Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
F9k1122 Firmware HIGH 8.8
CVE-2025-7082EPSS 15%

A vulnerability was found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this issue is the function formBSSetSitesurvey of the fil…

No fix yet
Fix from $1,950 2025-07-06
Unclassified MEDIUM 6.7
CVE-2025-47228EPSS 16%

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows authentica…

Mitigation only
Fix from $1,600 2025-07-05
Pandora Fms HIGH 8.8
CVE-2025-34088EPSS 5%

An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenti…

Fix: after 7.0_ng
Fix from $1,950 2025-07-03
Unclassified CRITICAL 9.3
CVE-2025-34082

A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Shadow services. The flaw arise…

Mitigation only
Fix from $2,300 2025-07-03
Pi Hole HIGH 8.8
CVE-2025-34087

An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, t…

Fix: after 3.3
Fix from $1,950 2025-07-03
Spaces Connector MEDIUM 6.7
CVE-2025-20308

A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the un…

Mitigation only
Fix from $1,600 2025-07-02
Unclassified CRITICAL 10.0
CVE-2025-34073

An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote attacker can execute arbitrary op…

Mitigation only
Fix from $2,300 2025-07-02
Unclassified HIGH 8.6
CVE-2025-53100

RestDB's Codehooks.io MCP Server is an MCP server on the Codehooks.io platform. Prior to version 0.2.2, the MCP server is written in a way that is vu…

Patch available
Fix from $1,950 2025-07-01
Unclassified CRITICAL 9.4
CVE-2025-34055

An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the A…

No fix yet
Fix from $2,300 2025-07-01
Unclassified CRITICAL 9.4
CVE-2025-34056

An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group mana…

No fix yet
Fix from $2,300 2025-07-01
Unclassified CRITICAL 10.0
CVE-2025-34054

An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input saniti…

Mitigation only
Fix from $2,300 2025-07-01
Unclassified CRITICAL 9.8
CVE-2025-26074

Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.

Mitigation only
Fix from $2,300 2025-06-30
Di 7300g\+ Firmware HIGH 8.8
CVE-2025-6899

A vulnerability, which was classified as critical, was found in D-Link DI-7300G+ and DI-8200G 17.12.20A1/19.12.25A1. This affects an unknown part of …

No fix yet
Fix from $1,950 2025-06-30
Di 7300g\+ Firmware HIGH 8.8
CVE-2025-6898EPSS 11%

A vulnerability, which was classified as critical, has been found in D-Link DI-7300G+ 19.12.25A1. Affected by this issue is some unknown functionalit…

Mitigation only
Fix from $1,950 2025-06-30
Di 7300g\+ Firmware CRITICAL 9.8
CVE-2025-6897

A vulnerability classified as critical was found in D-Link DI-7300G+ 19.12.25A1. Affected by this vulnerability is an unknown functionality of the fi…

Mitigation only
Fix from $2,300 2025-06-30
Di 7300g\+ Firmware HIGH 8.8
CVE-2025-6896

A vulnerability classified as critical has been found in D-Link DI-7300G+ 19.12.25A1. Affected is an unknown function of the file wget_test.asp. The …

No fix yet
Fix from $1,950 2025-06-30
Unclassified HIGH 7.8
CVE-2023-28906

A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the system to escalate privileges and…

Mitigation only
Fix from $1,950 2025-06-28
Unclassified HIGH 7.2
CVE-2025-36529

An OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnerability is exploited, an arbit…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified CRITICAL 9.4
CVE-2025-34049

An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version V2.1.11_X101 Build 1127.190306 and earlier. The rou…

No fix yet
Fix from $2,300 2025-06-26
Unclassified CRITICAL 9.4
CVE-2025-34042

An authenticated command injection vulnerability exists in the Beward N100 IP Camera firmware version M2.1.6.04C014 via the ServerName and TimeZone p…

Mitigation only
Fix from $2,300 2025-06-26
Unclassified CRITICAL 10.0
CVE-2025-34043EPSS 8%

A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper input sanitization in the board.c…

Mitigation only
Fix from $2,300 2025-06-26
Unclassified CRITICAL 9.4
CVE-2025-34044

A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP …

Mitigation only
Fix from $2,300 2025-06-26
Unclassified MEDIUM 6.0
CVE-2025-52573

iOS Simulator MCP Server (ios-simulator-mcp) is a Model Context Protocol (MCP) server for interacting with iOS simulators. Versions prior to 1.3.3 ar…

Patch available
Fix from $1,600 2025-06-26
Unclassified HIGH 8.8
CVE-2025-6562

Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allowing remote attackers with reg…

Mitigation only
Fix from $1,950 2025-06-26
Puppet Enterprise HIGH 8.8
CVE-2025-5459

A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary …

Fix: 2023.8.4+
Fix from $1,950 2025-06-26
Ca300 Poe Firmware CRITICAL 9.8
CVE-2025-6620

A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been rated as critical. Affected by this issue is the function setUpgradeUboot of th…

Mitigation only
Fix from $2,300 2025-06-25
Ca300 Poe Firmware CRITICAL 9.8
CVE-2025-6621

A vulnerability classified as critical has been found in TOTOLINK CA300-PoE 6.2c.884. This affects the function QuickSetting of the file ap.so. The m…

Mitigation only
Fix from $2,300 2025-06-25
Ca300 Poe Firmware CRITICAL 9.8
CVE-2025-6618

A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been classified as critical. Affected is the function SetWLanApcliSettings of the fi…

Mitigation only
Fix from $2,300 2025-06-25
Ca300 Poe Firmware CRITICAL 9.8
CVE-2025-6619

A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. Affected by this vulnerability is the function setUpgrade…

Mitigation only
Fix from $2,300 2025-06-25
Unclassified HIGH 8.8
CVE-2025-41427

WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vul…

Mitigation only
Fix from $1,950 2025-06-24