Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2025-11148 All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool that is interacted with locally,… Mitigation only Fix from $2,3002025-09-30 HIGH 8.8 CVE-2025-36245 IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges … Infosphere Information Server after 11.7.1.6 Fix from $1,9502025-09-29 CRITICAL 9.3 CVE-2025-30247 An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attacke… Mitigation only Fix from $2,3002025-09-29 HIGH 8.2 CVE-2025-57516 OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via… Publiccms No fix yet Fix from $1,9502025-09-29 HIGH 8.8 CVE-2025-11138 A vulnerability was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation… Wenkucms No fix yet Fix from $1,9502025-09-29 HIGH 7.7 CVE-2025-59844 SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command injection vulnerability exist… Mitigation only Fix from $1,9502025-09-26 HIGH 7.3 CVE-2025-35027 Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability.… G1 Firmware after 1.4.4 Fix from $1,9502025-09-26 HIGH 8.2 CVE-2025-60017 Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (w… Mitigation only Fix from $1,9502025-09-26 CRITICAL 9.8 CVE-2025-11005 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injecti… X6000r Firmware after 9.4.0cu.1360_b20241207 Fix from $2,3002025-09-25 HIGH 8.8 CVE-2025-34227EPSS 24% Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres… Nagios Xi after 2026 Fix from $1,9502025-09-25 MEDIUM 6.7 CVE-2025-43943 Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command… Cloud Disaster Recovery 19.20+ Fix from $1,6002025-09-25 HIGH 7.8 CVE-2025-27262 Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges. Indoor Connect 8855 Firmware 2025.q2+ Fix from $1,9502025-09-25 HIGH 8.8 CVE-2025-59831 git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection … Git Commiters 0.1.2+ Fix from $1,9502025-09-25 CRITICAL 9.8 CVE-2025-59834 ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server… Adb Mcp Server after 0.1.0 Fix from $2,3002025-09-25 CRITICAL 9.8 CVE-2025-52906EPSS 13% Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injecti… X6000r Firmware after 9.4.0cu.1360_b20241207 Fix from $2,3002025-09-24 CRITICAL 9.8 CVE-2025-56819 An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter. Datart Mitigation only Fix from $2,3002025-09-24 MEDIUM 6.5 CVE-2025-57636 OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injection vulnerability via the HTTP… Di 7100g Firmware No fix yet Fix from $1,6002025-09-23 HIGH 7.8 CVE-2025-59534 CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communication… Cryptolib 1.4.2+ Fix from $1,9502025-09-23 MEDIUM 6.5 CVE-2025-57639 OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user paramete… Ac9 Firmware No fix yet Fix from $1,6002025-09-23 CRITICAL 9.8 CVE-2025-9588 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnV… Envision 250563+ Fix from $2,3002025-09-23 HIGH 8.5 CVE-2025-9494 An OS command injection vulnerability has been discovered in the Vitogate 300, which can be exploited by malicious users to compromise affected insta… Mitigation only Fix from $1,9502025-09-23 HIGH 7.2 CVE-2025-10775EPSS 20% A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/logi… Wl Nu516u1 Firmware No fix yet Fix from $1,9502025-09-22 CRITICAL 9.8 CVE-2025-10568 HyperX NGENUITY software is potentially vulnerable to arbitrary code execution. HP is releasing updated software to address the potential vulnerabili… Ngenuity 5.32.0.0+ Fix from $2,3002025-09-19 CRITICAL 9.0 CVE-2025-48703 KEVEPSS 100% CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_tota… Webpanel 0.9.8.1205+ Fix from $2,3002025-09-19 HIGH 7.2 CVE-2025-36143 IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation … Watsonx.data Mitigation only Fix from $1,9502025-09-18 CRITICAL 9.8 CVE-2025-23316 NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote code exec… Triton Inference Server 25.08+ Fix from $2,3002025-09-17 MEDIUM 6.3 CVE-2025-10619 A vulnerability was detected in sequa-ai sequa-mcp up to 1.0.13. This affects the function redirectToAuthorization of the file src/helpers/node-oauth… Patch available Fix from $1,6002025-09-17 CRITICAL 9.8 CVE-2025-9972 Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability, allowing unauthenticated rem… Mitigation only Fix from $2,3002025-09-17 HIGH 8.0 CVE-2025-59518 In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during ru… Mitigation only Fix from $1,9502025-09-17 HIGH 7.2 CVE-2025-58116 Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulner… Mitigation only Fix from $1,9502025-09-17