Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2025-37171 Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Su… Arubaos 8.10.0.21 / 8.13.1.1+ Fix from $1,9502026-01-13 HIGH 7.2 CVE-2025-37172 Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Su… Arubaos 8.10.0.21 / 8.13.1.1+ Fix from $1,9502026-01-13 HIGH 7.2 CVE-2025-37170 Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Su… Arubaos 8.10.0.21 / 8.13.1.1+ Fix from $1,9502026-01-13 HIGH 8.6 CVE-2026-21267 Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec… Dreamweaver 21.7+ Fix from $1,9502026-01-13 CRITICAL 9.8 CVE-2025-64155EPSS 43% An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.… Fortisiem 7.1.9 / 7.2.7+ Fix from $2,3002026-01-13 MEDIUM 6.8 CVE-2025-13447EPSS 26% OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” pe… Connection Manager For Objectscale* 7.1.35.15 / 7.2.54.16+ Fix from $1,6002026-01-13 MEDIUM 6.8 CVE-2025-13444EPSS 26% OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” pe… Connection Manager For Objectscale 7.1.35.15 / 7.2.54.16+ Fix from $1,6002026-01-13 HIGH 8.4 CVE-2026-0507 Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrati… Mitigation only Fix from $1,9502026-01-13 CRITICAL 9.8 CVE-2026-22781 TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via … Tinyweb 1.98+ Fix from $2,3002026-01-12 HIGH 8.8 CVE-2026-0855 Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitra… Mitigation only Fix from $1,9502026-01-12 HIGH 8.8 CVE-2026-0854 Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary… Mitigation only Fix from $1,9502026-01-12 CRITICAL 9.8 CVE-2025-69269 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, L… Dx Netops Spectrum 23.3.7+ Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2025-15502EPSS 6% A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionContro… Operation And Maintenance Security Management System after 3.0.8 Fix from $2,3002026-01-10 CRITICAL 9.8 CVE-2025-15501EPSS 6% A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of th… Operation And Maintenance Security Management System after 3.0.8 Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-15500EPSS 6% A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file … Operation And Maintenance Management System after 3.0.8 Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-15499EPSS 5% A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN o… Operation And Maintenance Management System after 3.0.8 Fix from $2,3002026-01-09 HIGH 7.8 CVE-2026-0830 Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE b… Kiro Ide 0.6.18+ Fix from $1,9502026-01-09 HIGH 7.2 CVE-2025-46645 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version … Data Domain Operating System 7.10.1.80 / 7.13.1.50+ Fix from $1,9502026-01-09 MEDIUM 6.7 CVE-2025-46644 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version … Data Domain Operating System 7.10.1.80 / 7.13.1.50+ Fix from $1,6002026-01-09 HIGH 7.2 CVE-2025-66052 Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" … Ip7137 Firmware Mitigation only Fix from $1,9502026-01-09 HIGH 8.8 CVE-2025-64091 This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device. Tcis 3 Firmware 9.2.3.3+ Fix from $1,9502026-01-09 HIGH 7.3 CVE-2026-22035 Greenshot is an open source Windows screenshot utility. Versions 1.3.310 and below arvulnerable to OS Command Injection through unsanitized filename … Greenshot 1.3.311+ Fix from $1,9502026-01-08 HIGH 8.8 CVE-2019-25289 SmartLiving SmartLAN <=6.x contains an authenticated remote command injection vulnerability in the web.cgi binary through the 'par' POST parameter wi… No fix yet Fix from $1,9502026-01-08 HIGH 8.8 CVE-2017-20215EPSS 14% FLIR Thermal Camera FC-S/PT firmware version 8.0.0.64 contains an authenticated OS command injection vulnerability that allows attackers to execute s… No fix yet Fix from $1,9502026-01-08 CRITICAL 9.8 CVE-2017-20216EPSS 11% FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerF… Mitigation only Fix from $2,3002026-01-08 HIGH 7.8 CVE-2025-69262 pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .np… Pnpm 10.27.0+ Fix from $1,9502026-01-07 MEDIUM 6.9 CVE-2025-6225 Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to shell command injection via logi… Mitigation only Fix from $1,6002026-01-07 HIGH 7.2 CVE-2025-15472EPSS 20% A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL  of the file uapply.cgi of the component httpd . This ma… Tew 811dru Firmware No fix yet Fix from $1,9502026-01-07 CRITICAL 9.8 CVE-2025-15471EPSS 12% A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation… Tew 713re Firmware Mitigation only Fix from $2,3002026-01-07 HIGH 8.8 CVE-2020-36910 Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers … No fix yet Fix from $1,9502026-01-06