Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified CRITICAL 9.8
CVE-2025-11148

All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool that is interacted with locally,…

Mitigation only
Fix from $2,300 2025-09-30
Infosphere Information Server HIGH 8.8
CVE-2025-36245

IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges …

Fix: after 11.7.1.6
Fix from $1,950 2025-09-29
Unclassified CRITICAL 9.3
CVE-2025-30247

An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attacke…

Mitigation only
Fix from $2,300 2025-09-29
Publiccms HIGH 8.2
CVE-2025-57516

OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via…

No fix yet
Fix from $1,950 2025-09-29
Wenkucms HIGH 8.8
CVE-2025-11138

A vulnerability was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation…

No fix yet
Fix from $1,950 2025-09-29
Unclassified HIGH 7.7
CVE-2025-59844

SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command injection vulnerability exist…

Mitigation only
Fix from $1,950 2025-09-26
G1 Firmware HIGH 7.3
CVE-2025-35027

Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability.…

Fix: after 1.4.4
Fix from $1,950 2025-09-26
Unclassified HIGH 8.2
CVE-2025-60017

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (w…

Mitigation only
Fix from $1,950 2025-09-26
X6000r Firmware CRITICAL 9.8
CVE-2025-11005

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injecti…

Fix: after 9.4.0cu.1360_b20241207
Fix from $2,300 2025-09-25
Nagios Xi HIGH 8.8
CVE-2025-34227EPSS 24%

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres…

Fix: after 2026
Fix from $1,950 2025-09-25
Cloud Disaster Recovery MEDIUM 6.7
CVE-2025-43943

Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command…

Fix: 19.20+
Fix from $1,600 2025-09-25
Indoor Connect 8855 Firmware HIGH 7.8
CVE-2025-27262

Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.

Fix: 2025.q2+
Fix from $1,950 2025-09-25
Git Commiters HIGH 8.8
CVE-2025-59831

git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection …

Fix: 0.1.2+
Fix from $1,950 2025-09-25
Adb Mcp Server CRITICAL 9.8
CVE-2025-59834

ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server…

Fix: after 0.1.0
Fix from $2,300 2025-09-25
X6000r Firmware CRITICAL 9.8
CVE-2025-52906EPSS 13%

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injecti…

Fix: after 9.4.0cu.1360_b20241207
Fix from $2,300 2025-09-24
Datart CRITICAL 9.8
CVE-2025-56819

An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.

Mitigation only
Fix from $2,300 2025-09-24
Di 7100g Firmware MEDIUM 6.5
CVE-2025-57636

OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injection vulnerability via the HTTP…

No fix yet
Fix from $1,600 2025-09-23
Cryptolib HIGH 7.8
CVE-2025-59534

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communication…

Fix: 1.4.2+
Fix from $1,950 2025-09-23
Ac9 Firmware MEDIUM 6.5
CVE-2025-57639

OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user paramete…

No fix yet
Fix from $1,600 2025-09-23
Envision CRITICAL 9.8
CVE-2025-9588

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnV…

Fix: 250563+
Fix from $2,300 2025-09-23
Unclassified HIGH 8.5
CVE-2025-9494

An OS command injection vulnerability has been discovered in the Vitogate 300, which can be exploited by malicious users to compromise affected insta…

Mitigation only
Fix from $1,950 2025-09-23
Wl Nu516u1 Firmware HIGH 7.2
CVE-2025-10775EPSS 20%

A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/logi…

No fix yet
Fix from $1,950 2025-09-22
Ngenuity CRITICAL 9.8
CVE-2025-10568

HyperX NGENUITY software is potentially vulnerable to arbitrary code execution. HP is releasing updated software to address the potential vulnerabili…

Fix: 5.32.0.0+
Fix from $2,300 2025-09-19
Webpanel CRITICAL 9.0
CVE-2025-48703 KEVEPSS 100%

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_tota…

Fix: 0.9.8.1205+
Fix from $2,300 2025-09-19
Watsonx.data HIGH 7.2
CVE-2025-36143

IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation …

Mitigation only
Fix from $1,950 2025-09-18
Triton Inference Server CRITICAL 9.8
CVE-2025-23316

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote code exec…

Fix: 25.08+
Fix from $2,300 2025-09-17
Unclassified MEDIUM 6.3
CVE-2025-10619

A vulnerability was detected in sequa-ai sequa-mcp up to 1.0.13. This affects the function redirectToAuthorization of the file src/helpers/node-oauth…

Patch available
Fix from $1,600 2025-09-17
Unclassified CRITICAL 9.8
CVE-2025-9972

Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability, allowing unauthenticated rem…

Mitigation only
Fix from $2,300 2025-09-17
Unclassified HIGH 8.0
CVE-2025-59518

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during ru…

Mitigation only
Fix from $1,950 2025-09-17
Unclassified HIGH 7.2
CVE-2025-58116

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulner…

Mitigation only
Fix from $1,950 2025-09-17