Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Aapanel MEDIUM 6.5
CVE-2024-42922

AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.

Fix: after 7.0.7
Fix from $1,600 2025-05-21
Unclassified MEDIUM 6.5
CVE-2025-27804

Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishing a specially crafted messag…

Mitigation only
Fix from $1,600 2025-05-21
Wl Wn579a3 Firmware CRITICAL 9.8
CVE-2025-44880

A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a c…

No fix yet
Fix from $2,300 2025-05-20
Wl Wn579a3 Firmware CRITICAL 9.8
CVE-2025-44882

A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands vi…

No fix yet
Fix from $2,300 2025-05-20
Unclassified HIGH 8.8
CVE-2025-41225

The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run sc…

Mitigation only
Fix from $1,950 2025-05-20
Imagemagick Engine HIGH 7.2
CVE-2024-6486

The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" param…

Fix: 1.7.11+
Fix from $1,950 2025-05-15
Unclassified CRITICAL 9.8
CVE-2025-32002

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA network attached hard disk 'HDL-T…

Mitigation only
Fix from $2,300 2025-05-15
Unclassified HIGH 8.9
CVE-2025-47782

motionEye is an online interface for the software motion, a video surveillance program with motion detection. In versions 0.43.1b1 through 0.43.1b3, …

Patch available
Fix from $1,950 2025-05-14
Itop HIGH 8.5
CVE-2025-24022

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend o…

Fix: 2.7.12 / 3.1.3+
Fix from $1,950 2025-05-14
Coldfusion CRITICAL 9.1
CVE-2025-43562EPSS 45%

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co…

Mitigation only
Fix from $2,300 2025-05-13
A3002r Firmware CRITICAL 9.8
CVE-2025-45858EPSS 11%

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.

No fix yet
Fix from $2,300 2025-05-13
Scalance Lpe9403 Firmware HIGH 7.8
CVE-2025-40582

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Edge Client installed). Affecte…

Mitigation only
Fix from $1,950 2025-05-13
Ozw672 Firmware CRITICAL 9.8
CVE-2025-26389

A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does not sanit…

Fix: 8.0+
Fix from $2,300 2025-05-13
Sma 100 Firmware HIGH 7.2
CVE-2025-32821EPSS 20%

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command argu…

Fix: 10.2.1.15-81sv+
Fix from $1,950 2025-05-07
Catalyst Sd Wan Manager MEDIUM 5.5
CVE-2025-20213

A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite…

Mitigation only
Fix from $1,600 2025-05-07
Ios Xe MEDIUM 6.5
CVE-2025-20193

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perfo…

Mitigation only
Fix from $1,600 2025-05-07
Ios Xe MEDIUM 5.4
CVE-2025-20194

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perfo…

Mitigation only
Fix from $1,600 2025-05-07
Ios Xe HIGH 8.8
CVE-2025-20186

A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software could allow an authenticated, r…

Mitigation only
Fix from $1,950 2025-05-07
E5600 Firmware CRITICAL 9.8
CVE-2025-45491

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parame…

No fix yet
Fix from $2,300 2025-05-06
Ac9 Firmware CRITICAL 9.8
CVE-2025-45042

Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.

No fix yet
Fix from $2,300 2025-05-05
Mb Secure Firmware HIGH 8.8
CVE-2025-2605EPSS 13%

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abus…

Fix: 03.09 / 12.53+
Fix from $1,950 2025-05-02
Model S Firmware HIGH 7.8
CVE-2024-6032

Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code…

Fix: 2024.8+
Fix from $1,950 2025-04-30
Unclassified HIGH 8.8
CVE-2025-24351

A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to e…

Mitigation only
Fix from $1,950 2025-04-30
Aworld HIGH 8.1
CVE-2025-4032

A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as critical. This issue affects the…

Fix: after 2025-04-24
Fix from $1,950 2025-04-28
Seppmail HIGH 8.8
CVE-2022-41871

SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context…

Fix: after 12.1.17
Fix from $1,950 2025-04-28
Unclassified CRITICAL 9.1
CVE-2025-46271

UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.

Mitigation only
Fix from $2,300 2025-04-24
Unclassified CRITICAL 9.1
CVE-2025-46272

WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacker to execute OS commands on …

Mitigation only
Fix from $2,300 2025-04-24
Unclassified CRITICAL 9.2
CVE-2025-43858

YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, a…

Patch available
Fix from $2,300 2025-04-24
Fabric Operating System MEDIUM 6.7
CVE-2025-1976 KEV

Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary…

Fix: 9.1.1d7+
Fix from $1,600 2025-04-24
Router Firmware HIGH 7.2
CVE-2025-2773

BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu…

Mitigation only
Fix from $1,950 2025-04-23