Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Nagios Xi CRITICAL 9.8
CVE-2024-14003

Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. In…

Fix: 2024+
Fix from $2,300 2025-10-30
Nagios Xi HIGH 8.8
CVE-2020-36867

Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values use…

Fix: 5.7.3+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 8.8
CVE-2020-36856

Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_test.php script. Insufficient v…

Fix: 5.6.14+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 8.8
CVE-2018-25122

Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The download/import handler used uns…

Fix: 5.4.13+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 8.8
CVE-2013-10073

Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a…

Fix: 2012+
Fix from $1,950 2025-10-30
Unity Operating Environment HIGH 7.8
CVE-2025-43942

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…

Fix: 5.5.2.0+
Fix from $1,950 2025-10-30
Unity Operating Environment HIGH 7.8
CVE-2025-46422

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…

Fix: 5.5.2.0+
Fix from $1,950 2025-10-30
Unity Operating Environment HIGH 7.8
CVE-2025-46423

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…

Fix: 5.5.2.0+
Fix from $1,950 2025-10-30
Unity Operating Environment HIGH 7.8
CVE-2025-43940

Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…

Fix: 5.5.2.0+
Fix from $1,950 2025-10-30
Unity Operating Environment HIGH 7.8
CVE-2025-43941

Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…

Fix: 5.5.2.0+
Fix from $1,950 2025-10-30
Unity Operating Environment HIGH 7.8
CVE-2025-43939

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…

Fix: 5.5.2.0+
Fix from $1,950 2025-10-30
Unclassified CRITICAL 9.9
CVE-2025-54469

A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_LAN_PORT to generate a comman…

Mitigation only
Fix from $2,300 2025-10-30
Unclassified CRITICAL 9.8
CVE-2025-11202

win-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute ar…

Patch available
Fix from $2,300 2025-10-29
Dns 343 Firmware CRITICAL 9.8
CVE-2018-25120EPSS 10%

D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulnerability in the Mail Test func…

Fix: after 1.0.5
Fix from $2,300 2025-10-29
Azure Cli HIGH 8.8
CVE-2025-64140

Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configu…

Fix: after 0.9
Fix from $1,950 2025-10-29
Fastmcp HIGH 7.8
CVE-2025-62801

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who ca…

Fix: 2.13.0+
Fix from $1,950 2025-10-28
Ipfire HIGH 8.8
CVE-2025-34311EPSS 14%

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary …

Fix: 2.29+
Fix from $1,950 2025-10-28
Ipfire HIGH 8.8
CVE-2025-34312

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary …

Fix: 2.29+
Fix from $1,950 2025-10-28
Unclassified HIGH 8.7
CVE-2025-1036

Command injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated user with low privileged networ…

Mitigation only
Fix from $1,950 2025-10-28
Unclassified HIGH 7.5
CVE-2025-1038

The “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, allowing an authenticated user …

Mitigation only
Fix from $1,950 2025-10-28
Dap 2695 Firmware CRITICAL 9.8
CVE-2025-12296EPSS 7%

A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 of the component Firmware Upd…

Mitigation only
Fix from $2,300 2025-10-27
Unclassified CRITICAL 9.8
CVE-2025-60803

Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the component /ap…

Mitigation only
Fix from $2,300 2025-10-24
Unclassified HIGH 8.8
CVE-2025-10680EPSS 7%

OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --…

Mitigation only
Fix from $1,950 2025-10-24
Unclassified HIGH 7.2
CVE-2025-6978EPSS 14%

Diagnostics command injection vulnerability

No fix yet
Fix from $1,950 2025-10-23
Unclassified HIGH 7.2
CVE-2025-62713

Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authentication remote code execution (RCE…

Patch available
Fix from $1,950 2025-10-23
Hibos CRITICAL 9.8
CVE-2016-15048EPSS 7%

AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection vulnerability in the /manager/radius/server_ping.php endp…

Mitigation only
Fix from $2,300 2025-10-22
Unclassified HIGH 8.3
CVE-2024-58274EPSS 18%

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/ap…

Mitigation only
Fix from $1,950 2025-10-22
Zld HIGH 7.2
CVE-2025-8078

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versio…

Fix: 5.41+
Fix from $1,950 2025-10-21
Er8411 Firmware CRITICAL 9.8
CVE-2025-6542

An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.

Fix: 1.1.0 / 1.2.1+
Fix from $2,300 2025-10-21
Er8411 Firmware HIGH 7.2
CVE-2025-7850

A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.

Fix: 1.1.0 / 1.2.1+
Fix from $1,950 2025-10-21