Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Dmx958xr Firmware MEDIUM 6.8
CVE-2025-8638

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on…

Mitigation only
Fix from $1,600 2025-08-06
Dmx958xr Firmware MEDIUM 6.8
CVE-2025-8628

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on…

Mitigation only
Fix from $1,600 2025-08-06
Dmx958xr Firmware MEDIUM 6.8
CVE-2025-8629

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on…

Mitigation only
Fix from $1,600 2025-08-06
Dmx958xr Firmware MEDIUM 6.8
CVE-2025-8630

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on…

Mitigation only
Fix from $1,600 2025-08-06
Dmx958xr Firmware MEDIUM 6.8
CVE-2025-8631

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on…

Mitigation only
Fix from $1,600 2025-08-06
Dir 600 Firmware CRITICAL 9.8
CVE-2013-10069EPSS 12%

The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command in…

Fix: after 2.14b01
Fix from $2,300 2025-08-05
Unclassified CRITICAL 9.3
CVE-2012-10033

Narcissus is vulnerable to remote code execution via improper input handling in its image configuration workflow. Specifically, the backend.php scrip…

No fix yet
Fix from $2,300 2025-08-05
Unclassified HIGH 8.6
CVE-2012-10028

Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute ar…

No fix yet
Fix from $1,950 2025-08-05
Unclassified HIGH 8.6
CVE-2012-10029

Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated …

No fix yet
Fix from $1,950 2025-08-05
Unclassified HIGH 7.4
CVE-2025-43978

Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?fla…

Mitigation only
Fix from $1,950 2025-08-05
Unclassified HIGH 7.4
CVE-2025-43979EPSS 5%

An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute arbitrary OS system commands wi…

Mitigation only
Fix from $1,950 2025-08-05
Unclassified CRITICAL 9.3
CVE-2025-2611EPSS 6%

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session co…

Patch available
Fix from $2,300 2025-08-05
Apex One CRITICAL 9.8
CVE-2025-54987EPSS 17%

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and …

Patch available
Fix from $2,300 2025-08-05
Apex One CRITICAL 9.8
CVE-2025-54948 KEVEPSS 21%

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and …

Patch available
Fix from $2,300 2025-08-05
Claude Code CRITICAL 9.8
CVE-2025-54795

Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation…

Fix: 1.0.20+
Fix from $2,300 2025-08-05
Cursor CRITICAL 9.8
CVE-2025-54135

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the…

Fix: 1.3.9+
Fix from $2,300 2025-08-05
Unclassified CRITICAL 9.4
CVE-2025-34147

An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the d…

Mitigation only
Fix from $2,300 2025-08-04
N600r Firmware CRITICAL 9.8
CVE-2025-51390

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig func…

Mitigation only
Fix from $2,300 2025-08-04
Ruckus Smartzone Firmware HIGH 8.8
CVE-2025-44960

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.

Fix: 4.5.0.51 / 6.1.2+
Fix from $1,950 2025-08-04
Ruckus Smartzone Firmware HIGH 8.8
CVE-2025-44961

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

Fix: 4.5.0.51 / 6.1.2+
Fix from $1,950 2025-08-04
Data Domain Operating System MEDIUM 6.7
CVE-2025-30096

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version…

Fix: 7.10.1.60 / 7.13.1.30+
Fix from $1,600 2025-08-04
Data Domain Operating System MEDIUM 6.7
CVE-2025-30097

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version…

Fix: 7.10.1.60 / 7.13.1.30+
Fix from $1,600 2025-08-04
Data Domain Operating System MEDIUM 6.7
CVE-2025-30098

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version…

Fix: 7.10.1.60 / 7.13.1.30+
Fix from $1,600 2025-08-04
Data Domain Operating System HIGH 7.8
CVE-2025-30099

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version…

Fix: 7.10.1.60 / 7.13.1.30+
Fix from $1,950 2025-08-04
Unity Operating Environment CRITICAL 9.8
CVE-2025-36604EPSS 61%

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…

Fix: 5.5.1.0+
Fix from $2,300 2025-08-04
Unity Operating Environment HIGH 7.8
CVE-2025-36606

Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An authenticated attacker could…

Fix: 5.5.1.0+
Fix from $1,950 2025-08-04
Unity Operating Environment HIGH 7.8
CVE-2025-36607

Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potent…

Fix: 5.5.1.0+
Fix from $1,950 2025-08-04
Cursor CRITICAL 9.6
CVE-2025-54133

Cursor is a code editor built for programming with AI. In versions 1.17 through 1.2, there is a UI information disclosure vulnerability in Cursor's M…

Fix: 1.3+
Fix from $2,300 2025-08-02
Cursor HIGH 8.8
CVE-2025-54136EPSS 26%

Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by mod…

Fix: 1.3+
Fix from $1,950 2025-08-02
Devtools Integration HIGH 8.8
CVE-2025-54782EPSS 48%

Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulne…

Fix: 0.2.1+
Fix from $1,950 2025-08-02