Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Datastage On Cloud Pak For Data HIGH 8.8
CVE-2025-13687

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o…

Fix: 5.3.1+
Fix from $1,950 2026-03-03
Datastage On Cloud Pak For Data HIGH 8.8
CVE-2025-13688

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o…

Fix: 5.3.1+
Fix from $1,950 2026-03-03
Datastage On Cloud Pak For Data HIGH 8.8
CVE-2025-13686

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o…

Fix: 5.3.1+
Fix from $1,950 2026-03-03
Easyweb HIGH 7.5
CVE-2024-55021

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.

Mitigation only
Fix from $1,950 2026-03-03
Easyweb CRITICAL 9.8
CVE-2024-55020

A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to…

Mitigation only
Fix from $2,300 2026-03-03
Tranzman HIGH 7.2
CVE-2025-67840

Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Build 14614 through TZM_175758806…

No fix yet
Fix from $1,950 2026-03-03
Tranzman HIGH 7.2
CVE-2025-63911

Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injection vulnerability.

No fix yet
Fix from $1,950 2026-03-03
Deco Be25 Firmware HIGH 8.0
CVE-2026-0654

Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. …

Fix: after 1.1.1
Fix from $1,950 2026-03-02
Ac15 Firmware CRITICAL 9.8
CVE-2026-24101

An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, …

Mitigation only
Fix from $2,300 2026-03-02
Chamilo Lms HIGH 7.2
CVE-2025-50194

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/cron/lang/check_parse_lang…

Fix: 1.11.30+
Fix from $1,950 2026-03-02
Chamilo Lms HIGH 7.2
CVE-2025-50195

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/manage.co…

Fix: 1.11.30+
Fix from $1,950 2026-03-02
Chamilo Lms HIGH 7.2
CVE-2025-50196

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/editinsta…

Fix: 1.11.30+
Fix from $1,950 2026-03-02
Chamilo Lms HIGH 7.2
CVE-2025-50197

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/admin/sub_language_ajax.in…

Fix: 1.11.30+
Fix from $1,950 2026-03-02
Chamilo Lms HIGH 7.2
CVE-2025-50193

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.ph…

Fix: 1.11.30+
Fix from $1,950 2026-03-02
Unclassified CRITICAL 9.4
CVE-2025-30044

In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-bin/CliniNET.prd/utils/userlo…

Mitigation only
Fix from $2,300 2026-03-02
Opendcim CRITICAL 9.8
CVE-2026-28517EPSS 6%

openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves …

Patch available
Fix from $2,300 2026-02-27
Wegia HIGH 7.2
CVE-2026-28409

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA …

Fix: 3.6.5+
Fix from $1,950 2026-02-27
Vim HIGH 7.8
CVE-2026-28417

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plug…

Fix: 9.2.0073+
Fix from $1,950 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21654

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum H…

Fix: after 10.22
Fix from $2,300 2026-02-27
Satellite HIGH 8.8
CVE-2026-0980

A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with …

Fix: after 0.12.1
Fix from $1,950 2026-02-27
N300rh Firmware CRITICAL 9.8
CVE-2026-3301

A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file …

Mitigation only
Fix from $2,300 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-25196

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-25721

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-3037

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-25037

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-25105

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code e…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-20764

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-23702

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-24452

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 500b Pro Firmware HIGH 8.8
CVE-2026-24695

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code ex…

Fix: after 1.12.1
Fix from $1,950 2026-02-27