpt Sovits Webui after 20250228v3 Fix from $2,3002025-07-15 CRITICAL 9.8 CVE-2025-49835 GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webu… Gpt Sovits Webui after 20250228v3 Fix from $2,3002025-07-15 CRITICAL 9.8 CVE-2025-49836 GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webu… Gpt Sovits Webui after 20250228v3 Fix from $2,3002025-07-15 CRITICAL 9.8 CVE-2025-49833 GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in the … Gpt Sovits Webui after 20250228v3 Fix from $2,3002025-07-15 MEDIUM 5.4 CVE-2025-52377EPSS 9% Command injection vulnerability in Nexxt Solutions NCM-X1800 Mesh Router versions UV1.2.7 and below, allowing authenticated attackers to execute arbi… Mitigation only Fix from $1,6002025-07-15 CRITICAL 9.6 CVE-2025-3621 Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.  * vulnerabilit… Mitigation only Fix from $2,3002025-07-15 MEDIUM 5.6 CVE-2025-51650 An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary code via up… Foxcms after 1.2.6 Fix from $1,6002025-07-14 HIGH 8.8 CVE-2025-7615 A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. Affected by this vulnerability is the function clearPairCfg of the file … T6 Firmware No fix yet Fix from $1,9502025-07-14 HIGH 8.8 CVE-2025-7613 A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been rated as critical. This issue affects the function CloudSrvVersionCheck of the file… T6 Firmware No fix yet Fix from $1,9502025-07-14