Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2024-14003 Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. In… Nagios Xi 2024+ Fix from $2,3002025-10-30 HIGH 8.8 CVE-2020-36867 Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values use… Nagios Xi 5.7.3+ Fix from $1,9502025-10-30 HIGH 8.8 CVE-2020-36856 Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_test.php script. Insufficient v… Nagios Xi 5.6.14+ Fix from $1,9502025-10-30 HIGH 8.8 CVE-2018-25122 Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The download/import handler used uns… Nagios Xi 5.4.13+ Fix from $1,9502025-10-30 HIGH 8.8 CVE-2013-10073 Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a… Nagios Xi 2012+ Fix from $1,9502025-10-30 HIGH 7.8 CVE-2025-43942 Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner… Unity Operating Environment 5.5.2.0+ Fix from $1,9502025-10-30 HIGH 7.8 CVE-2025-46422 Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner… Unity Operating Environment 5.5.2.0+ Fix from $1,9502025-10-30 HIGH 7.8 CVE-2025-46423 Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner… Unity Operating Environment 5.5.2.0+ Fix from $1,9502025-10-30 HIGH 7.8 CVE-2025-43940 Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner… Unity Operating Environment 5.5.2.0+ Fix from $1,9502025-10-30 HIGH 7.8 CVE-2025-43941 Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner… Unity Operating Environment 5.5.2.0+ Fix from $1,9502025-10-30 HIGH 7.8 CVE-2025-43939 Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner… Unity Operating Environment 5.5.2.0+ Fix from $1,9502025-10-30 CRITICAL 9.9 CVE-2025-54469 A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_LAN_PORT to generate a comman… Mitigation only Fix from $2,3002025-10-30 CRITICAL 9.8 CVE-2025-11202 win-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute ar… Patch available Fix from $2,3002025-10-29 CRITICAL 9.8 CVE-2018-25120EPSS 10% D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulnerability in the Mail Test func… Dns 343 Firmware after 1.0.5 Fix from $2,3002025-10-29 HIGH 8.8 CVE-2025-64140 Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configu… Azure Cli after 0.9 Fix from $1,9502025-10-29 HIGH 7.8 CVE-2025-62801 FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who ca… Fastmcp 2.13.0+ Fix from $1,9502025-10-28 HIGH 8.8 CVE-2025-34311EPSS 14% IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary … Ipfire 2.29+ Fix from $1,9502025-10-28 HIGH 8.8 CVE-2025-34312 IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary … Ipfire 2.29+ Fix from $1,9502025-10-28 HIGH 8.7 CVE-2025-1036 Command injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated user with low privileged networ… Mitigation only Fix from $1,9502025-10-28 HIGH 7.5 CVE-2025-1038 The “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, allowing an authenticated user … Mitigation only Fix from $1,9502025-10-28 CRITICAL 9.8 CVE-2025-12296EPSS 7% A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 of the component Firmware Upd… Dap 2695 Firmware Mitigation only Fix from $2,3002025-10-27 CRITICAL 9.8 CVE-2025-60803 Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the component /ap… Mitigation only Fix from $2,3002025-10-24 HIGH 8.8 CVE-2025-10680EPSS 7% OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --… Mitigation only Fix from $1,9502025-10-24 HIGH 7.2 CVE-2025-6978EPSS 14% Diagnostics command injection vulnerability No fix yet Fix from $1,9502025-10-23 HIGH 7.2 CVE-2025-62713 Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authentication remote code execution (RCE… Patch available Fix from $1,9502025-10-23 CRITICAL 9.8 CVE-2016-15048EPSS 7% AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection vulnerability in the /manager/radius/server_ping.php endp… Hibos Mitigation only Fix from $2,3002025-10-22 HIGH 8.3 CVE-2024-58274EPSS 18% Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/ap… Mitigation only Fix from $1,9502025-10-22 HIGH 7.2 CVE-2025-8078 A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versio… Zld 5.41+ Fix from $1,9502025-10-21 CRITICAL 9.8 CVE-2025-6542 An arbitrary OS command may be executed on the product by a remote unauthenticated attacker. Er8411 Firmware 1.1.0 / 1.2.1+ Fix from $2,3002025-10-21 HIGH 7.2 CVE-2025-7850 A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. Er8411 Firmware 1.1.0 / 1.2.1+ Fix from $1,9502025-10-21