Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Coolify HIGH 8.8
CVE-2025-59156

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, a Remote Code …

Fix: 4.0.0+
Fix from $1,950 2026-01-05
Coolify HIGH 8.8
CVE-2025-59157

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Reposi…

Fix: 4.0.0+
Fix from $1,950 2026-01-05
Centreon Web HIGH 7.2
CVE-2025-5965EPSS 26%

In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neutralization of Speci…

Fix: 24.04.19 / 24.10.15+
Fix from $1,950 2026-01-05
Nplatform HIGH 8.8
CVE-2025-64124

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (M…

Fix: after 2.5.1
Fix from $1,950 2026-01-03
Nplatform HIGH 8.8
CVE-2025-64120

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (M…

Fix: 2.5.1+
Fix from $1,950 2026-01-02
Signal K Server HIGH 8.8
CVE-2025-66398EPSS 19%

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the in…

Fix: 2.19.0+
Fix from $1,950 2026-01-01
Ragflow HIGH 8.8
CVE-2025-68700

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login…

Fix: 0.23.0+
Fix from $1,950 2025-12-31
Gargoyle HIGH 8.8
CVE-2015-10145

Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The applic…

Fix: after 1.5.11
Fix from $1,950 2025-12-31
Unclassified HIGH 8.8
CVE-2021-47745

Cypress Solutions CTM-200 2.7.1 contains an authenticated command injection vulnerability in the firmware upgrade script that allows remote attackers…

No fix yet
Fix from $1,950 2025-12-31
Unclassified HIGH 8.8
CVE-2021-47747

meterN 1.2.3 contains an authenticated remote code execution vulnerability in admin_meter2.php and admin_indicator2.php scripts. Attackers can exploi…

No fix yet
Fix from $1,950 2025-12-31
Unclassified HIGH 8.8
CVE-2025-15389

VPN Firewall developed by QNO Technology has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS co…

Mitigation only
Fix from $1,950 2025-12-31
Unclassified HIGH 8.8
CVE-2025-15388

VPN Firewall developed by QNO Technology has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS co…

Mitigation only
Fix from $1,950 2025-12-31
Flamingo Xl Firmware CRITICAL 10.0
CVE-2024-58338

Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the trace…

Mitigation only
Fix from $2,300 2025-12-30
Impact Firmware HIGH 8.8
CVE-2022-50793

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attacker…

No fix yet
Fix from $1,950 2025-12-30
Impact Firmware CRITICAL 9.8
CVE-2022-50794

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers …

Mitigation only
Fix from $2,300 2025-12-30
Impact Firmware HIGH 7.8
CVE-2022-50795

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious …

No fix yet
Fix from $1,950 2025-12-30
Impact Firmware HIGH 7.8
CVE-2022-50789

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the…

No fix yet
Fix from $1,950 2025-12-30
Impact Firmware HIGH 7.8
CVE-2022-50791

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious …

No fix yet
Fix from $1,950 2025-12-30
Minidvblinux CRITICAL 9.8
CVE-2022-50691

MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root throug…

Mitigation only
Fix from $2,300 2025-12-30
W6 S Firmware HIGH 8.8
CVE-2025-15254

A vulnerability was found in Tenda W6-S 1.0.0.4(510). This affects the function TendaAte of the file /goform/ate of the component ATE Service. Perfor…

No fix yet
Fix from $1,950 2025-12-30
Streamvault CRITICAL 9.1
CVE-2025-66203

StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault…

Fix: 251126+
Fix from $2,300 2025-12-27
Unclassified HIGH 7.4
CVE-2025-68922

OpenOps before 0.6.11 allows remote code execution in the Terraform block.

Patch available
Fix from $1,950 2025-12-25
Facesentry Access Control System Firmware HIGH 8.8
CVE-2019-25243

FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit …

No fix yet
Fix from $1,950 2025-12-24
Ipn4g Firmware HIGH 8.8
CVE-2018-25143

Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc…

No fix yet
Fix from $1,950 2025-12-24
Unclassified HIGH 8.7
CVE-2025-43875

Under certain circumstances a successful exploitation could result in access to the device.

No fix yet
Fix from $1,950 2025-12-24
Unclassified HIGH 8.7
CVE-2025-43876

Under certain circumstances a successful exploitation could result in access to the device.

No fix yet
Fix from $1,950 2025-12-24
Coolify HIGH 8.8
CVE-2025-66209

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated…

Fix: 4.0.0+
Fix from $1,950 2025-12-23
Coolify HIGH 8.8
CVE-2025-66210

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated…

Fix: 4.0.0+
Fix from $1,950 2025-12-23
Coolify HIGH 8.8
CVE-2025-66211

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated…

Fix: 4.0.0+
Fix from $1,950 2025-12-23
Coolify HIGH 8.8
CVE-2025-66212

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated…

Fix: 4.0.0+
Fix from $1,950 2025-12-23