Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 7.3 CVE-2025-1448 A vulnerability was found in Synway SMG Gateway Management Software up to 20250204. It has been rated as critical. This issue affects some unknown pr… Mitigation only Fix from $1,9502025-02-19 MEDIUM 5.3 CVE-2025-1370 A vulnerability, which was classified as critical, has been found in MicroWorld eScan Antivirus 7.0.32 on Linux. Affected by this issue is the functi… Escan Anti Virus No fix yet Fix from $1,6002025-02-17 HIGH 8.8 CVE-2025-1339 A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been rated as critical. This issue affects the function setL2tpdConfig of th… X18 Firmware Mitigation only Fix from $1,9502025-02-16 HIGH 7.3 CVE-2025-1338EPSS 51% A vulnerability was found in NUUO Camera up to 20250203. It has been declared as critical. This vulnerability affects the function print_file of the … Mitigation only Fix from $1,9502025-02-16 HIGH 8.8 CVE-2025-0593 The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by using lower-level functions to interact with the dev… Mitigation only Fix from $1,9502025-02-14 CRITICAL 9.9 CVE-2025-22630 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Marketing Fire Widget Options widget-options all… Mitigation only Fix from $2,3002025-02-14 HIGH 7.2 CVE-2025-22962 A critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters when deb… Mitigation only Fix from $1,9502025-02-13 CRITICAL 9.8 CVE-2025-24861 An attacker may inject commands via specially-crafted post requests. Mojave Inverter Oghi8048a Firmware No fix yet Fix from $2,3002025-02-13 MEDIUM 6.3 CVE-2025-1229 A vulnerability classified as critical was found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378ddd6. Affected by this vulnerability … Mitigation only Fix from $1,6002025-02-12 HIGH 7.2 CVE-2025-25743 D-Link DIR-853 A1 FW1.20B07 was discovered to contain a command injection vulnerability in the SetVirtualServerSettings module. Dir 853 Firmware No fix yet Fix from $1,9502025-02-12 HIGH 7.8 CVE-2024-12251 In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperli… Telerik Ui For Winui 3.0.0+ Fix from $1,9502025-02-12 HIGH 7.9 CVE-2024-33469 An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate method of Da… Mitigation only Fix from $1,9502025-02-11 HIGH 7.3 CVE-2025-23094 The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R… Mitigation only Fix from $1,9502025-02-06 CRITICAL 9.4 CVE-2023-5878 Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a co… Mitigation only Fix from $2,3002025-02-06 HIGH 8.7 CVE-2025-23239 When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisc… Big Ip Access Policy Manager Mitigation only Fix from $1,9502025-02-05 HIGH 7.2 CVE-2025-20184 A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could a… Asyncos Mitigation only Fix from $1,9502025-02-05 CRITICAL 9.8 CVE-2024-55062 Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to … Co2scope after 8.6.0 Fix from $2,3002025-01-31 HIGH 8.8 CVE-2024-23971 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. … Home Flex Nema 14 50 Plug Firmware Mitigation only Fix from $1,9502025-01-31 MEDIUM 6.5 CVE-2024-53615 A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attacke… Mitigation only Fix from $1,6002025-01-30 HIGH 8.1 CVE-2025-0798EPSS 7% A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of… Escan Anti Virus No fix yet Fix from $1,9502025-01-29 HIGH 8.8 CVE-2025-24150 A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copy… Safari 15.3 / 18.3+ Fix from $1,9502025-01-27 CRITICAL 10.0 CVE-2024-48841 Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older. Mitigation only Fix from $2,3002025-01-27 HIGH 8.8 CVE-2024-48419EPSS 5% Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be trigge… Br 6476ac Firmware No fix yet Fix from $1,9502025-01-27 CRITICAL 9.8 CVE-2024-57590 TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to… Tew 632brp Firmware Mitigation only Fix from $2,3002025-01-27 CRITICAL 9.6 CVE-2024-52325 ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection. Goat G1 2000 Firmware 1.2.120 / 1.36.187+ Fix from $2,3002025-01-23 HIGH 8.8 CVE-2025-23196 A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell co… Ambari 2.7.9+ Fix from $1,9502025-01-21 HIGH 8.0 CVE-2024-57536 Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status. E8450 Firmware No fix yet Fix from $1,9502025-01-21 HIGH 8.2 CVE-2024-57539 Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail. E8450 Firmware No fix yet Fix from $1,9502025-01-21 CRITICAL 9.1 CVE-2024-54794EPSS 13% The script input feature of SpagoBI 3.5.1 allows arbitrary code execution. Spagobi No fix yet Fix from $2,3002025-01-21 HIGH 8.1 CVE-2024-57036 TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability a… A810r Firmware No fix yet Fix from $1,9502025-01-21