Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2025-56083 OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request … Rg Yst250f Firmware Mitigation only Fix from $1,9502025-12-11 HIGH 8.8 CVE-2025-56084 OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a cra… Rg Yst250f Firmware Mitigation only Fix from $1,9502025-12-11 HIGH 8.8 CVE-2025-56085 OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary comman… Rg Ew1200 Firmware No fix yet Fix from $1,9502025-12-11 HIGH 8.8 CVE-2025-56086 OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary comman… Rg Ew1200 Firmware No fix yet Fix from $1,9502025-12-11 HIGH 8.8 CVE-2025-56087 OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the run… Rg Bcr600w Firmware Mitigation only Fix from $1,9502025-12-11 HIGH 8.8 CVE-2025-56088 OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the acti… Rg Bcr860 Firmware No fix yet Fix from $1,9502025-12-11 HIGH 8.5 CVE-2025-67738 squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature … Patch available Fix from $1,9502025-12-11 HIGH 7.8 CVE-2025-65199 A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to exec… Windscribe after 2.17.10 Fix from $1,9502025-12-10 MEDIUM 5.0 CVE-2025-67640 Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary s… Git Client 6.4.1+ Fix from $1,6002025-12-10 HIGH 7.5 CVE-2025-66626 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions 3.6.13 and below and versio… Argo Workflows 3.6.14 / 3.7.5+ Fix from $1,9502025-12-09 CRITICAL 9.8 CVE-2021-47728 Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbit… Izero Box Full Firmware Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-65882 An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ip… Openmptcprouter after 0.64 Fix from $2,3002025-12-09 HIGH 7.2 CVE-2025-64153 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExte… Fortiextender Firmware after 7.6.3 Fix from $1,9502025-12-09 HIGH 7.2 CVE-2025-53679EPSS 12% An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiS… Fortisandbox 4.4.8 / 5.0.3+ Fix from $1,9502025-12-09 HIGH 8.8 CVE-2025-53949EPSS 17% An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiS… Fortisandbox after 5.0.2 Fix from $1,9502025-12-09 MEDIUM 6.3 CVE-2025-14204 A vulnerability has been found in TykoDev cherry-studio-TykoFork 0.1. This issue affects the function redirectToAuthorization of the file /.well-know… Mitigation only Fix from $1,6002025-12-07 CRITICAL 9.8 CVE-2025-66644 KEV Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. Arrayos Ag 9.4.5.9+ Fix from $2,3002025-12-05 CRITICAL 9.3 CVE-2020-36877 ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary… No fix yet Fix from $2,3002025-12-05 CRITICAL 9.8 CVE-2025-14093EPSS 20% A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The … Br 6478ac V3 Firmware Mitigation only Fix from $2,3002025-12-05 CRITICAL 9.8 CVE-2025-14094EPSS 21% A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulatio… Br 6478ac V3 Firmware Mitigation only Fix from $2,3002025-12-05 HIGH 7.2 CVE-2025-14092EPSS 17% A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the function sub_416898 of the file /boafrm/formDebugDia… Br 6478ac V3 Firmware No fix yet Fix from $1,9502025-12-05 CRITICAL 9.8 CVE-2025-66576 Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthentic… Remote Keyboard Desktop Mitigation only Fix from $2,3002025-12-04 MEDIUM 6.9 CVE-2025-66572 Loaded Commerce 6.6 contains a client-side template injection vulnerability via the search parameter that allows unauthenticated attackers to execute… No fix yet Fix from $1,6002025-12-04 HIGH 8.5 CVE-2024-58278 perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attack… No fix yet Fix from $1,9502025-12-04 CRITICAL 9.8 CVE-2025-29269 ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint. All Rut22gw Firmware Mitigation only Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-66208 Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online.… Online 25.04.702+ Fix from $2,3002025-12-03 CRITICAL 9.3 CVE-2025-34319 TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contain an OS command injection vul… Mitigation only Fix from $2,3002025-12-03 HIGH 8.8 CVE-2025-12744 A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places … Mitigation only Fix from $1,9502025-12-03 HIGH 8.8 CVE-2025-11787 Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()', 'CheckPing()' and 'TraceRout… Sge Plc1000 Firmware Mitigation only Fix from $1,9502025-12-02 CRITICAL 9.8 CVE-2025-66401 MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critica… Mcp Watch after 0.1.2 Fix from $2,3002025-12-01