Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified CRITICAL 9.8
CVE-2025-43879

WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in the …

Mitigation only
Fix from $2,300 2025-06-24
Unclassified CRITICAL 9.8
CVE-2025-48890

WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mini…

Mitigation only
Fix from $2,300 2025-06-24
Unclassified CRITICAL 9.8
CVE-2025-6559

Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary…

Mitigation only
Fix from $2,300 2025-06-24
Unclassified CRITICAL 10.0
CVE-2025-34041EPSS 7%

An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.…

Mitigation only
Fix from $2,300 2025-06-24
Unclassified CRITICAL 10.0
CVE-2025-34037EPSS 91%

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over …

Mitigation only
Fix from $2,300 2025-06-24
Blue Angel Software Suite HIGH 8.8
CVE-2025-34033

An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the we…

No fix yet
Fix from $1,950 2025-06-24
Esr300 Firmware CRITICAL 9.8
CVE-2025-34035EPSS 12%

An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to proper…

Mitigation only
Fix from $2,300 2025-06-24
Td 2108ts Cl Firmware CRITICAL 9.8
CVE-2025-34036EPSS 26%

An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" tha…

Mitigation only
Fix from $2,300 2025-06-24
Unclassified MEDIUM 6.6
CVE-2025-2172EPSS 10%

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities,…

Mitigation only
Fix from $1,600 2025-06-23
Unclassified HIGH 8.4
CVE-2025-23049

Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.

Mitigation only
Fix from $1,950 2025-06-23
A3002r Firmware MEDIUM 6.3
CVE-2025-6485EPSS 7%

A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the function formWlSiteSurvey of …

No fix yet
Fix from $1,600 2025-06-22
Ew 7438rpn Mini Firmware HIGH 8.8
CVE-2025-34024

An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp end…

Fix: after 1.13
Fix from $1,950 2025-06-20
Ew 7438rpn Mini Firmware HIGH 8.8
CVE-2025-34029

An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /gofo…

Fix: after 1.13
Fix from $1,950 2025-06-20
Unclassified CRITICAL 10.0
CVE-2025-34030EPSS 60%

An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails to saniti…

Mitigation only
Fix from $2,300 2025-06-20
Minidvblinux CRITICAL 9.8
CVE-2025-25038EPSS 5%

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly s…

Fix: after 5.4
Fix from $2,300 2025-06-20
Unclassified CRITICAL 9.8
CVE-2025-44635

There are multiple unauthorized remote command execution vulnerabilities in the H3C ER2200G2, ERG2-450W, ERG2-1200W, ERG2-1350W, NR1200W series route…

Mitigation only
Fix from $2,300 2025-06-20
Unclassified MEDIUM 5.9
CVE-2025-6193

A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob c…

Patch available
Fix from $1,600 2025-06-20
Wegia CRITICAL 9.8
CVE-2025-50201

WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, an OS Command Injection vulnerability was identified in the /html/configu…

Fix: 3.4.2+
Fix from $2,300 2025-06-19
Unclassified HIGH 8.8
CVE-2025-6104

A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects an unknown part of the file …

Mitigation only
Fix from $1,950 2025-06-16
Unclassified HIGH 8.8
CVE-2025-6102

A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown function…

Mitigation only
Fix from $1,950 2025-06-16
Unclassified HIGH 8.8
CVE-2025-6103

A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affected by this issue is some unkno…

Mitigation only
Fix from $1,950 2025-06-16
Unclassified HIGH 7.2
CVE-2025-39240

Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with va…

Mitigation only
Fix from $1,950 2025-06-13
Unclassified HIGH 8.4
CVE-2025-4230

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run…

Mitigation only
Fix from $1,950 2025-06-13
Unclassified CRITICAL 9.8
CVE-2025-41663

For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary commands in responses returned by W…

Mitigation only
Fix from $2,300 2025-06-11
Fortiadc HIGH 7.2
CVE-2025-31104

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiADC 7.6.0 through 7.6.1,…

Fix: 7.1.5 / 7.2.8+
Fix from $1,950 2025-06-10
Unclassified HIGH 7.2
CVE-2024-13089

An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execute unauthorized arbitrary OS c…

Mitigation only
Fix from $1,950 2025-06-10
Unclassified MEDIUM 5.5
CVE-2025-5743

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote contr…

Mitigation only
Fix from $1,600 2025-06-10
Unclassified HIGH 7.3
CVE-2025-5952

A vulnerability, which was classified as critical, has been found in Zend.To up to 6.10-6 Beta. This issue affects the function exec of the file NSSD…

Mitigation only
Fix from $1,950 2025-06-10
Haxcms Nodejs HIGH 8.8
CVE-2025-49141

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a …

Fix: 11.0.0 / 11.0.3+
Fix from $1,950 2025-06-09
Qts HIGH 8.8
CVE-2025-22481

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow rem…

Mitigation only
Fix from $1,950 2025-06-06