Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified CRITICAL 9.1
CVE-2025-35028EPSS 5%

By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI…

Mitigation only
Fix from $2,300 2025-11-30
Unclassified CRITICAL 9.3
CVE-2025-8890

Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell command injection attacks. In order…

Mitigation only
Fix from $2,300 2025-11-27
Tew 657brm Firmware HIGH 8.0
CVE-2025-65202EPSS 7%

TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameter…

No fix yet
Fix from $1,950 2025-11-26
Unclassified CRITICAL 10.0
CVE-2025-64126

An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without…

Mitigation only
Fix from $2,300 2025-11-26
Unclassified CRITICAL 10.0
CVE-2025-64127

An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are l…

Mitigation only
Fix from $2,300 2025-11-26
Unclassified CRITICAL 10.0
CVE-2025-64128

An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting…

Mitigation only
Fix from $2,300 2025-11-26
Unclassified CRITICAL 9.8
CVE-2025-62354

Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to execute commands…

Mitigation only
Fix from $2,300 2025-11-26
Mozart Next 100 Firmware CRITICAL 9.8
CVE-2025-66261

Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 30…

Mitigation only
Fix from $2,300 2025-11-26
Mozart Next 100 Firmware CRITICAL 9.8
CVE-2025-66253

Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, …

Mitigation only
Fix from $2,300 2025-11-26
Unclassified CRITICAL 9.2
CVE-2025-59366EPSS 16%

An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality…

Mitigation only
Fix from $2,300 2025-11-25
Unclassified HIGH 7.5
CVE-2025-59370

A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially exe…

Mitigation only
Fix from $1,950 2025-11-25
Unclassified HIGH 7.5
CVE-2025-12742

A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Teradata driver parameters. Loo…

Mitigation only
Fix from $1,950 2025-11-25
Unclassified CRITICAL 9.3
CVE-2018-25126

Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and…

No fix yet
Fix from $2,300 2025-11-24
Claude Code CRITICAL 9.8
CVE-2025-64755

Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code rea…

Fix: 2.0.31+
Fix from $2,300 2025-11-21
Unclassified MEDIUM 6.2
CVE-2025-13087EPSS 7%

A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code execution with root privileges.…

Mitigation only
Fix from $1,600 2025-11-20
Lite Xl HIGH 7.3
CVE-2025-12121

Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized s…

Fix: after 2.1.8
Fix from $1,950 2025-11-20
Eve X1 Server Firmware CRITICAL 9.8
CVE-2025-60738

An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to e…

Mitigation only
Fix from $2,300 2025-11-20
Dir 868l Firmware HIGH 7.3
CVE-2025-63932EPSS 8%

D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary. The HNAP service provided b…

No fix yet
Fix from $1,950 2025-11-19
Fax Server HIGH 8.8
CVE-2025-34334

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in t…

Fix: after 2.6.23
Fix from $1,950 2025-11-19
Fax Server HIGH 8.8
CVE-2025-34335

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability i…

Fix: 2.6.23+
Fix from $1,950 2025-11-19
Airwave HIGH 7.2
CVE-2025-37163

A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated at…

Fix: 8.3.0.5+
Fix from $1,950 2025-11-18
Arubaos Cx HIGH 8.8
CVE-2025-37157

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to cond…

Fix: 10.10.1170 / 10.13.1101+
Fix from $1,950 2025-11-18
Arubaos Cx HIGH 8.8
CVE-2025-37158

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to cond…

Fix: 10.10.1170 / 10.13.1101+
Fix from $1,950 2025-11-18
Fortiweb HIGH 7.2
CVE-2025-58034 KEVEPSS 56%

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiW…

Fix: 7.0.12 / 7.2.12+
Fix from $1,950 2025-11-18
Agent Dvr HIGH 7.8
CVE-2025-63408

Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive…

Fix: after 6.6.7.0
Fix from $1,950 2025-11-18
Dm4200 B0 Firmware HIGH 8.8
CVE-2025-8693

A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could …

Fix: after 5.63
Fix from $1,950 2025-11-18
Dwr M920 Firmware HIGH 8.8
CVE-2025-13306EPSS 8%

A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /bo…

No fix yet
Fix from $1,950 2025-11-18
Glob HIGH 7.5
CVE-2025-64756

Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, the glob CLI contains a command…

Fix: 10.5.0 / 11.1.0+
Fix from $1,950 2025-11-17
Rumpus CRITICAL 9.8
CVE-2025-55055

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Mitigation only
Fix from $2,300 2025-11-17
Log Server HIGH 7.2
CVE-2025-34322EPSS 9%

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries…

Fix: 2026+
Fix from $1,950 2025-11-17