Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2025-13687 IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o… Datastage On Cloud Pak For Data 5.3.1+ Fix from $1,9502026-03-03 HIGH 8.8 CVE-2025-13688 IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o… Datastage On Cloud Pak For Data 5.3.1+ Fix from $1,9502026-03-03 HIGH 8.8 CVE-2025-13686 IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o… Datastage On Cloud Pak For Data 5.3.1+ Fix from $1,9502026-03-03 HIGH 7.5 CVE-2024-55021 Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol. Easyweb Mitigation only Fix from $1,9502026-03-03 CRITICAL 9.8 CVE-2024-55020 A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to… Easyweb Mitigation only Fix from $2,3002026-03-03 HIGH 7.2 CVE-2025-67840 Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Build 14614 through TZM_175758806… Tranzman No fix yet Fix from $1,9502026-03-03 HIGH 7.2 CVE-2025-63911 Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injection vulnerability. Tranzman No fix yet Fix from $1,9502026-03-03 HIGH 8.0 CVE-2026-0654 Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. … Deco Be25 Firmware after 1.1.1 Fix from $1,9502026-03-02 CRITICAL 9.8 CVE-2026-24101 An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, … Ac15 Firmware Mitigation only Fix from $2,3002026-03-02 HIGH 7.2 CVE-2025-50194 Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/cron/lang/check_parse_lang… Chamilo Lms 1.11.30+ Fix from $1,9502026-03-02 HIGH 7.2 CVE-2025-50195 Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/manage.co… Chamilo Lms 1.11.30+ Fix from $1,9502026-03-02 HIGH 7.2 CVE-2025-50196 Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/editinsta… Chamilo Lms 1.11.30+ Fix from $1,9502026-03-02 HIGH 7.2 CVE-2025-50197 Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/admin/sub_language_ajax.in… Chamilo Lms 1.11.30+ Fix from $1,9502026-03-02 HIGH 7.2 CVE-2025-50193 Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.ph… Chamilo Lms 1.11.30+ Fix from $1,9502026-03-02 CRITICAL 9.4 CVE-2025-30044 In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-bin/CliniNET.prd/utils/userlo… Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-28517EPSS 6% openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves … Opendcim Patch available Fix from $2,3002026-02-27 HIGH 7.2 CVE-2026-28409 WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA … Wegia 3.6.5+ Fix from $1,9502026-02-27 HIGH 7.8 CVE-2026-28417 Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plug… Vim 9.2.0073+ Fix from $1,9502026-02-27 CRITICAL 9.8 CVE-2026-21654 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum H… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 HIGH 8.8 CVE-2026-0980 A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with … Satellite after 0.12.1 Fix from $1,9502026-02-27 CRITICAL 9.8 CVE-2026-3301 A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file … N300rh Firmware Mitigation only Fix from $2,3002026-02-27 HIGH 8.8 CVE-2026-25196 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-25721 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-3037 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-25037 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-25105 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code e… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-20764 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-23702 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-24452 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-24695 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code ex… Xweb 500b Pro Firmware after 1.12.1 Fix from $1,9502026-02-27