Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
521g Firmware HIGH 7.2
CVE-2026-2188EPSS 6%

A vulnerability was determined in UTT 进取 521G 3.1.1-190816. The impacted element is the function sub_446B18 of the file /goform/formPdbUpConfig. Ex…

No fix yet
Fix from $1,950 2026-02-08
Certificate CRITICAL 9.8
CVE-2026-2184EPSS 10%

A vulnerability was detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This vulnerability aff…

Fix: after 2017-10-16
Fix from $2,300 2026-02-08
Dir 823x Firmware HIGH 7.2
CVE-2026-2175

A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420618 of the file /goform/set_upnp. This manip…

No fix yet
Fix from $1,950 2026-02-08
Wa300 Firmware HIGH 8.8
CVE-2026-2167

A vulnerability was detected in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setAPNetwork of the file /cgi-bin/cstecgi.c…

No fix yet
Fix from $1,950 2026-02-08
Dir 823x Firmware HIGH 7.2
CVE-2026-2157

A security vulnerability has been detected in D-Link DIR-823X 250416. This affects the function sub_4175CC of the file /goform/set_static_route_table…

No fix yet
Fix from $1,950 2026-02-08
Dir 823x Firmware HIGH 7.2
CVE-2026-2155

A security flaw has been discovered in D-Link DIR-823X 250416. The affected element is the function sub_4208A0 of the file /goform/set_dmz of the com…

No fix yet
Fix from $1,950 2026-02-08
Dir 615 Firmware HIGH 7.2
CVE-2026-2152

A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configurat…

No fix yet
Fix from $1,950 2026-02-08
Dir 615 Firmware HIGH 7.2
CVE-2026-2151

A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the component DMZ Host Feature. S…

No fix yet
Fix from $1,950 2026-02-08
Dir 823x Firmware HIGH 7.2
CVE-2026-2143

A security vulnerability has been detected in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/set_ddns of the …

No fix yet
Fix from $1,950 2026-02-08
Dir 823x Firmware HIGH 7.2
CVE-2026-2142EPSS 6%

A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420688 of the file /goform/set_qos. Executing a…

No fix yet
Fix from $1,950 2026-02-08
Harmonyos Mcp Server HIGH 8.8
CVE-2026-2131EPSS 15%

A vulnerability was identified in XixianLiang HarmonyOS-mcp-server 0.1.0. This vulnerability affects the function input_text. The manipulation of the…

No fix yet
Fix from $1,950 2026-02-08
Dir 823x Firmware HIGH 7.2
CVE-2026-2129

A vulnerability was found in D-Link DIR-823X 250416. Affected by this issue is some unknown functionality of the file /goform/set_ac_status. Performi…

No fix yet
Fix from $1,950 2026-02-08
Dir 823x Firmware HIGH 7.2
CVE-2026-2120

A vulnerability was identified in D-Link DIR-823X 250416. This affects an unknown function of the file /goform/set_server_settings of the component C…

No fix yet
Fix from $1,950 2026-02-08
G300 F Firmware HIGH 8.8
CVE-2026-25857

Tenda G300-F router firmware version 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetW…

Fix: after 16.01.14.2
Fix from $1,950 2026-02-07
Dir 823x Firmware HIGH 7.2
CVE-2026-2084

A weakness has been identified in D-Link DIR-823X 250416. This impacts an unknown function of the file /goform/set_language. Executing a manipulation…

No fix yet
Fix from $1,950 2026-02-07
Dir 823x Firmware HIGH 7.2
CVE-2026-2081EPSS 5%

A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_password. This manipula…

No fix yet
Fix from $1,950 2026-02-07
Dir 823x Firmware HIGH 7.2
CVE-2026-2082

A vulnerability was identified in D-Link DIR-823X 250416. The impacted element is an unknown function of the file /goform/set_mac_clone. Such manipul…

No fix yet
Fix from $1,950 2026-02-07
Openproject CRITICAL 9.9
CVE-2026-25763

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exis…

Fix: 16.6.7 / 17.0.3+
Fix from $2,300 2026-02-06
Privileged Remote Access CRITICAL 9.8
CVE-2026-1731 KEVEPSS 89%

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execut…

Fix: 25.1 / 25.3.2+
Fix from $2,300 2026-02-06
Openclaw HIGH 8.4
CVE-2026-25593

OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via conf…

Fix: 2026.1.20+
Fix from $1,950 2026-02-06
Frigate CRITICAL 9.1
CVE-2026-25643

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (…

Fix: 0.16.4+
Fix from $2,300 2026-02-06
Dir 823x Firmware HIGH 7.2
CVE-2026-2063

A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/set_ac_server of the compo…

No fix yet
Fix from $1,950 2026-02-06
Openstamanager HIGH 8.8
CVE-2025-69212

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vu…

Fix: after 2.9.8
Fix from $1,950 2026-02-06
Dir 823x Firmware HIGH 7.2
CVE-2026-2061

A vulnerability was determined in D-Link DIR-823X 250416. Affected by this issue is the function sub_424D20 of the file /goform/set_ipv6. Executing a…

No fix yet
Fix from $1,950 2026-02-06
Claude Code CRITICAL 9.1
CVE-2026-25722

Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory changes when combined with write op…

Fix: 2.0.57+
Fix from $2,300 2026-02-06
Claude Code MEDIUM 6.5
CVE-2026-25723

Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using piped sed operations with the …

Fix: 2.0.55+
Fix from $1,600 2026-02-06
Gogs CRITICAL 9.8
CVE-2025-64111

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to…

Fix: 0.13.4+
Fix from $2,300 2026-02-06
Ew 7438rpn Mini Firmware CRITICAL 9.8
CVE-2020-37125EPSS 6%

Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands thr…

Mitigation only
Fix from $2,300 2026-02-05
Unclassified CRITICAL 9.8
CVE-2020-37123

Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the ping and socket parameters. Atta…

Mitigation only
Fix from $2,300 2026-02-05
Unclassified HIGH 7.2
CVE-2025-11730

A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP series firmware versions from …

Mitigation only
Fix from $1,950 2026-02-05