Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 8.8
CVE-2025-10589

The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenticated remote attackers to inj…

Mitigation only
Fix from $1,950 2025-09-17
Unclassified HIGH 7.2
CVE-2025-37126

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run a…

Mitigation only
Fix from $1,950 2025-09-16
Unclassified MEDIUM 6.7
CVE-2025-37129

A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution c…

Mitigation only
Fix from $1,600 2025-09-16
Eve X1 Server Firmware CRITICAL 9.8
CVE-2025-34184

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote…

Fix: after 4.7.18.0
Fix from $2,300 2025-09-16
Eve X1 Server Firmware CRITICAL 9.8
CVE-2025-34186

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() c…

Fix: after 4.7.18.0
Fix from $2,300 2025-09-16
Eve X1 Server Firmware HIGH 8.8
CVE-2025-34187

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash sc…

Fix: after 4.7.18.0
Fix from $1,950 2025-09-16
Freepbx HIGH 8.8
CVE-2025-55211

FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Pan…

Fix: 17.0.21+
Fix from $1,950 2025-09-15
Mcp Kubernetes Server CRITICAL 9.8
CVE-2025-59377

feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl because shell=True is used. NOTE:…

Fix: after 0.1.11
Fix from $2,300 2025-09-15
Chaos Mesh CRITICAL 9.8
CVE-2025-59359

The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthentic…

Fix: 2.7.3+
Fix from $2,300 2025-09-15
Chaos Mesh CRITICAL 9.8
CVE-2025-59360

The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthe…

Fix: 2.7.3+
Fix from $2,300 2025-09-15
Chaos Mesh CRITICAL 9.8
CVE-2025-59361

The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthe…

Fix: 2.7.3+
Fix from $2,300 2025-09-15
Unclassified MEDIUM 6.3
CVE-2025-10441EPSS 12%

A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the function sub_433F7C of the f…

No fix yet
Fix from $1,600 2025-09-15
Ac9 Firmware HIGH 8.8
CVE-2025-10442EPSS 8%

A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manip…

No fix yet
Fix from $1,950 2025-09-15
Unclassified MEDIUM 6.3
CVE-2025-10440EPSS 12%

A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A1/19.12.10A1. Affected by thi…

Mitigation only
Fix from $1,600 2025-09-15
Wl Wn578w2 Firmware CRITICAL 9.8
CVE-2025-10359EPSS 6%

A vulnerability was detected in Wavlink WL-WN578W2 221110. This impacts the function sub_404DBC of the file /cgi-bin/wireless.cgi. The manipulation o…

Mitigation only
Fix from $2,300 2025-09-13
Wl Wn578w2 Firmware CRITICAL 9.8
CVE-2025-10358EPSS 6%

A security vulnerability has been detected in Wavlink WL-WN578W2 221110. This affects the function sub_404850 of the file /cgi-bin/wireless.cgi. The …

Mitigation only
Fix from $2,300 2025-09-13
Rpi Jukebox Rfid CRITICAL 9.8
CVE-2025-10328EPSS 9%

A security vulnerability has been detected in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file…

Fix: after 2.8.0
Fix from $2,300 2025-09-12
Rpi Jukebox Rfid CRITICAL 9.8
CVE-2025-10326EPSS 7%

A security flaw has been discovered in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/api/playlist/single…

Fix: after 2.8.0
Fix from $2,300 2025-09-12
Rpi Jukebox Rfid CRITICAL 9.8
CVE-2025-10327EPSS 10%

A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdo…

Fix: after 2.8.0
Fix from $2,300 2025-09-12
Unclassified HIGH 7.3
CVE-2025-27234

Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the sma…

Mitigation only
Fix from $1,950 2025-09-12
Unclassified HIGH 8.8
CVE-2025-10265

Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS…

Mitigation only
Fix from $1,950 2025-09-12
Hoverfly CRITICAL 9.8
CVE-2025-54123EPSS 11%

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command injec…

Fix: 1.12.0+
Fix from $2,300 2025-09-10
Powerprotect Data Manager MEDIUM 6.7
CVE-2025-43884

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command (…

Fix: 19.21+
Fix from $1,600 2025-09-10
Powerprotect Data Manager HIGH 7.8
CVE-2025-43885

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command (…

Fix: 19.21+
Fix from $1,950 2025-09-10
1panel HIGH 8.8
CVE-2025-56413

OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation paramete…

Mitigation only
Fix from $1,950 2025-09-10
Unclassified MEDIUM 5.8
CVE-2025-9997

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command inje…

No fix yet
Fix from $1,600 2025-09-09
Unclassified MEDIUM 5.8
CVE-2025-9996

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause the executio…

Mitigation only
Fix from $1,600 2025-09-09
Tautulli HIGH 7.2
CVE-2025-58763

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Tautulli v2.15.3 and prior allows…

Fix: 2.16.0+
Fix from $1,950 2025-09-09
Unclassified HIGH 8.5
CVE-2025-54084

OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user cr…

Mitigation only
Fix from $1,950 2025-09-09
Nvdebug CRITICAL 9.8
CVE-2025-23344

The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to run code on the platform host as a non-privileged user. A successful expl…

Fix: 1.7.0+
Fix from $2,300 2025-09-09