Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
MEDIUM 6.8 CVE-2025-8638 Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on… Dmx958xr Firmware Mitigation only Fix from $1,6002025-08-06 MEDIUM 6.8 CVE-2025-8628 Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on… Dmx958xr Firmware Mitigation only Fix from $1,6002025-08-06 MEDIUM 6.8 CVE-2025-8629 Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on… Dmx958xr Firmware Mitigation only Fix from $1,6002025-08-06 MEDIUM 6.8 CVE-2025-8630 Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on… Dmx958xr Firmware Mitigation only Fix from $1,6002025-08-06 MEDIUM 6.8 CVE-2025-8631 Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on… Dmx958xr Firmware Mitigation only Fix from $1,6002025-08-06 CRITICAL 9.8 CVE-2013-10069EPSS 12% The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command in… Dir 600 Firmware after 2.14b01 Fix from $2,3002025-08-05 CRITICAL 9.3 CVE-2012-10033 Narcissus is vulnerable to remote code execution via improper input handling in its image configuration workflow. Specifically, the backend.php scrip… No fix yet Fix from $2,3002025-08-05 HIGH 8.6 CVE-2012-10028 Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute ar… No fix yet Fix from $1,9502025-08-05 HIGH 8.6 CVE-2012-10029 Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated … No fix yet Fix from $1,9502025-08-05 HIGH 7.4 CVE-2025-43978 Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?fla… Mitigation only Fix from $1,9502025-08-05 HIGH 7.4 CVE-2025-43979EPSS 5% An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute arbitrary OS system commands wi… Mitigation only Fix from $1,9502025-08-05 CRITICAL 9.3 CVE-2025-2611EPSS 6% The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session co… Patch available Fix from $2,3002025-08-05 CRITICAL 9.8 CVE-2025-54987EPSS 17% A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and … Apex One Patch available Fix from $2,3002025-08-05 CRITICAL 9.8 CVE-2025-54948 KEVEPSS 21% A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and … Apex One Patch available Fix from $2,3002025-08-05 CRITICAL 9.8 CVE-2025-54795 Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation… Claude Code 1.0.20+ Fix from $2,3002025-08-05 CRITICAL 9.8 CVE-2025-54135 Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the… Cursor 1.3.9+ Fix from $2,3002025-08-05 CRITICAL 9.4 CVE-2025-34147 An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the d… Mitigation only Fix from $2,3002025-08-04 CRITICAL 9.8 CVE-2025-51390 TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig func… N600r Firmware Mitigation only Fix from $2,3002025-08-04 HIGH 8.8 CVE-2025-44960 RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route. Ruckus Smartzone Firmware 4.5.0.51 / 6.1.2+ Fix from $1,9502025-08-04 HIGH 8.8 CVE-2025-44961 In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user. Ruckus Smartzone Firmware 4.5.0.51 / 6.1.2+ Fix from $1,9502025-08-04 MEDIUM 6.7 CVE-2025-30096 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version… Data Domain Operating System 7.10.1.60 / 7.13.1.30+ Fix from $1,6002025-08-04 MEDIUM 6.7 CVE-2025-30097 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version… Data Domain Operating System 7.10.1.60 / 7.13.1.30+ Fix from $1,6002025-08-04 MEDIUM 6.7 CVE-2025-30098 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version… Data Domain Operating System 7.10.1.60 / 7.13.1.30+ Fix from $1,6002025-08-04 HIGH 7.8 CVE-2025-30099 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version… Data Domain Operating System 7.10.1.60 / 7.13.1.30+ Fix from $1,9502025-08-04 CRITICAL 9.8 CVE-2025-36604EPSS 61% Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner… Unity Operating Environment 5.5.1.0+ Fix from $2,3002025-08-04 HIGH 7.8 CVE-2025-36606 Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An authenticated attacker could… Unity Operating Environment 5.5.1.0+ Fix from $1,9502025-08-04 HIGH 7.8 CVE-2025-36607 Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potent… Unity Operating Environment 5.5.1.0+ Fix from $1,9502025-08-04 CRITICAL 9.6 CVE-2025-54133 Cursor is a code editor built for programming with AI. In versions 1.17 through 1.2, there is a UI information disclosure vulnerability in Cursor's M… Cursor 1.3+ Fix from $2,3002025-08-02 HIGH 8.8 CVE-2025-54136EPSS 26% Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by mod… Cursor 1.3+ Fix from $1,9502025-08-02 HIGH 8.8 CVE-2025-54782EPSS 48% Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulne… Devtools Integration 0.2.1+ Fix from $1,9502025-08-02