Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.1 CVE-2025-63916 MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The application fails to properly sanitize… Myscreentools after 2.2.1.0 Fix from $1,9502025-11-17 CRITICAL 9.8 CVE-2025-13284 ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands a… Mitigation only Fix from $2,3002025-11-17 CRITICAL 9.3 CVE-2021-4470 TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd POST parameter is passed dir… Mitigation only Fix from $2,3002025-11-14 HIGH 8.7 CVE-2021-4466 IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. … No fix yet Fix from $1,9502025-11-14 HIGH 7.2 CVE-2025-64444 Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploi… Mitigation only Fix from $1,9502025-11-14 HIGH 8.8 CVE-2025-20349 A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitrary commands in a restricted … Catalyst Center 2.3.7.10+ Fix from $1,9502025-11-13 HIGH 8.8 CVE-2025-12763 pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True duri… Pgadmin 4 9.10+ Fix from $1,9502025-11-13 MEDIUM 6.8 CVE-2025-42892 Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network acc… Business Connector Mitigation only Fix from $1,6002025-11-11 CRITICAL 10.0 CVE-2025-10230EPSS 40% A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validati… Mitigation only Fix from $2,3002025-11-07 HIGH 7.2 CVE-2025-64328 KEVEPSS 85% FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestor… Filestore 17.0.3+ Fix from $1,9502025-11-07 CRITICAL 9.3 CVE-2025-11546 CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleServerSafe … Mitigation only Fix from $2,3002025-11-07 HIGH 7.8 CVE-2025-12489 evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privilege… Patch available Fix from $1,9502025-11-06 HIGH 7.2 CVE-2025-34239 Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows a… Webaccess\/vpn 1.1.5+ Fix from $1,9502025-11-06 CRITICAL 9.8 CVE-2022-50596 D-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability within the web management inter… Dir 1260 Firmware after 1.20b05 Fix from $2,3002025-11-06 CRITICAL 9.8 CVE-2025-63334 PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The… Pocketvj Control Panel Firmware Mitigation only Fix from $2,3002025-11-05 CRITICAL 9.1 CVE-2025-45378 Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command s… Cloudlink after 8.1.2 Fix from $2,3002025-11-05 HIGH 8.4 CVE-2025-45379 Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to … Cloudlink 8.2+ Fix from $1,9502025-11-05 HIGH 7.2 CVE-2025-30479 Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control … Cloudlink 8.2+ Fix from $1,9502025-11-05 CRITICAL 9.8 CVE-2025-61304 OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address. Activegate Ping Extension after 1.016 Fix from $2,3002025-11-05 HIGH 8.0 CVE-2025-10622 A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve … Mitigation only Fix from $1,9502025-11-05 HIGH 8.8 CVE-2025-64109 Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta allowed an attacker to achieve r… Mitigation only Fix from $1,9502025-11-05 HIGH 8.8 CVE-2025-64106 Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation ena… Cursor 2.0+ Fix from $1,9502025-11-04 CRITICAL 9.8 CVE-2025-11953 KEVEPSS 94% The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpo… React Native Community Cli 19.1.2+ Fix from $2,3002025-11-03 HIGH 7.2 CVE-2025-54763 FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of… Mitigation only Fix from $1,9502025-10-31 HIGH 7.2 CVE-2025-34280 Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate… Network Analyzer 2024+ Fix from $1,9502025-10-30 HIGH 8.8 CVE-2025-34284 Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters… Nagios Xi 2024+ Fix from $1,9502025-10-30 HIGH 7.2 CVE-2025-34286 Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient va… Nagios Xi 2026+ Fix from $1,9502025-10-30 HIGH 8.8 CVE-2024-14005 Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input i… Nagios Xi 2024+ Fix from $1,9502025-10-30 HIGH 7.2 CVE-2024-14008 Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Insufficient validation of… Nagios Xi 2024+ Fix from $1,9502025-10-30 HIGH 7.2 CVE-2025-34134 Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficie… Nagios Xi 2024+ Fix from $1,9502025-10-30