Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.1 CVE-2025-35028EPSS 5% By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI… Mitigation only Fix from $2,3002025-11-30 CRITICAL 9.3 CVE-2025-8890 Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell command injection attacks. In order… Mitigation only Fix from $2,3002025-11-27 HIGH 8.0 CVE-2025-65202EPSS 7% TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameter… Tew 657brm Firmware No fix yet Fix from $1,9502025-11-26 CRITICAL 10.0 CVE-2025-64126 An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without… Mitigation only Fix from $2,3002025-11-26 CRITICAL 10.0 CVE-2025-64127 An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are l… Mitigation only Fix from $2,3002025-11-26 CRITICAL 10.0 CVE-2025-64128 An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting… Mitigation only Fix from $2,3002025-11-26 CRITICAL 9.8 CVE-2025-62354 Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to execute commands… Mitigation only Fix from $2,3002025-11-26 CRITICAL 9.8 CVE-2025-66261 Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 30… Mozart Next 100 Firmware Mitigation only Fix from $2,3002025-11-26 CRITICAL 9.8 CVE-2025-66253 Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, … Mozart Next 100 Firmware Mitigation only Fix from $2,3002025-11-26 CRITICAL 9.2 CVE-2025-59366EPSS 16% An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality… Mitigation only Fix from $2,3002025-11-25 HIGH 7.5 CVE-2025-59370 A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially exe… Mitigation only Fix from $1,9502025-11-25 HIGH 7.5 CVE-2025-12742 A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Teradata driver parameters. Loo… Mitigation only Fix from $1,9502025-11-25 CRITICAL 9.3 CVE-2018-25126 Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and… No fix yet Fix from $2,3002025-11-24 CRITICAL 9.8 CVE-2025-64755 Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code rea… Claude Code 2.0.31+ Fix from $2,3002025-11-21 MEDIUM 6.2 CVE-2025-13087EPSS 7% A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code execution with root privileges.… Mitigation only Fix from $1,6002025-11-20 HIGH 7.3 CVE-2025-12121 Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized s… Lite Xl after 2.1.8 Fix from $1,9502025-11-20 CRITICAL 9.8 CVE-2025-60738 An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to e… Eve X1 Server Firmware Mitigation only Fix from $2,3002025-11-20 HIGH 7.3 CVE-2025-63932EPSS 8% D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary. The HNAP service provided b… Dir 868l Firmware No fix yet Fix from $1,9502025-11-19 HIGH 8.8 CVE-2025-34334 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in t… Fax Server after 2.6.23 Fix from $1,9502025-11-19 HIGH 8.8 CVE-2025-34335 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability i… Fax Server 2.6.23+ Fix from $1,9502025-11-19 HIGH 7.2 CVE-2025-37163 A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated at… Airwave 8.3.0.5+ Fix from $1,9502025-11-18 HIGH 8.8 CVE-2025-37157 A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to cond… Arubaos Cx 10.10.1170 / 10.13.1101+ Fix from $1,9502025-11-18 HIGH 8.8 CVE-2025-37158 A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to cond… Arubaos Cx 10.10.1170 / 10.13.1101+ Fix from $1,9502025-11-18 HIGH 7.2 CVE-2025-58034 KEVEPSS 56% An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiW… Fortiweb 7.0.12 / 7.2.12+ Fix from $1,9502025-11-18 HIGH 7.8 CVE-2025-63408 Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive… Agent Dvr after 6.6.7.0 Fix from $1,9502025-11-18 HIGH 8.8 CVE-2025-8693 A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could … Dm4200 B0 Firmware after 5.63 Fix from $1,9502025-11-18 HIGH 8.8 CVE-2025-13306EPSS 8% A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /bo… Dwr M920 Firmware No fix yet Fix from $1,9502025-11-18 HIGH 7.5 CVE-2025-64756 Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, the glob CLI contains a command… Glob 10.5.0 / 11.1.0+ Fix from $1,9502025-11-17 CRITICAL 9.8 CVE-2025-55055 CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Rumpus Mitigation only Fix from $2,3002025-11-17 HIGH 7.2 CVE-2025-34322EPSS 9% Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries… Log Server 2026+ Fix from $1,9502025-11-17