Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Coolify HIGH 8.8
CVE-2025-66213

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated…

Fix: 4.0.0+
Fix from $1,950 2025-12-23
Unclassified CRITICAL 9.8
CVE-2025-14500

IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $2,300 2025-12-23
Unclassified HIGH 7.2
CVE-2025-13700

DreamFactory saveZipFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …

Patch available
Fix from $1,950 2025-12-23
Photoshow HIGH 7.2
CVE-2023-53981

PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftr…

No fix yet
Fix from $1,950 2025-12-22
Impact Firmware CRITICAL 9.8
CVE-2023-53963

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary s…

Mitigation only
Fix from $2,300 2025-12-22
Unclassified CRITICAL 9.8
CVE-2023-53948

Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary…

Mitigation only
Fix from $2,300 2025-12-19
Brainycp HIGH 8.8
CVE-2023-53945

BrainyCP 1.0 contains an authenticated remote code execution vulnerability that allows logged-in users to inject arbitrary commands through the cront…

No fix yet
Fix from $1,950 2025-12-19
Unclassified HIGH 8.2
CVE-2025-11774

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software keyboard function (hereinaft…

Mitigation only
Fix from $1,950 2025-12-19
Webserver CRITICAL 9.8
CVE-2023-53941EPSS 6%

EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by i…

Mitigation only
Fix from $2,300 2025-12-18
Tl Wa850re Firmware HIGH 8.0
CVE-2025-14737

Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue aff…

Fix: after 160922
Fix from $1,950 2025-12-18
Unclassified CRITICAL 9.4
CVE-2025-65008

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in the adm.cgi endpoint, the mal…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified HIGH 7.2
CVE-2025-68459

RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. An arbitr…

Mitigation only
Fix from $1,950 2025-12-18
Churchcrm HIGH 7.2
CVE-2025-68109

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or…

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Ritecms HIGH 7.2
CVE-2025-67172

RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.

No fix yet
Fix from $1,950 2025-12-17
Pagekit CRITICAL 9.9
CVE-2025-67164

An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary c…

Mitigation only
Fix from $2,300 2025-12-17
Unclassified HIGH 8.7
CVE-2025-43873

Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the device.

No fix yet
Fix from $1,950 2025-12-17
Systeminformation HIGH 8.1
CVE-2025-68154EPSS 13%

systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is v…

Fix: 5.27.14+
Fix from $1,950 2025-12-16
Allsky CRITICAL 10.0
CVE-2025-63414

A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command exec…

Mitigation only
Fix from $2,300 2025-12-16
Video Management Software Server HIGH 7.2
CVE-2025-65074

WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker wit…

Fix: after 6.42.4
Fix from $1,950 2025-12-16
Unclassified CRITICAL 9.3
CVE-2023-53872

Wp2Fac 1.0 contains an OS command injection vulnerability in the send.php endpoint that allows remote attackers to execute arbitrary system commands.…

No fix yet
Fix from $2,300 2025-12-15
X5000r Firmware CRITICAL 9.8
CVE-2025-14586

A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecg…

Mitigation only
Fix from $2,300 2025-12-13
Unclassified HIGH 8.8
CVE-2024-58314

Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web configuration CGI script that allo…

No fix yet
Fix from $1,950 2025-12-12
Unclassified CRITICAL 9.8
CVE-2024-14010

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Att…

Mitigation only
Fix from $2,300 2025-12-12
Freepbx HIGH 8.8
CVE-2024-58294

FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to ex…

No fix yet
Fix from $1,950 2025-12-11
Rengine HIGH 8.8
CVE-2024-58287

reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers t…

No fix yet
Fix from $1,950 2025-12-11
Unclassified CRITICAL 9.3
CVE-2024-58286

dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path s…

No fix yet
Fix from $2,300 2025-12-11
Aspera Orchestrator HIGH 8.8
CVE-2025-13481

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system du…

Fix: 4.1.1+
Fix from $1,950 2025-12-11
Rg Bcr860 Firmware HIGH 8.8
CVE-2025-56129

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the acti…

No fix yet
Fix from $1,950 2025-12-11
Rg Nbs5100 24gt4sfp Firmware HIGH 8.8
CVE-2025-56130

OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3.0(1)B11P230 allowing attackers to execute arbitrary commands via a crafted POST r…

No fix yet
Fix from $1,950 2025-12-11
Rg Ew1300g Firmware HIGH 8.8
CVE-2025-56114

OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST re…

No fix yet
Fix from $1,950 2025-12-11