Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2025-6541 An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. Er706w Firmware 1.0.3 / 1.1.4+ Fix from $1,9502025-10-21 CRITICAL 10.0 CVE-2018-25118 GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that ena… Mitigation only Fix from $2,3002025-10-20 HIGH 8.8 CVE-2025-47900 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Co… Timeprovider 4100 Firmware 2.5+ Fix from $1,9502025-10-20 HIGH 8.8 CVE-2025-47901 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Co… Timeprovider 4100 Firmware 2.5+ Fix from $1,9502025-10-20 CRITICAL 9.8 CVE-2025-11900 The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands… Mitigation only Fix from $2,3002025-10-17 CRITICAL 9.8 CVE-2025-34513EPSS 8% Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauth… Eve X1 Server Firmware after 4.7.18.0 Fix from $2,3002025-10-16 HIGH 8.8 CVE-2025-34514 Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scri… Eve X1 Server Firmware after 4.7.18.0 Fix from $1,9502025-10-16 HIGH 8.7 CVE-2025-53868 When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restricti… Big Ip Access Policy Manager 15.1.10.8 / 16.1.6.1+ Fix from $1,9502025-10-15 CRITICAL 9.3 CVE-2023-7311 BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is n… No fix yet Fix from $2,3002025-10-15 CRITICAL 9.3 CVE-2023-7304 Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. An unauthenticated attacker… Mitigation only Fix from $2,3002025-10-15 HIGH 8.6 CVE-2025-59051 The FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device disco… Mitigation only Fix from $1,9502025-10-14 HIGH 7.0 CVE-2024-48891 An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1… Fortisoar 7.5.2 / 7.6.2+ Fix from $1,9502025-10-14 HIGH 7.2 CVE-2025-5946EPSS 14% Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload … Centreon Web 23.10.28 / 24.04.18+ Fix from $1,9502025-10-14 HIGH 7.2 CVE-2025-10242EPSS 21% OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad… Endpoint Manager Mobile 12.4.0.4 / 12.5.0.4+ Fix from $1,9502025-10-14 HIGH 7.2 CVE-2025-10243EPSS 21% OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad… Endpoint Manager Mobile 12.4.0.4 / 12.5.0.4+ Fix from $1,9502025-10-14 HIGH 7.2 CVE-2025-10985EPSS 21% OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad… Endpoint Manager Mobile 12.4.0.4 / 12.5.0.4+ Fix from $1,9502025-10-14 HIGH 7.2 CVE-2025-47856 Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice versio… Fortivoice 6.4.11 / 7.0.7+ Fix from $1,9502025-10-14 CRITICAL 9.0 CVE-2025-9976 An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPE… Mitigation only Fix from $2,3002025-10-13 CRITICAL 9.8 CVE-2025-11665EPSS 7% A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Updat… Dap 2695 Firmware Mitigation only Fix from $2,3002025-10-13 HIGH 8.4 CVE-2025-0636 EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command could be exploited leading to Ar… Mitigation only Fix from $1,9502025-10-13 HIGH 8.7 CVE-2016-15047 AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in C… No fix yet Fix from $1,9502025-10-09 MEDIUM 5.3 CVE-2025-60006 Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Jun… Junos Os Evolved Mitigation only Fix from $1,6002025-10-09 HIGH 7.2 CVE-2025-10239 In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privileges and access to the managemen… Mitigation only Fix from $1,9502025-10-09 CRITICAL 9.8 CVE-2025-11491 A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/comma… Desktopcommandermcp after 0.2.13 Fix from $2,3002025-10-08 HIGH 8.8 CVE-2025-57457 An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the… Mitigation only Fix from $1,9502025-10-08 CRITICAL 9.8 CVE-2025-11490 A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file … Desktopcommandermcp after 0.2.13 Fix from $2,3002025-10-08 MEDIUM 6.7 CVE-2025-36567 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version… Data Domain Operating System 7.10.1.60 / 7.13.1.30+ Fix from $1,6002025-10-07 MEDIUM 6.7 CVE-2025-36569 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version… Data Domain Operating System 7.10.1.60 / 7.13.1.30+ Fix from $1,6002025-10-07 CRITICAL 9.8 CVE-2025-11407 A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of the file /upgrade_filter.asp. This manipulation … Di 7001mini 8g Firmware Mitigation only Fix from $2,3002025-10-07 MEDIUM 6.7 CVE-2025-36566 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version… Data Domain Operating System 7.10.1.60 / 7.13.1.30+ Fix from $1,6002025-10-07