Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Octoprint HIGH 8.8
CVE-2025-58180EPSS 21%

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability tha…

Fix: 1.11.3+
Fix from $1,950 2025-09-09
Unclassified CRITICAL 9.8
CVE-2025-55048

Multiple CWE-78

No fix yet
Fix from $2,300 2025-09-09
Fortiddos F MEDIUM 6.7
CVE-2024-45325

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F versio…

Fix: 7.0.3+
Fix from $1,600 2025-09-09
Unclassified CRITICAL 9.3
CVE-2025-54994

@akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13, the MCP Server is written i…

Patch available
Fix from $2,300 2025-09-08
Roo Code HIGH 7.8
CVE-2025-58374

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands…

Fix: 3.26.0+
Fix from $1,950 2025-09-06
Roo Code HIGH 8.1
CVE-2025-58370

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing …

Fix: 3.26.0+
Fix from $1,950 2025-09-05
Roo Code CRITICAL 9.8
CVE-2025-58371

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github workflow used unsanitized pull…

Fix: 3.26.7+
Fix from $2,300 2025-09-05
Unclassified CRITICAL 9.8
CVE-2025-55037

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI versions prior to v1.0.22. If th…

Mitigation only
Fix from $2,300 2025-09-05
Desktop HIGH 8.4
CVE-2025-56803

Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbitrary OS…

No fix yet
Fix from $1,950 2025-09-03
Pgn6401v Firmware MEDIUM 5.3
CVE-2025-56498

An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interface. The ping6.asp page submi…

Fix: after 8.1.2
Fix from $1,600 2025-09-03
Unclassified HIGH 7.2
CVE-2025-8613

Vacron Camera ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff…

Mitigation only
Fix from $1,950 2025-09-02
Unclassified HIGH 8.6
CVE-2025-9573

The ns_backup extension through 13.0.2 for TYPO3 allows command injection.

Mitigation only
Fix from $1,950 2025-09-02
Unclassified HIGH 8.7
CVE-2025-57799

StreamVault is a multi-platform video parsing and downloading tool. Prior to version 250822, after logging into the StreamVault-system, an attacker c…

Patch available
Fix from $1,950 2025-09-01
Unclassified CRITICAL 9.8
CVE-2025-54857

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge BASIC MB-A130 Ver.1.5.8 and earl…

Mitigation only
Fix from $2,300 2025-09-01
Dir 852 Firmware CRITICAL 9.8
CVE-2025-9752EPSS 16%

A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component …

Mitigation only
Fix from $2,300 2025-09-01
Di 500wf Firmware HIGH 7.2
CVE-2025-9745EPSS 10%

A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.a…

No fix yet
Fix from $1,950 2025-08-31
Dir 816l Firmware CRITICAL 9.8
CVE-2025-9727

A weakness has been identified in D-Link DIR-816L 206b01. Affected by this issue is the function soapcgi_main of the file /soap.cgi. This manipulatio…

Mitigation only
Fix from $2,300 2025-08-31
Unclassified CRITICAL 10.0
CVE-2009-20011

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure h…

Mitigation only
Fix from $2,300 2025-08-30
Unclassified CRITICAL 9.3
CVE-2009-20010

Dogfood CRM version 2.0.10 contains a remote command execution vulnerability in the spell.php script used by its mail subsystem. The vulnerability ar…

No fix yet
Fix from $2,300 2025-08-30
Cacti HIGH 8.8
CVE-2005-10004

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbit…

Fix: 0.8.6d+
Fix from $1,950 2025-08-30
Tv Ip410 Firmware CRITICAL 9.8
CVE-2024-46484

TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.

Mitigation only
Fix from $2,300 2025-08-29
Tl Wr841n Firmware HIGH 7.2
CVE-2025-9377 KEVEPSS 12%

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) …

Fix: 241108+
Fix from $1,950 2025-08-29
Hybriddesk Station HIGH 8.4
CVE-2025-44015

A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network access, they can then exploit th…

Fix: 4.2.18+
Fix from $1,950 2025-08-29
Qts HIGH 8.8
CVE-2025-30264

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they…

Mitigation only
Fix from $1,950 2025-08-29
Qurouter HIGH 7.2
CVE-2025-29887

A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrator account, they can then expl…

Mitigation only
Fix from $1,950 2025-08-29
Unclassified HIGH 7.2
CVE-2025-53508

Multiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed and se…

Mitigation only
Fix from $1,950 2025-08-29
Unclassified HIGH 7.3
CVE-2025-58062

LSTM-Kirigaya's openmcp-client is a vscode plugin for mcp developer. Prior to version 0.1.12, when users on a Windows platform connect to an attacker…

Patch available
Fix from $1,950 2025-08-28
Bl X26 Firmware HIGH 8.8
CVE-2025-9579EPSS 7%

A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/set_hidessid_cfg of the compo…

No fix yet
Fix from $1,950 2025-08-28
Bl X26 Firmware HIGH 8.8
CVE-2025-9580EPSS 7%

A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the compone…

No fix yet
Fix from $1,950 2025-08-28
Re6250 Firmware HIGH 8.8
CVE-2025-9575EPSS 8%

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. …

No fix yet
Fix from $1,950 2025-08-28