Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Data Domain Operating System MEDIUM 6.7
CVE-2025-43908

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version…

Fix: 7.10.1.70 / 7.13.1.40+
Fix from $1,600 2025-10-07
Data Domain Operating System MEDIUM 6.7
CVE-2025-43890

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version…

Fix: 7.10.1.70 / 7.13.1.40+
Fix from $1,600 2025-10-07
Data Domain Operating System MEDIUM 6.7
CVE-2025-43906

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version…

Fix: 7.10.1.70 / 7.13.1.40+
Fix from $1,600 2025-10-07
Data Domain Operating System MEDIUM 6.7
CVE-2025-43911

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version…

Fix: 7.10.1.70 / 7.13.1.40+
Fix from $1,600 2025-10-07
Wgr 500 Firmware HIGH 8.8
CVE-2025-54403

Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request…

No fix yet
Fix from $1,950 2025-10-07
Wgr 500 Firmware HIGH 8.8
CVE-2025-54404

Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request…

No fix yet
Fix from $1,950 2025-10-07
Wgr 500 Firmware HIGH 8.8
CVE-2025-54405

Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of …

No fix yet
Fix from $1,950 2025-10-07
Wgr 500 Firmware HIGH 8.8
CVE-2025-54406

Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of …

No fix yet
Fix from $1,950 2025-10-07
Sonoma D12 Firmware HIGH 8.2
CVE-2025-60962

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain se…

Mitigation only
Fix from $1,950 2025-10-06
Sonoma D12 Firmware HIGH 8.2
CVE-2025-60963

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute…

Mitigation only
Fix from $1,950 2025-10-06
Sonoma D12 Firmware CRITICAL 9.1
CVE-2025-60964

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute…

Mitigation only
Fix from $2,300 2025-10-06
Sonoma D12 Firmware CRITICAL 9.1
CVE-2025-60965

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute…

Mitigation only
Fix from $2,300 2025-10-06
Sonoma D12 Firmware CRITICAL 9.9
CVE-2025-60957

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute…

Mitigation only
Fix from $2,300 2025-10-06
Sonoma D12 Firmware HIGH 8.2
CVE-2025-60959

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain se…

Mitigation only
Fix from $1,950 2025-10-06
Sonoma D12 Firmware HIGH 8.2
CVE-2025-60960

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute…

Mitigation only
Fix from $1,950 2025-10-06
Security Verify Access HIGH 7.3
CVE-2025-36354

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthent…

Fix: 10.0.9.0 / 11.0.1.0+
Fix from $1,950 2025-10-06
Mcphub HIGH 8.8
CVE-2025-11285EPSS 8%

A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the file src/controllers/serverC…

Fix: after 0.9.10
Fix from $1,950 2025-10-05
Qts HIGH 7.2
CVE-2025-47212

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…

Mitigation only
Fix from $1,950 2025-10-03
Cursor HIGH 8.8
CVE-2025-61591

Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an…

Fix: after 1.7
Fix from $1,950 2025-10-03
Motioneye HIGH 7.2
CVE-2025-60787EPSS 18%

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is w…

No fix yet
Fix from $1,950 2025-10-03
E Tms CRITICAL 9.8
CVE-2025-59741

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
E Tms CRITICAL 9.8
CVE-2025-59735

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
E Tms CRITICAL 9.8
CVE-2025-59736

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
E Tms CRITICAL 9.8
CVE-2025-59737

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
E Tms CRITICAL 9.8
CVE-2025-59738

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
E Tms CRITICAL 9.8
CVE-2025-59739

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
E Tms CRITICAL 9.8
CVE-2025-59740

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…

Mitigation only
Fix from $2,300 2025-10-02
X18 Firmware CRITICAL 9.8
CVE-2025-61045

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg fun…

Mitigation only
Fix from $2,300 2025-10-01
Unclassified CRITICAL 9.8
CVE-2025-10659

The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-supp…

Mitigation only
Fix from $2,300 2025-09-30
Unclassified CRITICAL 9.8
CVE-2025-9762

The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the save_attachments function i…

Mitigation only
Fix from $2,300 2025-09-30