Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.1 CVE-2025-58059 Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to before 13.1.2.RELEASE, any admi… Patch available Fix from $2,3002025-08-28 CRITICAL 9.8 CVE-2025-55583EPSS 6% D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component… Dir 868l Firmware Mitigation only Fix from $2,3002025-08-28 CRITICAL 10.0 CVE-2025-34160 AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port 10250. The endpoint /api/Ser… Mitigation only Fix from $2,3002025-08-27 CRITICAL 10.0 CVE-2024-13985EPSS 13% A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system command… Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.8 CVE-2018-25115EPSS 9% Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vuln… Dir 110 Firmware Mitigation only Fix from $2,3002025-08-27 HIGH 8.8 CVE-2025-34161 Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform … Coolify 4.0.0+ Fix from $1,9502025-08-27 MEDIUM 6.5 CVE-2025-20294 Multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker wi… Mitigation only Fix from $1,6002025-08-27 MEDIUM 6.0 CVE-2025-20295 A vulnerability in the CLI of Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to read or creat… Mitigation only Fix from $1,6002025-08-27 CRITICAL 9.1 CVE-2025-50989EPSS 8% OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). … Opnsense 25.1.8+ Fix from $2,3002025-08-27 HIGH 7.2 CVE-2025-9528EPSS 48% A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand.… E1700 Firmware No fix yet Fix from $1,9502025-08-27 MEDIUM 6.5 CVE-2025-50974 The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating p… Ipfire No fix yet Fix from $1,6002025-08-26 CRITICAL 9.8 CVE-2025-9424EPSS 18% A vulnerability was identified in Ruijie WS7204-A 2017.06.15. Affected by this vulnerability is an unknown functionality of the file /itbox_pi/branch… Ws7204 A Firmware Mitigation only Fix from $2,3002025-08-25 CRITICAL 9.8 CVE-2025-9387EPSS 9% A vulnerability was found in DCN DCME-720 9.1.5.11. This affects an unknown function of the file /usr/local/www/function/audit/newstatistics/ip_block… Dcme 720 Firmware Mitigation only Fix from $2,3002025-08-24 HIGH 8.1 CVE-2025-57771 Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions prior to 3.25.5, Roo-Code fails to properly handle proces… Patch available Fix from $1,9502025-08-22 CRITICAL 9.8 CVE-2025-3128 A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamper with, destroy or delete i… Mitigation only Fix from $2,3002025-08-21 HIGH 8.1 CVE-2025-9262EPSS 5% A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/provider.js of the component o… Mcp Cli No fix yet Fix from $1,9502025-08-20 HIGH 8.8 CVE-2025-9244EPSS 8% A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/… Re6250 Firmware No fix yet Fix from $1,9502025-08-20 HIGH 8.5 CVE-2025-6181 The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escala… Mitigation only Fix from $1,9502025-08-20 HIGH 7.0 CVE-2025-6183 The StrongDM macOS client incorrectly processed JSON-formatted messages. Attackers could potentially modify macOS system configuration by crafting a … Mitigation only Fix from $1,9502025-08-20 CRITICAL 9.8 CVE-2011-10026 Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation … Spree 0.50.1+ Fix from $2,3002025-08-20 CRITICAL 9.3 CVE-2010-20059 FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a c… No fix yet Fix from $2,3002025-08-20 HIGH 7.8 CVE-2025-9176 A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment Var… Shc after 4.0.3 Fix from $1,9502025-08-20 HIGH 7.8 CVE-2025-9174 A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the function make of the file src/shc.c of the component Filen… Shc after 4.0.3 Fix from $1,9502025-08-19 MEDIUM 6.5 CVE-2025-55589 TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff … A3002r Firmware No fix yet Fix from $1,6002025-08-18 HIGH 7.5 CVE-2025-55284 Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prompts to read a file and then s… Claude Code 1.0.4+ Fix from $1,9502025-08-16 CRITICAL 9.8 CVE-2025-9026 A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cgibin of the component Simple … Dir 860l Firmware Mitigation only Fix from $2,3002025-08-15 MEDIUM 6.0 CVE-2025-20220 A vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could al… Mitigation only Fix from $1,6002025-08-14 HIGH 8.8 CVE-2025-8876 KEV Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1. N Central 2025.3.1+ Fix from $1,9502025-08-14 CRITICAL 9.8 CVE-2025-43984EPSS 19% An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_20191211). They are vulnerabl… Mitigation only Fix from $2,3002025-08-14 CRITICAL 9.4 CVE-2012-10059 Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The e… No fix yet Fix from $2,3002025-08-13