Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Qurouter MEDIUM 6.7
CVE-2024-13087

A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have also gained an administrator …

Mitigation only
Fix from $1,600 2025-06-06
Unclassified HIGH 8.8
CVE-2011-10007

File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted filename. A file handle is opene…

Patch available
Fix from $1,950 2025-06-05
Unclassified CRITICAL 9.4
CVE-2025-49008

Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of `escapeshellcmd()` in `/compo…

Patch available
Fix from $2,300 2025-06-05
Dir 816 Firmware CRITICAL 9.8
CVE-2025-5620EPSS 7%

A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected is the function setipsec_config of the file /gofor…

Mitigation only
Fix from $2,300 2025-06-05
Dir 816 Firmware CRITICAL 9.8
CVE-2025-5621EPSS 7%

A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this vulnerability is the function qosClassifier o…

No fix yet
Fix from $2,300 2025-06-05
Dcs 932l Firmware HIGH 8.8
CVE-2025-5571EPSS 10%

A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. Affected is the function setSystemAdmin of the file /setSys…

No fix yet
Fix from $1,950 2025-06-04
Dcs 932l Firmware CRITICAL 9.8
CVE-2025-5573EPSS 12%

A vulnerability was found in D-Link DCS-932L 2.18.01. It has been rated as critical. Affected by this issue is the function setSystemWizard/setSystem…

No fix yet
Fix from $2,300 2025-06-04
Trojan HIGH 8.1
CVE-2025-5525

A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the function LogChan of the file…

Fix: after 2.15.3
Fix from $1,950 2025-06-03
Re9000 Firmware CRITICAL 9.8
CVE-2025-5447EPSS 33%

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It ha…

Mitigation only
Fix from $2,300 2025-06-02
Re9000 Firmware CRITICAL 9.8
CVE-2025-5446EPSS 21%

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It ha…

No fix yet
Fix from $2,300 2025-06-02
Re9000 Firmware CRITICAL 9.8
CVE-2025-5445EPSS 21%

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and cl…

Mitigation only
Fix from $2,300 2025-06-02
Re9000 Firmware CRITICAL 9.8
CVE-2025-5443EPSS 21%

A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.…

No fix yet
Fix from $2,300 2025-06-02
Re9000 Firmware CRITICAL 9.8
CVE-2025-5444EPSS 18%

A vulnerability has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 a…

Mitigation only
Fix from $2,300 2025-06-02
Re9000 Firmware CRITICAL 9.8
CVE-2025-5441EPSS 21%

A vulnerability classified as critical was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.0…

No fix yet
Fix from $2,300 2025-06-02
Re9000 Firmware CRITICAL 9.8
CVE-2025-5442EPSS 21%

A vulnerability, which was classified as critical, has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001…

Mitigation only
Fix from $2,300 2025-06-02
Re9000 Firmware HIGH 8.8
CVE-2025-5440EPSS 7%

A vulnerability classified as critical has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/…

No fix yet
Fix from $1,950 2025-06-02
Re9000 Firmware HIGH 8.8
CVE-2025-5439EPSS 7%

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It ha…

No fix yet
Fix from $1,950 2025-06-02
Wivia 5 Firmware HIGH 7.2
CVE-2025-41385

An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS command may be executed by a logged…

Mitigation only
Fix from $1,950 2025-05-30
Unclassified CRITICAL 9.4
CVE-2025-48047EPSS 14%

An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.

Mitigation only
Fix from $2,300 2025-05-29
Unclassified CRITICAL 9.6
CVE-2025-5277

aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run arbitrary …

Patch available
Fix from $2,300 2025-05-28
Llamaindex HIGH 7.8
CVE-2025-1753

LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the improper handling of the `--files`…

Patch available
Fix from $1,950 2025-05-28
Unclassified HIGH 8.7
CVE-2023-34873

On MOBOTIX P3 cameras before MX-V4.7.2.18 and Mx6 cameras before MX-V5.2.0.61, the tcpdump feature does not properly validate input, which allows aut…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified HIGH 7.3
CVE-2025-5106

A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the file /app/fax/fax_view.php o…

Mitigation only
Fix from $1,950 2025-05-23
Asterisk HIGH 7.8
CVE-2025-47780

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14…

Fix: 18.9 / 18.26.2+
Fix from $1,950 2025-05-22
Cph2 Echarge Firmware HIGH 8.8
CVE-2025-3883

eCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to exe…

Mitigation only
Fix from $1,950 2025-05-22
Cph2 Echarge Firmware HIGH 8.8
CVE-2025-3881

eCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attacker…

Mitigation only
Fix from $1,950 2025-05-22
Cph2 Echarge Firmware HIGH 8.8
CVE-2025-3882

eCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attac…

Mitigation only
Fix from $1,950 2025-05-22
Unclassified MEDIUM 6.6
CVE-2025-48069

ejson2env allows users to decrypt EJSON secrets and export them as environment variables. Prior to version 2.0.8, the `ejson2env` tool has a vulnerab…

Patch available
Fix from $1,600 2025-05-21
Killwxapkg HIGH 8.1
CVE-2025-5030

A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affects the function processFile of…

Fix: after 2.4.1
Fix from $1,950 2025-05-21
Unclassified MEDIUM 6.8
CVE-2025-48204

The ns_backup extension through 13.0.0 for TYPO3 allows command injection.

Mitigation only
Fix from $1,600 2025-05-21