Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
MEDIUM 6.3 CVE-2025-4135 A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the function ui_get_input_value. The m… Wg302v2 Firmware after 5.2.9 Fix from $1,6002025-04-30 HIGH 8.8 CVE-2025-4122 A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been rated as critical. Affected by this issue is the function sub_435E04. The manip… Jwnr2000v2 Firmware Mitigation only Fix from $1,9502025-04-30 CRITICAL 9.8 CVE-2025-4121 A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been declared as critical. Affected by this vulnerability is the function cmd_wirele… Jwnr2000v2 Firmware Mitigation only Fix from $2,3002025-04-30 MEDIUM 5.3 CVE-2025-45010 A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. Thi… Park Ticketing Management System No fix yet Fix from $1,6002025-04-30 MEDIUM 5.3 CVE-2025-45011 A HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerabilit… Park Ticketing Management System No fix yet Fix from $1,6002025-04-30 MEDIUM 5.3 CVE-2025-45009 A HTML Injection vulnerability was discovered in the normal-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability a… Park Ticketing Management System No fix yet Fix from $1,6002025-04-30 MEDIUM 6.3 CVE-2025-4076EPSS 17% A vulnerability classified as critical has been found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function easy_uci_set_option_string_0 of th… No fix yet Fix from $1,6002025-04-29 MEDIUM 5.1 CVE-2025-4089 Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially… Firefox 138.0+ Fix from $1,6002025-04-29 HIGH 8.1 CVE-2025-4032 A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as critical. This issue affects the… Aworld after 2025-04-24 Fix from $1,9502025-04-28 HIGH 8.8 CVE-2025-3987EPSS 10% A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /… N150rt Firmware No fix yet Fix from $1,9502025-04-27 HIGH 7.2 CVE-2025-3983EPSS 14% A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown … Hibos No fix yet Fix from $1,9502025-04-27 CRITICAL 9.2 CVE-2025-43858 YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, a… Patch available Fix from $2,3002025-04-24 MEDIUM 6.5 CVE-2025-28017 TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter. A800r Firmware No fix yet Fix from $1,6002025-04-23 MEDIUM 6.5 CVE-2025-29743 D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting. Dir 816 Firmware No fix yet Fix from $1,6002025-04-22 HIGH 7.3 CVE-2025-43948 Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorti… Mitigation only Fix from $1,9502025-04-22 HIGH 7.3 CVE-2024-40445 A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by … Mimetex 1.77+ Fix from $1,9502025-04-22 HIGH 7.2 CVE-2025-3816EPSS 6% A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of the file /system/schedule/save… Cicadascms No fix yet Fix from $1,9502025-04-19 CRITICAL 9.8 CVE-2025-29209 TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub_41105C function of cstecgi .… X18 Firmware No fix yet Fix from $2,3002025-04-18 MEDIUM 6.3 CVE-2024-46089 74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin. 74cms 3.33.0+ Fix from $1,6002025-04-18 CRITICAL 9.8 CVE-2025-43012 In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible Toolbox 2.6+ Fix from $2,3002025-04-17 CRITICAL 9.8 CVE-2025-3729 A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affe… Web Based Pharmacy Product Management System No fix yet Fix from $2,3002025-04-16 HIGH 7.3 CVE-2024-53305 An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supplying a crafted search query. Whoogle Search Patch available Fix from $1,9502025-04-16 MEDIUM 5.1 CVE-2024-40070 Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=s… Online Id Generator System No fix yet Fix from $1,6002025-04-16 HIGH 7.3 CVE-2024-36842 An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220301, and Build Number Platfor… Mitigation only Fix from $1,9502025-04-15 MEDIUM 6.5 CVE-2025-28142EPSS 10% Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /… Br 6478ac V3 Firmware No fix yet Fix from $1,6002025-04-15 MEDIUM 6.5 CVE-2025-28143EPSS 9% Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at th… Br 6478ac V3 Firmware No fix yet Fix from $1,6002025-04-15 MEDIUM 6.5 CVE-2025-28145EPSS 10% Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafr… Br 6478ac V3 Firmware No fix yet Fix from $1,6002025-04-15 HIGH 8.0 CVE-2025-3545 A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as cri… Mitigation only Fix from $1,9502025-04-14 HIGH 8.0 CVE-2025-3546 A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as criti… Magic Nx15 Firmware after 100r014 Fix from $1,9502025-04-14 HIGH 8.0 CVE-2025-3544 A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. Th… Mitigation only Fix from $1,9502025-04-14