Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Dir 615h Firmware HIGH 7.2
CVE-2013-10059EPSS 19%

An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tool…

Fix: after 8.04
Fix from $1,950 2025-08-01
Dgn2200b Firmware HIGH 7.2
CVE-2013-10060

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via…

Fix: after 1.1.0.36
Fix from $1,950 2025-08-01
Dgn1000b Firmware HIGH 7.2
CVE-2013-10061

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45…

No fix yet
Fix from $1,950 2025-08-01
Unclassified HIGH 8.7
CVE-2013-10053

A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htaccess files, the inHTUsername fi…

Mitigation only
Fix from $1,950 2025-08-01
Unclassified HIGH 8.6
CVE-2013-10058

An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 vi…

No fix yet
Fix from $1,950 2025-08-01
Dir 300 Firmware CRITICAL 9.8
CVE-2013-10048EPSS 12%

An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, res…

Fix: after 2.14b01
Fix from $2,300 2025-08-01
Unclassified CRITICAL 9.3
CVE-2013-10049

An OS command injection vulnerability exists in multiple Raidsonic NAS devices—specifically tested on IB-NAS5220 and IB-NAS4220—via the unauthenticat…

No fix yet
Fix from $2,300 2025-08-01
Dir 300 Firmware HIGH 8.8
CVE-2013-10050EPSS 10%

An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authentica…

Fix: after 4.13
Fix from $1,950 2025-08-01
Ilx 507 Firmware MEDIUM 6.6
CVE-2025-8473

Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code…

Mitigation only
Fix from $1,600 2025-08-01
Unclassified HIGH 7.3
CVE-2025-54595

Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged helper tool bundled with the Pe…

Patch available
Fix from $1,950 2025-08-01
Unclassified CRITICAL 9.8
CVE-2025-50475EPSS 8%

An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6, allowing unauthenticated attackers to execute arbitrary…

Mitigation only
Fix from $2,300 2025-07-31
Unclassified CRITICAL 10.0
CVE-2014-125124

An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, wh…

Mitigation only
Fix from $2,300 2025-07-31
Unclassified CRITICAL 9.3
CVE-2013-10037EPSS 10%

An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword…

No fix yet
Fix from $2,300 2025-07-31
Unclassified HIGH 8.7
CVE-2013-10039

A command injection vulnerability exists in GestioIP 3.0 commit ac67be and earlier in ip_checkhost.cgi. Crafted input to the 'ip' parameter allows at…

Mitigation only
Fix from $1,950 2025-07-31
Unclassified CRITICAL 9.1
CVE-2025-54430

dedupe is a python library that uses machine learning to perform fuzzy matching, deduplication and entity resolution quickly on structured data. Befo…

Patch available
Fix from $2,300 2025-07-30
Unclassified HIGH 8.8
CVE-2025-29534

An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker with valid credentials to exe…

Mitigation only
Fix from $1,950 2025-07-28
Codeigniter CRITICAL 9.8
CVE-2025-54418

CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the…

Fix: 4.6.2+
Fix from $2,300 2025-07-28
Unclassified CRITICAL 9.4
CVE-2025-53695

OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to th…

Mitigation only
Fix from $2,300 2025-07-28
Vaelsys CRITICAL 9.8
CVE-2025-8259

A vulnerability was identified in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. Affected by this issue is the function execute_DataObjectProc of the file /gri…

Mitigation only
Fix from $2,300 2025-07-28
Unclassified CRITICAL 9.1
CVE-2025-54415

dag-factory is a library for Apache Airflow® to construct DAGs declaratively via configuration files. In versions 0.23.0a8 and below, a high-severity…

Patch available
Fix from $2,300 2025-07-26
Unclassified CRITICAL 9.8
CVE-2025-29631

Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injectio…

Mitigation only
Fix from $2,300 2025-07-25
Unclassified CRITICAL 9.4
CVE-2014-125118

A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' par…

No fix yet
Fix from $2,300 2025-07-25
Wp Database Backup CRITICAL 9.8
CVE-2019-25224EPSS 17%

The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerabili…

Fix: 5.2+
Fix from $2,300 2025-07-25
Autocaliweb CRITICAL 9.8
CVE-2025-7404

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS …

Mitigation only
Fix from $2,300 2025-07-24
Unclassified CRITICAL 10.0
CVE-2025-5243

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi…

Mitigation only
Fix from $2,300 2025-07-24
Unclassified CRITICAL 9.3
CVE-2022-4978

Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, which is the …

Mitigation only
Fix from $2,300 2025-07-23
Unclassified CRITICAL 9.3
CVE-2015-10141EPSS 5%

An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick …

No fix yet
Fix from $2,300 2025-07-23
Unclassified HIGH 8.8
CVE-2025-41683

An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user i…

Mitigation only
Fix from $1,950 2025-07-23
Unclassified HIGH 8.8
CVE-2025-41684

An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user i…

Mitigation only
Fix from $1,950 2025-07-23
Router Manager HIGH 7.2
CVE-2024-53286

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Rou…

Fix: 1.3.1-9346+
Fix from $1,950 2025-07-23