Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2025-10589 The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenticated remote attackers to inj… Mitigation only Fix from $1,9502025-09-17 HIGH 7.2 CVE-2025-37126 A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run a… Mitigation only Fix from $1,9502025-09-16 MEDIUM 6.7 CVE-2025-37129 A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution c… Mitigation only Fix from $1,6002025-09-16 CRITICAL 9.8 CVE-2025-34184 Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote… Eve X1 Server Firmware after 4.7.18.0 Fix from $2,3002025-09-16 CRITICAL 9.8 CVE-2025-34186 Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() c… Eve X1 Server Firmware after 4.7.18.0 Fix from $2,3002025-09-16 HIGH 8.8 CVE-2025-34187 Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash sc… Eve X1 Server Firmware after 4.7.18.0 Fix from $1,9502025-09-16 HIGH 8.8 CVE-2025-55211 FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Pan… Freepbx 17.0.21+ Fix from $1,9502025-09-15 CRITICAL 9.8 CVE-2025-59377 feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl because shell=True is used. NOTE:… Mcp Kubernetes Server after 0.1.11 Fix from $2,3002025-09-15 CRITICAL 9.8 CVE-2025-59359 The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthentic… Chaos Mesh 2.7.3+ Fix from $2,3002025-09-15 CRITICAL 9.8 CVE-2025-59360 The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthe… Chaos Mesh 2.7.3+ Fix from $2,3002025-09-15 CRITICAL 9.8 CVE-2025-59361 The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthe… Chaos Mesh 2.7.3+ Fix from $2,3002025-09-15 MEDIUM 6.3 CVE-2025-10441EPSS 12% A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the function sub_433F7C of the f… No fix yet Fix from $1,6002025-09-15 HIGH 8.8 CVE-2025-10442EPSS 8% A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manip… Ac9 Firmware No fix yet Fix from $1,9502025-09-15 MEDIUM 6.3 CVE-2025-10440EPSS 12% A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A1/19.12.10A1. Affected by thi… Mitigation only Fix from $1,6002025-09-15 CRITICAL 9.8 CVE-2025-10359EPSS 6% A vulnerability was detected in Wavlink WL-WN578W2 221110. This impacts the function sub_404DBC of the file /cgi-bin/wireless.cgi. The manipulation o… Wl Wn578w2 Firmware Mitigation only Fix from $2,3002025-09-13 CRITICAL 9.8 CVE-2025-10358EPSS 6% A security vulnerability has been detected in Wavlink WL-WN578W2 221110. This affects the function sub_404850 of the file /cgi-bin/wireless.cgi. The … Wl Wn578w2 Firmware Mitigation only Fix from $2,3002025-09-13 CRITICAL 9.8 CVE-2025-10328EPSS 9% A security vulnerability has been detected in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file… Rpi Jukebox Rfid after 2.8.0 Fix from $2,3002025-09-12 CRITICAL 9.8 CVE-2025-10326EPSS 7% A security flaw has been discovered in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/api/playlist/single… Rpi Jukebox Rfid after 2.8.0 Fix from $2,3002025-09-12 CRITICAL 9.8 CVE-2025-10327EPSS 10% A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdo… Rpi Jukebox Rfid after 2.8.0 Fix from $2,3002025-09-12 HIGH 7.3 CVE-2025-27234 Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the sma… Mitigation only Fix from $1,9502025-09-12 HIGH 8.8 CVE-2025-10265 Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS… Mitigation only Fix from $1,9502025-09-12 CRITICAL 9.8 CVE-2025-54123EPSS 11% Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command injec… Hoverfly 1.12.0+ Fix from $2,3002025-09-10 MEDIUM 6.7 CVE-2025-43884 Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command (… Powerprotect Data Manager 19.21+ Fix from $1,6002025-09-10 HIGH 7.8 CVE-2025-43885 Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command (… Powerprotect Data Manager 19.21+ Fix from $1,9502025-09-10 HIGH 8.8 CVE-2025-56413 OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation paramete… 1panel Mitigation only Fix from $1,9502025-09-10 MEDIUM 5.8 CVE-2025-9997 CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command inje… No fix yet Fix from $1,6002025-09-09 MEDIUM 5.8 CVE-2025-9996 CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause the executio… Mitigation only Fix from $1,6002025-09-09 HIGH 7.2 CVE-2025-58763 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Tautulli v2.15.3 and prior allows… Tautulli 2.16.0+ Fix from $1,9502025-09-09 HIGH 8.5 CVE-2025-54084 OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user cr… Mitigation only Fix from $1,9502025-09-09 CRITICAL 9.8 CVE-2025-23344 The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to run code on the platform host as a non-privileged user. A successful expl… Nvdebug 1.7.0+ Fix from $2,3002025-09-09