Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Er706w Firmware HIGH 8.8
CVE-2025-6541

An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.

Fix: 1.0.3 / 1.1.4+
Fix from $1,950 2025-10-21
Unclassified CRITICAL 10.0
CVE-2018-25118

GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that ena…

Mitigation only
Fix from $2,300 2025-10-20
Timeprovider 4100 Firmware HIGH 8.8
CVE-2025-47900

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Co…

Fix: 2.5+
Fix from $1,950 2025-10-20
Timeprovider 4100 Firmware HIGH 8.8
CVE-2025-47901

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Co…

Fix: 2.5+
Fix from $1,950 2025-10-20
Unclassified CRITICAL 9.8
CVE-2025-11900

The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands…

Mitigation only
Fix from $2,300 2025-10-17
Eve X1 Server Firmware CRITICAL 9.8
CVE-2025-34513EPSS 8%

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauth…

Fix: after 4.7.18.0
Fix from $2,300 2025-10-16
Eve X1 Server Firmware HIGH 8.8
CVE-2025-34514

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scri…

Fix: after 4.7.18.0
Fix from $1,950 2025-10-16
Big Ip Access Policy Manager HIGH 8.7
CVE-2025-53868

When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restricti…

Fix: 15.1.10.8 / 16.1.6.1+
Fix from $1,950 2025-10-15
Unclassified CRITICAL 9.3
CVE-2023-7311

BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is n…

No fix yet
Fix from $2,300 2025-10-15
Unclassified CRITICAL 9.3
CVE-2023-7304

Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. An unauthenticated attacker…

Mitigation only
Fix from $2,300 2025-10-15
Unclassified HIGH 8.6
CVE-2025-59051

The FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device disco…

Mitigation only
Fix from $1,950 2025-10-14
Fortisoar HIGH 7.0
CVE-2024-48891

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1…

Fix: 7.5.2 / 7.6.2+
Fix from $1,950 2025-10-14
Centreon Web HIGH 7.2
CVE-2025-5946EPSS 14%

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload …

Fix: 23.10.28 / 24.04.18+
Fix from $1,950 2025-10-14
Endpoint Manager Mobile HIGH 7.2
CVE-2025-10242EPSS 21%

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad…

Fix: 12.4.0.4 / 12.5.0.4+
Fix from $1,950 2025-10-14
Endpoint Manager Mobile HIGH 7.2
CVE-2025-10243EPSS 21%

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad…

Fix: 12.4.0.4 / 12.5.0.4+
Fix from $1,950 2025-10-14
Endpoint Manager Mobile HIGH 7.2
CVE-2025-10985EPSS 21%

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad…

Fix: 12.4.0.4 / 12.5.0.4+
Fix from $1,950 2025-10-14
Fortivoice HIGH 7.2
CVE-2025-47856

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice versio…

Fix: 6.4.11 / 7.0.7+
Fix from $1,950 2025-10-14
Unclassified CRITICAL 9.0
CVE-2025-9976

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPE…

Mitigation only
Fix from $2,300 2025-10-13
Dap 2695 Firmware CRITICAL 9.8
CVE-2025-11665EPSS 7%

A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Updat…

Mitigation only
Fix from $2,300 2025-10-13
Unclassified HIGH 8.4
CVE-2025-0636

EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command could be exploited leading to Ar…

Mitigation only
Fix from $1,950 2025-10-13
Unclassified HIGH 8.7
CVE-2016-15047

AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in C…

No fix yet
Fix from $1,950 2025-10-09
Junos Os Evolved MEDIUM 5.3
CVE-2025-60006

Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Jun…

Mitigation only
Fix from $1,600 2025-10-09
Unclassified HIGH 7.2
CVE-2025-10239

In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privileges and access to the managemen…

Mitigation only
Fix from $1,950 2025-10-09
Desktopcommandermcp CRITICAL 9.8
CVE-2025-11491

A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/comma…

Fix: after 0.2.13
Fix from $2,300 2025-10-08
Unclassified HIGH 8.8
CVE-2025-57457

An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the…

Mitigation only
Fix from $1,950 2025-10-08
Desktopcommandermcp CRITICAL 9.8
CVE-2025-11490

A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file …

Fix: after 0.2.13
Fix from $2,300 2025-10-08
Data Domain Operating System MEDIUM 6.7
CVE-2025-36567

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version…

Fix: 7.10.1.60 / 7.13.1.30+
Fix from $1,600 2025-10-07
Data Domain Operating System MEDIUM 6.7
CVE-2025-36569

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version…

Fix: 7.10.1.60 / 7.13.1.30+
Fix from $1,600 2025-10-07
Di 7001mini 8g Firmware CRITICAL 9.8
CVE-2025-11407

A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of the file /upgrade_filter.asp. This manipulation …

Mitigation only
Fix from $2,300 2025-10-07
Data Domain Operating System MEDIUM 6.7
CVE-2025-36566

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version…

Fix: 7.10.1.60 / 7.13.1.30+
Fix from $1,600 2025-10-07