Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Arubaos HIGH 7.2
CVE-2025-37171

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Su…

Fix: 8.10.0.21 / 8.13.1.1+
Fix from $1,950 2026-01-13
Arubaos HIGH 7.2
CVE-2025-37172

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Su…

Fix: 8.10.0.21 / 8.13.1.1+
Fix from $1,950 2026-01-13
Arubaos HIGH 7.2
CVE-2025-37170

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Su…

Fix: 8.10.0.21 / 8.13.1.1+
Fix from $1,950 2026-01-13
Dreamweaver HIGH 8.6
CVE-2026-21267

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec…

Fix: 21.7+
Fix from $1,950 2026-01-13
Fortisiem CRITICAL 9.8
CVE-2025-64155EPSS 43%

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.…

Fix: 7.1.9 / 7.2.7+
Fix from $2,300 2026-01-13
Connection Manager For Objectscale* MEDIUM 6.8
CVE-2025-13447EPSS 26%

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” pe…

Fix: 7.1.35.15 / 7.2.54.16+
Fix from $1,600 2026-01-13
Connection Manager For Objectscale MEDIUM 6.8
CVE-2025-13444EPSS 26%

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” pe…

Fix: 7.1.35.15 / 7.2.54.16+
Fix from $1,600 2026-01-13
Unclassified HIGH 8.4
CVE-2026-0507

Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrati…

Mitigation only
Fix from $1,950 2026-01-13
Tinyweb CRITICAL 9.8
CVE-2026-22781

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via …

Fix: 1.98+
Fix from $2,300 2026-01-12
Unclassified HIGH 8.8
CVE-2026-0855

Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitra…

Mitigation only
Fix from $1,950 2026-01-12
Unclassified HIGH 8.8
CVE-2026-0854

Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary…

Mitigation only
Fix from $1,950 2026-01-12
Dx Netops Spectrum CRITICAL 9.8
CVE-2025-69269

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, L…

Fix: 23.3.7+
Fix from $2,300 2026-01-12
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2025-15502EPSS 6%

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionContro…

Fix: after 3.0.8
Fix from $2,300 2026-01-10
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2025-15501EPSS 6%

A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of th…

Fix: after 3.0.8
Fix from $2,300 2026-01-09
Operation And Maintenance Management System CRITICAL 9.8
CVE-2025-15500EPSS 6%

A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file …

Fix: after 3.0.8
Fix from $2,300 2026-01-09
Operation And Maintenance Management System CRITICAL 9.8
CVE-2025-15499EPSS 5%

A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN o…

Fix: after 3.0.8
Fix from $2,300 2026-01-09
Kiro Ide HIGH 7.8
CVE-2026-0830

Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE b…

Fix: 0.6.18+
Fix from $1,950 2026-01-09
Data Domain Operating System HIGH 7.2
CVE-2025-46645

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version …

Fix: 7.10.1.80 / 7.13.1.50+
Fix from $1,950 2026-01-09
Data Domain Operating System MEDIUM 6.7
CVE-2025-46644

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version …

Fix: 7.10.1.80 / 7.13.1.50+
Fix from $1,600 2026-01-09
Ip7137 Firmware HIGH 7.2
CVE-2025-66052

Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" …

Mitigation only
Fix from $1,950 2026-01-09
Tcis 3 Firmware HIGH 8.8
CVE-2025-64091

This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.

Fix: 9.2.3.3+
Fix from $1,950 2026-01-09
Greenshot HIGH 7.3
CVE-2026-22035

Greenshot is an open source Windows screenshot utility. Versions 1.3.310 and below arvulnerable to OS Command Injection through unsanitized filename …

Fix: 1.3.311+
Fix from $1,950 2026-01-08
Unclassified HIGH 8.8
CVE-2019-25289

SmartLiving SmartLAN <=6.x contains an authenticated remote command injection vulnerability in the web.cgi binary through the 'par' POST parameter wi…

No fix yet
Fix from $1,950 2026-01-08
Unclassified HIGH 8.8
CVE-2017-20215EPSS 14%

FLIR Thermal Camera FC-S/PT firmware version 8.0.0.64 contains an authenticated OS command injection vulnerability that allows attackers to execute s…

No fix yet
Fix from $1,950 2026-01-08
Unclassified CRITICAL 9.8
CVE-2017-20216EPSS 11%

FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerF…

Mitigation only
Fix from $2,300 2026-01-08
Pnpm HIGH 7.8
CVE-2025-69262

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .np…

Fix: 10.27.0+
Fix from $1,950 2026-01-07
Unclassified MEDIUM 6.9
CVE-2025-6225

Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to shell command injection via logi…

Mitigation only
Fix from $1,600 2026-01-07
Tew 811dru Firmware HIGH 7.2
CVE-2025-15472EPSS 20%

A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL  of the file uapply.cgi of the component httpd . This ma…

No fix yet
Fix from $1,950 2026-01-07
Tew 713re Firmware CRITICAL 9.8
CVE-2025-15471EPSS 12%

A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation…

Mitigation only
Fix from $2,300 2026-01-07
Unclassified HIGH 8.8
CVE-2020-36910

Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers …

No fix yet
Fix from $1,950 2026-01-06