Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 8.3
CVE-2013-3307EPSS 53%

Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacte…

Mitigation only
Fix from $1,950 2025-07-11
Junos MEDIUM 6.7
CVE-2025-52988

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS a…

Fix: 21.2 / 22.4+
Fix from $1,600 2025-07-11
Unclassified CRITICAL 9.5
CVE-2025-50121EPSS 18%

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenti…

Mitigation only
Fix from $2,300 2025-07-11
Meshtastic Firmware HIGH 8.0
CVE-2025-53637

Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has ext…

Fix: 2.6.6+
Fix from $1,950 2025-07-10
O3 Firmware HIGH 8.8
CVE-2025-7414EPSS 13%

A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function fromNetToolGet of the file /go…

No fix yet
Fix from $1,950 2025-07-10
Unclassified CRITICAL 9.3
CVE-2025-34102EPSS 7%

A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploitation of SQL injection and c…

No fix yet
Fix from $2,300 2025-07-10
Unclassified CRITICAL 9.3
CVE-2025-34099

An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vicidial_sales_viewer.php compone…

No fix yet
Fix from $2,300 2025-07-10
Unclassified CRITICAL 9.3
CVE-2025-34101

An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, in the /rest/action API endpoi…

No fix yet
Fix from $2,300 2025-07-10
Unclassified HIGH 7.5
CVE-2025-34093

An authenticated command injection vulnerability exists in the Polycom HDX Series command shell interface accessible over Telnet. The lan traceroute …

No fix yet
Fix from $1,950 2025-07-10
Unclassified CRITICAL 9.3
CVE-2025-34095

An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial interface provided by the examples…

No fix yet
Fix from $2,300 2025-07-10
Unclassified HIGH 7.7
CVE-2025-53542

Headlamp is an extensible Kubernetes web UI. A command injection vulnerability was discovered in the codeSign.js script used in the macOS packaging w…

Patch available
Fix from $1,950 2025-07-10
Unclassified HIGH 8.6
CVE-2025-46334

Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv f…

Mitigation only
Fix from $1,950 2025-07-10
Unclassified HIGH 8.6
CVE-2025-27614

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a u…

Patch available
Fix from $1,950 2025-07-10
D6400 Firmware HIGH 8.8
CVE-2025-7407EPSS 9%

A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. This affects an unknown part of the file diag.cgi. The manip…

No fix yet
Fix from $1,950 2025-07-10
Unclassified CRITICAL 9.6
CVE-2025-6514EPSS 78%

mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response …

Patch available
Fix from $2,300 2025-07-09
Unclassified CRITICAL 10.0
CVE-2025-3499

The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). Exploiting OS command injec…

Mitigation only
Fix from $2,300 2025-07-09
Coldfusion HIGH 7.9
CVE-2025-49537

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co…

Mitigation only
Fix from $1,950 2025-07-08
Endpoint Manager Mobile HIGH 7.2
CVE-2025-6771EPSS 17%

OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker w…

Fix: 12.3.0.3 / 12.4.0.3+
Fix from $1,950 2025-07-08
Endpoint Manager Mobile HIGH 7.2
CVE-2025-6770EPSS 16%

OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to …

Fix: 12.3.0.3 / 12.4.0.3+
Fix from $1,950 2025-07-08
Charx Sec 3000 Firmware HIGH 8.4
CVE-2025-25269

An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.

Fix: 1.7.3+
Fix from $1,950 2025-07-08
N200re Firmware HIGH 8.8
CVE-2025-7154

A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this is…

No fix yet
Fix from $1,950 2025-07-08
Splunk MEDIUM 6.8
CVE-2025-20319

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-privilege capability `edit_script…

Fix: 9.1.10 / 9.2.7+
Fix from $1,600 2025-07-07
Dokploy HIGH 8.8
CVE-2025-53376

Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated…

Fix: 0.23.7+
Fix from $1,950 2025-07-07
Unclassified MEDIUM 6.8
CVE-2025-3705

A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of special elements used in an OS …

Mitigation only
Fix from $1,600 2025-07-07
Unclassified CRITICAL 9.1
CVE-2025-3626

A remote attacker with administrator account can gain full control of the device due to improper neutralization of special elements used in an OS Com…

Mitigation only
Fix from $2,300 2025-07-07
Unclassified CRITICAL 9.8
CVE-2025-48501

An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be…

Mitigation only
Fix from $2,300 2025-07-07
Unclassified HIGH 7.2
CVE-2025-7145

ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers with product platform intermedia…

Mitigation only
Fix from $1,950 2025-07-07
Internet Security HIGH 8.8
CVE-2025-7097

A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This issue affects some unknown pr…

No fix yet
Fix from $1,950 2025-07-06
F9k1122 Firmware HIGH 8.8
CVE-2025-7083EPSS 41%

A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. This affects the function mp of the file /goform/mp of the c…

No fix yet
Fix from $1,950 2025-07-06
F9k1122 Firmware HIGH 8.8
CVE-2025-7081EPSS 17%

A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this vulnerability is the function formSetWanStatic …

No fix yet
Fix from $1,950 2025-07-06