Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified CRITICAL 10.0
CVE-2011-10017

Snort Report versions < 1.3.2 contains a remote command execution vulnerability in the nmap.php and nbtscan.php scripts. These scripts fail to proper…

Mitigation only
Fix from $2,300 2025-08-13
Unclassified MEDIUM 6.5
CVE-2025-43989EPSS 6%

The /goform/formJsonAjaxReq POST endpoint of Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices mishandles the set_timesetting action…

Mitigation only
Fix from $1,600 2025-08-13
Olivetin MEDIUM 6.5
CVE-2025-50946

OS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go.

No fix yet
Fix from $1,600 2025-08-13
Unclassified HIGH 7.8
CVE-2025-23294

NVIDIA WebDataset for all platforms contains a vulnerability where an attacker could execute arbitrary code with elevated permissions. A successful e…

Mitigation only
Fix from $1,950 2025-08-13
Cherry Studio HIGH 8.8
CVE-2025-54382EPSS 6%

Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in t…

Fix: 1.5.2+
Fix from $1,950 2025-08-13
Cherry Studio CRITICAL 9.8
CVE-2025-54074

Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio is vulnerable to OS Command I…

Fix: 1.5.2+
Fix from $2,300 2025-08-13
Fortiadc HIGH 7.2
CVE-2025-49813

An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in Fortinet FortiADC version 7.2…

Fix: 7.1.2+
Fix from $1,950 2025-08-12
Fortiweb MEDIUM 6.7
CVE-2025-47857

A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version …

Fix: 7.4.9 / 7.6.4+
Fix from $1,600 2025-08-12
Fortisiem CRITICAL 9.8
CVE-2025-25256EPSS 60%

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiS…

Fix: 6.7.10 / 7.0.4+
Fix from $2,300 2025-08-12
Fortiweb MEDIUM 6.7
CVE-2025-27759

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6…

Fix: 7.0.11 / 7.2.11+
Fix from $1,600 2025-08-12
Unclassified CRITICAL 9.3
CVE-2012-10037

PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely passed to the exec() functio…

No fix yet
Fix from $2,300 2025-08-11
Unclassified CRITICAL 9.4
CVE-2012-10039

ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog parameter is passed directly into…

No fix yet
Fix from $2,300 2025-08-11
Unclassified CRITICAL 9.4
CVE-2012-10040

Openfiler v2.x contains a command injection vulnerability in the system.html page. The device parameter is used to instantiate a NetworkCard object, …

No fix yet
Fix from $2,300 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8830EPSS 8%

A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function su…

No fix yet
Fix from $1,950 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8829EPSS 8%

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the fun…

No fix yet
Fix from $1,950 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8828EPSS 8%

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function ipv6cmd of the f…

No fix yet
Fix from $1,950 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8827EPSS 8%

A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function um_inspect_cro…

No fix yet
Fix from $1,950 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8825EPSS 8%

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function RP_setBasicAuto…

No fix yet
Fix from $1,950 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8823EPSS 8%

A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function…

No fix yet
Fix from $1,950 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8821EPSS 8%

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function RP_setBas…

No fix yet
Fix from $1,950 2025-08-11
Re6250 Firmware HIGH 8.8
CVE-2025-8818EPSS 8%

A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function se…

No fix yet
Fix from $1,950 2025-08-10
Unclassified CRITICAL 9.3
CVE-2012-10046

The E-Mail Security Virtual Appliance (ESVA) (tested on version ESVA_2057) contains an unauthenticated command injection vulnerability in the learn-m…

No fix yet
Fix from $2,300 2025-08-08
Unclassified CRITICAL 9.3
CVE-2012-10041

WAN Emulator v2.3 contains two unauthenticated command execution vulnerabilities. The result.php script calls shell_exec() with unsanitized input fro…

No fix yet
Fix from $2,300 2025-08-08
Unclassified CRITICAL 9.3
CVE-2010-10013

An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior to 2.6. The flaw resides in …

No fix yet
Fix from $2,300 2025-08-08
Unclassified HIGH 8.8
CVE-2025-8748

MiR software versions prior to version 3.0.0 are affected by a command injection vulnerability. A malicious HTTP request crafted by an authenticated…

Mitigation only
Fix from $1,950 2025-08-08
Unclassified MEDIUM 6.3
CVE-2025-54958

Powered BLUE 870 versions 0.20130927 and prior contain an OS command injection vulnerability. If this vulnerability is exploited, arbitrary OS comman…

Mitigation only
Fix from $1,600 2025-08-08
Enzoh W5611t Firmware MEDIUM 6.7
CVE-2024-58257

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

Mitigation only
Fix from $1,600 2025-08-08
Enzoh W5611t Firmware HIGH 7.8
CVE-2024-58256

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

No fix yet
Fix from $1,950 2025-08-08
Enzoh W5611t Firmware MEDIUM 6.7
CVE-2024-58255

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

No fix yet
Fix from $1,600 2025-08-08
Unclassified MEDIUM 6.3
CVE-2025-8697

A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function StdioServerParameters of the comp…

Mitigation only
Fix from $1,600 2025-08-07