Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2013-10059EPSS 19% An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tool… Dir 615h Firmware after 8.04 Fix from $1,9502025-08-01 HIGH 7.2 CVE-2013-10060 An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via… Dgn2200b Firmware after 1.1.0.36 Fix from $1,9502025-08-01 HIGH 7.2 CVE-2013-10061 An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45… Dgn1000b Firmware No fix yet Fix from $1,9502025-08-01 HIGH 8.7 CVE-2013-10053 A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htaccess files, the inHTUsername fi… Mitigation only Fix from $1,9502025-08-01 HIGH 8.6 CVE-2013-10058 An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 vi… No fix yet Fix from $1,9502025-08-01 CRITICAL 9.8 CVE-2013-10048EPSS 12% An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, res… Dir 300 Firmware after 2.14b01 Fix from $2,3002025-08-01 CRITICAL 9.3 CVE-2013-10049 An OS command injection vulnerability exists in multiple Raidsonic NAS devices—specifically tested on IB-NAS5220 and IB-NAS4220—via the unauthenticat… No fix yet Fix from $2,3002025-08-01 HIGH 8.8 CVE-2013-10050EPSS 10% An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authentica… Dir 300 Firmware after 4.13 Fix from $1,9502025-08-01 MEDIUM 6.6 CVE-2025-8473 Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code… Ilx 507 Firmware Mitigation only Fix from $1,6002025-08-01 HIGH 7.3 CVE-2025-54595 Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged helper tool bundled with the Pe… Patch available Fix from $1,9502025-08-01 CRITICAL 9.8 CVE-2025-50475EPSS 8% An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6, allowing unauthenticated attackers to execute arbitrary… Mitigation only Fix from $2,3002025-07-31 CRITICAL 10.0 CVE-2014-125124 An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, wh… Mitigation only Fix from $2,3002025-07-31 CRITICAL 9.3 CVE-2013-10037EPSS 10% An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword… No fix yet Fix from $2,3002025-07-31 HIGH 8.7 CVE-2013-10039 A command injection vulnerability exists in GestioIP 3.0 commit ac67be and earlier in ip_checkhost.cgi. Crafted input to the 'ip' parameter allows at… Mitigation only Fix from $1,9502025-07-31 CRITICAL 9.1 CVE-2025-54430 dedupe is a python library that uses machine learning to perform fuzzy matching, deduplication and entity resolution quickly on structured data. Befo… Patch available Fix from $2,3002025-07-30 HIGH 8.8 CVE-2025-29534 An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker with valid credentials to exe… Mitigation only Fix from $1,9502025-07-28 CRITICAL 9.8 CVE-2025-54418 CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the… Codeigniter 4.6.2+ Fix from $2,3002025-07-28 CRITICAL 9.4 CVE-2025-53695 OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to th… Mitigation only Fix from $2,3002025-07-28 CRITICAL 9.8 CVE-2025-8259 A vulnerability was identified in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. Affected by this issue is the function execute_DataObjectProc of the file /gri… Vaelsys Mitigation only Fix from $2,3002025-07-28 CRITICAL 9.1 CVE-2025-54415 dag-factory is a library for Apache Airflow® to construct DAGs declaratively via configuration files. In versions 0.23.0a8 and below, a high-severity… Patch available Fix from $2,3002025-07-26 CRITICAL 9.8 CVE-2025-29631 Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injectio… Mitigation only Fix from $2,3002025-07-25 CRITICAL 9.4 CVE-2014-125118 A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' par… No fix yet Fix from $2,3002025-07-25 CRITICAL 9.8 CVE-2019-25224EPSS 17% The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerabili… Wp Database Backup 5.2+ Fix from $2,3002025-07-25 CRITICAL 9.8 CVE-2025-7404 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS … Autocaliweb Mitigation only Fix from $2,3002025-07-24 CRITICAL 10.0 CVE-2025-5243 Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi… Mitigation only Fix from $2,3002025-07-24 CRITICAL 9.3 CVE-2022-4978 Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, which is the … Mitigation only Fix from $2,3002025-07-23 CRITICAL 9.3 CVE-2015-10141EPSS 5% An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick … No fix yet Fix from $2,3002025-07-23 HIGH 8.8 CVE-2025-41683 An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user i… Mitigation only Fix from $1,9502025-07-23 HIGH 8.8 CVE-2025-41684 An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user i… Mitigation only Fix from $1,9502025-07-23 HIGH 7.2 CVE-2024-53286 Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Rou… Router Manager 1.3.1-9346+ Fix from $1,9502025-07-23