Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Ex1800t Firmware CRITICAL 9.8
CVE-2025-2094EPSS 13%

A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. It has been rated as critical. Affected by this issue is the function setWiFiEx…

No fix yet
Fix from $2,300 2025-03-07
Qurouter HIGH 7.2
CVE-2024-53700

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained adm…

Mitigation only
Fix from $1,950 2025-03-07
Qurouter CRITICAL 9.8
CVE-2024-50390

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrar…

Mitigation only
Fix from $2,300 2025-03-07
Unclassified HIGH 7.7
CVE-2024-13892

Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are vulnerable to command injecti…

Mitigation only
Fix from $1,950 2025-03-06
Ic 7100 Firmware CRITICAL 9.8
CVE-2025-1316 KEVEPSS 73%

Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device

Mitigation only
Fix from $2,300 2025-03-05
Broadlinkmanager MEDIUM 6.5
CVE-2025-26320

t0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via the IP Address parameter at /device/ping.

Fix: after 5.9.1
Fix from $1,600 2025-03-04
X18 Firmware HIGH 8.8
CVE-2025-1829EPSS 12%

A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been declared as critical. This vulnerability affects the function setMtknat…

No fix yet
Fix from $1,950 2025-03-02
Ac7 Firmware CRITICAL 9.8
CVE-2025-1819

A vulnerability, which was classified as critical, was found in Tenda AC7 1200M 15.03.06.44. Affected is the function TendaTelnet of the file /goform…

Mitigation only
Fix from $2,300 2025-03-02
Unclassified MEDIUM 5.1
CVE-2025-20161

A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode cou…

Mitigation only
Fix from $1,600 2025-02-26
Education And Training System CRITICAL 9.8
CVE-2025-1676

A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. Affected by this vulnerability is the function pdf2…

Mitigation only
Fix from $2,300 2025-02-25
Wegia CRITICAL 9.8
CVE-2025-27140

WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA app…

Fix: 3.2.15+
Fix from $2,300 2025-02-24
Unclassified CRITICAL 10.0
CVE-2025-27364EPSS 26%

In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compila…

Patch available
Fix from $2,300 2025-02-24
Unclassified HIGH 8.4
CVE-2025-22495

An improper input validation vulnerability was discovered in the NTP server configuration field of the Network-M2 card. This could result in an authe…

Mitigation only
Fix from $1,950 2025-02-24
An5506 01a Firmware CRITICAL 9.8
CVE-2025-1616EPSS 8%

A vulnerability, which was classified as critical, has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this issue is some unknown fun…

Mitigation only
Fix from $2,300 2025-02-24
Ac1900 Firmware CRITICAL 9.8
CVE-2025-1609EPSS 10%

A vulnerability has been found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this vulnerability is the function websGetVar o…

No fix yet
Fix from $2,300 2025-02-24
Ac1900 Firmware CRITICAL 9.8
CVE-2025-1610EPSS 13%

A vulnerability was found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this issue is the function websGetVar of the file /g…

No fix yet
Fix from $2,300 2025-02-24
Ac1900 Firmware CRITICAL 9.8
CVE-2025-1608EPSS 10%

A vulnerability, which was classified as critical, was found in LB-LINK AC1900 Router 1.0.2. Affected is the function websGetVar of the file /goform/…

No fix yet
Fix from $2,300 2025-02-24
Unclassified HIGH 8.8
CVE-2025-27106

binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-trading-bot can achieve Remot…

Patch available
Fix from $1,950 2025-02-21
Unclassified HIGH 7.3
CVE-2025-1546

A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210 and classified as critical. Affected by this vulnerabi…

Mitigation only
Fix from $1,950 2025-02-21
Unclassified HIGH 7.3
CVE-2025-1536

A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208. It has been declared as critical. This vulnerability affects …

Mitigation only
Fix from $1,950 2025-02-21
Unclassified CRITICAL 9.9
CVE-2025-1265

An OS command injection vulnerability exists in Vinci Protocol Analyzer that could allow an attacker to escalate privileges and perform code executio…

Mitigation only
Fix from $2,300 2025-02-20
Unclassified HIGH 7.2
CVE-2025-26856

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlie…

Mitigation only
Fix from $1,950 2025-02-20
Dsl 3782 Firmware HIGH 8.0
CVE-2025-25894

An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the samba_wg and samba_nbn parameters. This vulnerability allows at…

Mitigation only
Fix from $1,950 2025-02-18
Dsl 3782 Firmware HIGH 8.0
CVE-2025-25895

An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the public_type parameter. This vulnerability allows attackers to e…

Mitigation only
Fix from $1,950 2025-02-18
Dsl 3782 Firmware HIGH 8.0
CVE-2025-25893

An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocol paramete…

Mitigation only
Fix from $1,950 2025-02-18
Wegia CRITICAL 9.8
CVE-2025-26613

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection vulnerability was discovered …

Fix: 3.2.14+
Fix from $2,300 2025-02-18
Unclassified CRITICAL 9.8
CVE-2021-46686

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in acmailer CGI ver.4.0.3 and earlier and acm…

Mitigation only
Fix from $2,300 2025-02-18
Escan Anti Virus MEDIUM 5.3
CVE-2025-1370

A vulnerability, which was classified as critical, has been found in MicroWorld eScan Antivirus 7.0.32 on Linux. Affected by this issue is the functi…

No fix yet
Fix from $1,600 2025-02-17
X18 Firmware HIGH 8.8
CVE-2025-1339

A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been rated as critical. This issue affects the function setL2tpdConfig of th…

Mitigation only
Fix from $1,950 2025-02-16
Fabric Operating System HIGH 8.0
CVE-2024-5461

Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script…

Fix: 8.2.3e1+
Fix from $1,950 2025-02-15