Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Poly Clariti Manager MEDIUM 6.8
CVE-2025-43020

A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could al…

Fix: 10.12.2+
Fix from $1,600 2025-07-22
Yt Dlp HIGH 8.1
CVE-2025-54072

yt-dlp is a feature-rich command-line audio/video downloader. In versions 2025.06.25 and below, when the --exec option is used on Windows with the de…

Fix: 2025.07.21+
Fix from $1,950 2025-07-22
Unclassified HIGH 8.5
CVE-2025-7723

A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affec…

Mitigation only
Fix from $1,950 2025-07-22
Unclassified HIGH 8.7
CVE-2025-7724

An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1:…

Mitigation only
Fix from $1,950 2025-07-22
Unclassified CRITICAL 9.3
CVE-2025-34143EPSS 31%

An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal S…

Mitigation only
Fix from $2,300 2025-07-22
Unclassified HIGH 7.2
CVE-2025-53472

WRC-BE36QS-B and WRC-W701-B contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in We…

Mitigation only
Fix from $1,950 2025-07-22
Urve Web Manager CRITICAL 9.8
CVE-2025-36846

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated u…

Mitigation only
Fix from $2,300 2025-07-21
Ruckus Unleashed CRITICAL 9.1
CVE-2025-46117

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, …

Fix: 10.5.1.0.279 / 200.15.6.212.14+
Fix from $2,300 2025-07-21
Firewall Firmware CRITICAL 9.8
CVE-2025-6704EPSS 8%

An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to…

Fix: 21.0.2+
Fix from $2,300 2025-07-21
Firewall Firmware HIGH 8.8
CVE-2025-7382

A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-a…

Fix: 21.0.2+
Fix from $1,950 2025-07-21
Mbnet.mini Firmware HIGH 7.2
CVE-2025-41674

A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of …

Fix: 2.3.3+
Fix from $1,950 2025-07-21
Mbnet.mini Firmware HIGH 7.2
CVE-2025-41675

A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neu…

Fix: 2.3.3+
Fix from $1,950 2025-07-21
Mbnet.mini Firmware HIGH 7.2
CVE-2025-41673

A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of sp…

Fix: 2.3.3+
Fix from $1,950 2025-07-21
Wavesuite Noc HIGH 8.4
CVE-2025-24938

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged a…

Mitigation only
Fix from $1,950 2025-07-21
Wavesuite Noc CRITICAL 9.0
CVE-2025-24936

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound …

No fix yet
Fix from $2,300 2025-07-21
Xxl Job HIGH 8.8
CVE-2025-7788EPSS 5%

A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability is the function commandJobHa…

Fix: after 3.1.1
Fix from $1,950 2025-07-18
Unclassified CRITICAL 9.3
CVE-2025-34125

An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware ver…

No fix yet
Fix from $2,300 2025-07-16
Unclassified HIGH 8.7
CVE-2025-34129

A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 due to insufficient …

Mitigation only
Fix from $1,950 2025-07-16
Unclassified CRITICAL 9.3
CVE-2025-34132

A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field…

Mitigation only
Fix from $2,300 2025-07-16
Unclassified CRITICAL 9.3
CVE-2025-34117EPSS 20%

A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the pres…

No fix yet
Fix from $2,300 2025-07-16
Unclassified MEDIUM 5.4
CVE-2025-52379EPSS 10%

Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below contains an authenticated command injection vulnerability in the firmware update fea…

Mitigation only
Fix from $1,600 2025-07-15
Unclassified HIGH 8.7
CVE-2025-34116

A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated att…

No fix yet
Fix from $1,950 2025-07-15
Unclassified CRITICAL 10.0
CVE-2025-34112

An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances…

Mitigation only
Fix from $2,300 2025-07-15
Unclassified HIGH 8.7
CVE-2025-34113

An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET param…

No fix yet
Fix from $1,950 2025-07-15
Unclassified HIGH 8.7
CVE-2025-34115

An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endp…

No fix yet
Fix from $1,950 2025-07-15
Unclassified CRITICAL 9.3
CVE-2025-34103

An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due to improper input handling i…

No fix yet
Fix from $2,300 2025-07-15
Unclassified HIGH 8.9
CVE-2025-53818

GitHub Kanban MCP Server is a Model Context Protocol (MCP) server for managing GitHub issues in Kanban board format and streamlining LLM task managem…

Mitigation only
Fix from $1,950 2025-07-14
Unclassified HIGH 8.1
CVE-2025-53623

The Job Iteration API is an an extension for ActiveJob that make jobs interruptible and resumable Versions prior to 1.11.0 have an arbitrary code exe…

Patch available
Fix from $1,950 2025-07-14
Unclassified CRITICAL 9.8
CVE-2025-7451

The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands…

Mitigation only
Fix from $2,300 2025-07-14
Dir 818lw Firmware HIGH 7.2
CVE-2025-7553

A vulnerability classified as critical has been found in D-Link DIR-818LW up to 20191215. This affects an unknown part of the component System Time P…

Fix: 20191215+
Fix from $1,950 2025-07-14