Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Rg Yst250f Firmware HIGH 8.8
CVE-2025-56083

OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request …

Mitigation only
Fix from $1,950 2025-12-11
Rg Yst250f Firmware HIGH 8.8
CVE-2025-56084

OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a cra…

Mitigation only
Fix from $1,950 2025-12-11
Rg Ew1200 Firmware HIGH 8.8
CVE-2025-56085

OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary comman…

No fix yet
Fix from $1,950 2025-12-11
Rg Ew1200 Firmware HIGH 8.8
CVE-2025-56086

OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary comman…

No fix yet
Fix from $1,950 2025-12-11
Rg Bcr600w Firmware HIGH 8.8
CVE-2025-56087

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the run…

Mitigation only
Fix from $1,950 2025-12-11
Rg Bcr860 Firmware HIGH 8.8
CVE-2025-56088

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the acti…

No fix yet
Fix from $1,950 2025-12-11
Unclassified HIGH 8.5
CVE-2025-67738

squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature …

Patch available
Fix from $1,950 2025-12-11
Windscribe HIGH 7.8
CVE-2025-65199

A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to exec…

Fix: after 2.17.10
Fix from $1,950 2025-12-10
Git Client MEDIUM 5.0
CVE-2025-67640

Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary s…

Fix: 6.4.1+
Fix from $1,600 2025-12-10
Argo Workflows HIGH 7.5
CVE-2025-66626

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions 3.6.13 and below and versio…

Fix: 3.6.14 / 3.7.5+
Fix from $1,950 2025-12-09
Izero Box Full Firmware CRITICAL 9.8
CVE-2021-47728

Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbit…

Mitigation only
Fix from $2,300 2025-12-09
Openmptcprouter CRITICAL 9.8
CVE-2025-65882

An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ip…

Fix: after 0.64
Fix from $2,300 2025-12-09
Fortiextender Firmware HIGH 7.2
CVE-2025-64153

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExte…

Fix: after 7.6.3
Fix from $1,950 2025-12-09
Fortisandbox HIGH 7.2
CVE-2025-53679EPSS 12%

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiS…

Fix: 4.4.8 / 5.0.3+
Fix from $1,950 2025-12-09
Fortisandbox HIGH 8.8
CVE-2025-53949EPSS 17%

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiS…

Fix: after 5.0.2
Fix from $1,950 2025-12-09
Unclassified MEDIUM 6.3
CVE-2025-14204

A vulnerability has been found in TykoDev cherry-studio-TykoFork 0.1. This issue affects the function redirectToAuthorization of the file /.well-know…

Mitigation only
Fix from $1,600 2025-12-07
Arrayos Ag CRITICAL 9.8
CVE-2025-66644 KEV

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

Fix: 9.4.5.9+
Fix from $2,300 2025-12-05
Unclassified CRITICAL 9.3
CVE-2020-36877

ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary…

No fix yet
Fix from $2,300 2025-12-05
Br 6478ac V3 Firmware CRITICAL 9.8
CVE-2025-14093EPSS 20%

A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The …

Mitigation only
Fix from $2,300 2025-12-05
Br 6478ac V3 Firmware CRITICAL 9.8
CVE-2025-14094EPSS 21%

A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulatio…

Mitigation only
Fix from $2,300 2025-12-05
Br 6478ac V3 Firmware HIGH 7.2
CVE-2025-14092EPSS 17%

A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the function sub_416898 of the file /boafrm/formDebugDia…

No fix yet
Fix from $1,950 2025-12-05
Remote Keyboard Desktop CRITICAL 9.8
CVE-2025-66576

Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthentic…

Mitigation only
Fix from $2,300 2025-12-04
Unclassified MEDIUM 6.9
CVE-2025-66572

Loaded Commerce 6.6 contains a client-side template injection vulnerability via the search parameter that allows unauthenticated attackers to execute…

No fix yet
Fix from $1,600 2025-12-04
Unclassified HIGH 8.5
CVE-2024-58278

perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attack…

No fix yet
Fix from $1,950 2025-12-04
All Rut22gw Firmware CRITICAL 9.8
CVE-2025-29269

ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.

Mitigation only
Fix from $2,300 2025-12-04
Online CRITICAL 9.8
CVE-2025-66208

Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online.…

Fix: 25.04.702+
Fix from $2,300 2025-12-03
Unclassified CRITICAL 9.3
CVE-2025-34319

TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contain an OS command injection vul…

Mitigation only
Fix from $2,300 2025-12-03
Unclassified HIGH 8.8
CVE-2025-12744

A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places …

Mitigation only
Fix from $1,950 2025-12-03
Sge Plc1000 Firmware HIGH 8.8
CVE-2025-11787

Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()', 'CheckPing()' and 'TraceRout…

Mitigation only
Fix from $1,950 2025-12-02
Mcp Watch CRITICAL 9.8
CVE-2025-66401

MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critica…

Fix: after 0.1.2
Fix from $2,300 2025-12-01