Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Myscreentools HIGH 8.1
CVE-2025-63916

MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The application fails to properly sanitize…

Fix: after 2.2.1.0
Fix from $1,950 2025-11-17
Unclassified CRITICAL 9.8
CVE-2025-13284

ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands a…

Mitigation only
Fix from $2,300 2025-11-17
Unclassified CRITICAL 9.3
CVE-2021-4470

TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd POST parameter is passed dir…

Mitigation only
Fix from $2,300 2025-11-14
Unclassified HIGH 8.7
CVE-2021-4466

IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. …

No fix yet
Fix from $1,950 2025-11-14
Unclassified HIGH 7.2
CVE-2025-64444

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploi…

Mitigation only
Fix from $1,950 2025-11-14
Catalyst Center HIGH 8.8
CVE-2025-20349

A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitrary commands in a restricted …

Fix: 2.3.7.10+
Fix from $1,950 2025-11-13
Pgadmin 4 HIGH 8.8
CVE-2025-12763

pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True duri…

Fix: 9.10+
Fix from $1,950 2025-11-13
Business Connector MEDIUM 6.8
CVE-2025-42892

Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network acc…

Mitigation only
Fix from $1,600 2025-11-11
Unclassified CRITICAL 10.0
CVE-2025-10230EPSS 40%

A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validati…

Mitigation only
Fix from $2,300 2025-11-07
Filestore HIGH 7.2
CVE-2025-64328 KEVEPSS 85%

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestor…

Fix: 17.0.3+
Fix from $1,950 2025-11-07
Unclassified CRITICAL 9.3
CVE-2025-11546

CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleServerSafe …

Mitigation only
Fix from $2,300 2025-11-07
Unclassified HIGH 7.8
CVE-2025-12489

evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privilege…

Patch available
Fix from $1,950 2025-11-06
Webaccess\/vpn HIGH 7.2
CVE-2025-34239

Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows a…

Fix: 1.1.5+
Fix from $1,950 2025-11-06
Dir 1260 Firmware CRITICAL 9.8
CVE-2022-50596

D-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability within the web management inter…

Fix: after 1.20b05
Fix from $2,300 2025-11-06
Pocketvj Control Panel Firmware CRITICAL 9.8
CVE-2025-63334

PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The…

Mitigation only
Fix from $2,300 2025-11-05
Cloudlink CRITICAL 9.1
CVE-2025-45378

Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command s…

Fix: after 8.1.2
Fix from $2,300 2025-11-05
Cloudlink HIGH 8.4
CVE-2025-45379

Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to …

Fix: 8.2+
Fix from $1,950 2025-11-05
Cloudlink HIGH 7.2
CVE-2025-30479

Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control …

Fix: 8.2+
Fix from $1,950 2025-11-05
Activegate Ping Extension CRITICAL 9.8
CVE-2025-61304

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.

Fix: after 1.016
Fix from $2,300 2025-11-05
Unclassified HIGH 8.0
CVE-2025-10622

A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve …

Mitigation only
Fix from $1,950 2025-11-05
Unclassified HIGH 8.8
CVE-2025-64109

Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta allowed an attacker to achieve r…

Mitigation only
Fix from $1,950 2025-11-05
Cursor HIGH 8.8
CVE-2025-64106

Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation ena…

Fix: 2.0+
Fix from $1,950 2025-11-04
React Native Community Cli CRITICAL 9.8
CVE-2025-11953 KEVEPSS 94%

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpo…

Fix: 19.1.2+
Fix from $2,300 2025-11-03
Unclassified HIGH 7.2
CVE-2025-54763

FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of…

Mitigation only
Fix from $1,950 2025-10-31
Network Analyzer HIGH 7.2
CVE-2025-34280

Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate…

Fix: 2024+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 8.8
CVE-2025-34284

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters…

Fix: 2024+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 7.2
CVE-2025-34286

Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient va…

Fix: 2026+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 8.8
CVE-2024-14005

Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input i…

Fix: 2024+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 7.2
CVE-2024-14008

Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Insufficient validation of…

Fix: 2024+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 7.2
CVE-2025-34134

Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficie…

Fix: 2024+
Fix from $1,950 2025-10-30