Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unity Operating Environment HIGH 7.8
CVE-2024-49564

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…

Fix: 5.5.0.0.5.259+
Fix from $1,950 2025-03-28
Unity Operating Environment HIGH 7.8
CVE-2024-49565

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…

Fix: 5.5.0.0.5.259+
Fix from $1,950 2025-03-28
A800r Firmware CRITICAL 9.8
CVE-2025-28138

The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function throu…

No fix yet
Fix from $2,300 2025-03-27
Total Upkeep HIGH 7.2
CVE-2025-2257

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all vers…

Fix: 1.17.0+
Fix from $1,950 2025-03-26
Unclassified MEDIUM 6.3
CVE-2025-2733

A vulnerability classified as critical has been found in mannaandpoem OpenManus up to 2025.3.13. This affects an unknown part of the file app/tool/py…

Mitigation only
Fix from $1,600 2025-03-25
Dir 823x Firmware HIGH 7.2
CVE-2025-2717

A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126/240802. This issue affects the function sub_41710C of the…

Mitigation only
Fix from $1,950 2025-03-25
Hcl Devops Deploy HIGH 7.2
CVE-2025-0255

HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending speciall…

Fix: 7.0.5.26 / 7.1.2.22+
Fix from $1,950 2025-03-24
Hibos CRITICAL 9.8
CVE-2025-2701EPSS 7%

A vulnerability classified as critical was found in AMTT Hotel Broadband Operation System 1.0. This vulnerability affects the function popen of the f…

No fix yet
Fix from $2,300 2025-03-24
Vllm CRITICAL 9.8
CVE-2024-9053

vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop…

No fix yet
Fix from $2,300 2025-03-20
Lollms Web Ui MEDIUM 6.7
CVE-2024-10019

A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The …

No fix yet
Fix from $1,600 2025-03-20
Unclassified HIGH 7.2
CVE-2025-24306

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.0_1101. I…

Mitigation only
Fix from $1,950 2025-03-18
Unclassified HIGH 8.8
CVE-2025-25220

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.1_1101. I…

Mitigation only
Fix from $1,950 2025-03-18
Unclassified MEDIUM 6.3
CVE-2025-2367

A vulnerability has been found in Oiwtech OIW-2431APGN-HP 2.5.3-B20131128 and classified as critical. This vulnerability affects unknown code of the …

Mitigation only
Fix from $1,600 2025-03-17
Unclassified HIGH 7.7
CVE-2025-30076

Koha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl report parameter.

Mitigation only
Fix from $1,950 2025-03-16
Ios Xr HIGH 8.8
CVE-2025-20138

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underly…

Fix: 24.2.21 / 24.4+
Fix from $1,950 2025-03-12
Fortisandbox HIGH 7.2
CVE-2024-54018EPSS 10%

Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged …

Fix: 4.4.6+
Fix from $1,950 2025-03-11
Fortiisolator HIGH 8.8
CVE-2024-55590

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolato…

Fix: 2.4.6+
Fix from $1,950 2025-03-11
Fortisandbox HIGH 8.8
CVE-2024-52961

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbo…

Fix: 4.0.6 / 4.2.8+
Fix from $1,950 2025-03-11
Fortianalyzer MEDIUM 6.7
CVE-2024-32123

Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions …

Fix: 7.2.6 / 7.2.8+
Fix from $1,600 2025-03-11
Unclassified HIGH 8.7
CVE-2025-22366

The authenticated firmware update capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because …

Mitigation only
Fix from $1,950 2025-03-11
Unclassified HIGH 8.7
CVE-2025-22367

The authenticated time setting capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS …

Mitigation only
Fix from $1,950 2025-03-11
Unclassified HIGH 8.7
CVE-2025-22368

The authenticated SCU firmware command of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS com…

Mitigation only
Fix from $1,950 2025-03-11
Scalance Lpe9403 Firmware HIGH 7.2
CVE-2025-27392

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly sanitize user in…

Fix: 4.0+
Fix from $1,950 2025-03-11
Scalance Lpe9403 Firmware HIGH 7.2
CVE-2025-27393

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly sanitize user in…

Fix: 4.0+
Fix from $1,950 2025-03-11
Scalance Lpe9403 Firmware HIGH 7.2
CVE-2025-27394

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly sanitize user in…

Fix: 4.0+
Fix from $1,950 2025-03-11
Emg5723 T50k Firmware HIGH 7.2
CVE-2024-11253

A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyxel VMG8825-T50K firmware vers…

Fix: after 5.50
Fix from $1,950 2025-03-11
Dx3300 T0 Firmware HIGH 7.2
CVE-2024-12009

A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier co…

Fix: after 5.50
Fix from $1,950 2025-03-11
Wx5610 B0 Firmware HIGH 7.2
CVE-2024-12010

A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and …

Fix: after 5.50
Fix from $1,950 2025-03-11
Ex1800t Firmware CRITICAL 9.8
CVE-2025-2095

A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the function setDmzCfg of the file /cg…

No fix yet
Fix from $2,300 2025-03-07
Ex1800t Firmware CRITICAL 9.8
CVE-2025-2096

A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function setRebootScheCfg…

No fix yet
Fix from $2,300 2025-03-07