Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
MEDIUM 6.8 CVE-2025-43020 A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could al… Poly Clariti Manager 10.12.2+ Fix from $1,6002025-07-22 HIGH 8.1 CVE-2025-54072 yt-dlp is a feature-rich command-line audio/video downloader. In versions 2025.06.25 and below, when the --exec option is used on Windows with the de… Yt Dlp 2025.07.21+ Fix from $1,9502025-07-22 HIGH 8.5 CVE-2025-7723 A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affec… Mitigation only Fix from $1,9502025-07-22 HIGH 8.7 CVE-2025-7724 An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1:… Mitigation only Fix from $1,9502025-07-22 CRITICAL 9.3 CVE-2025-34143EPSS 31% An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal S… Mitigation only Fix from $2,3002025-07-22 HIGH 7.2 CVE-2025-53472 WRC-BE36QS-B and WRC-W701-B contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in We… Mitigation only Fix from $1,9502025-07-22 CRITICAL 9.8 CVE-2025-36846 An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated u… Urve Web Manager Mitigation only Fix from $2,3002025-07-21 CRITICAL 9.1 CVE-2025-46117 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, … Ruckus Unleashed 10.5.1.0.279 / 200.15.6.212.14+ Fix from $2,3002025-07-21 CRITICAL 9.8 CVE-2025-6704EPSS 8% An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to… Firewall Firmware 21.0.2+ Fix from $2,3002025-07-21 HIGH 8.8 CVE-2025-7382 A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-a… Firewall Firmware 21.0.2+ Fix from $1,9502025-07-21 HIGH 7.2 CVE-2025-41674 A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of … Mbnet.mini Firmware 2.3.3+ Fix from $1,9502025-07-21 HIGH 7.2 CVE-2025-41675 A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neu… Mbnet.mini Firmware 2.3.3+ Fix from $1,9502025-07-21 HIGH 7.2 CVE-2025-41673 A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of sp… Mbnet.mini Firmware 2.3.3+ Fix from $1,9502025-07-21 HIGH 8.4 CVE-2025-24938 The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged a… Wavesuite Noc Mitigation only Fix from $1,9502025-07-21 CRITICAL 9.0 CVE-2025-24936 The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound … Wavesuite Noc No fix yet Fix from $2,3002025-07-21 HIGH 8.8 CVE-2025-7788EPSS 5% A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability is the function commandJobHa… Xxl Job after 3.1.1 Fix from $1,9502025-07-18 CRITICAL 9.3 CVE-2025-34125 An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware ver… No fix yet Fix from $2,3002025-07-16 HIGH 8.7 CVE-2025-34129 A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 due to insufficient … Mitigation only Fix from $1,9502025-07-16 CRITICAL 9.3 CVE-2025-34132 A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field… Mitigation only Fix from $2,3002025-07-16 CRITICAL 9.3 CVE-2025-34117EPSS 20% A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the pres… No fix yet Fix from $2,3002025-07-16 MEDIUM 5.4 CVE-2025-52379EPSS 10% Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below contains an authenticated command injection vulnerability in the firmware update fea… Mitigation only Fix from $1,6002025-07-15 HIGH 8.7 CVE-2025-34116 A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated att… No fix yet Fix from $1,9502025-07-15 CRITICAL 10.0 CVE-2025-34112 An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances… Mitigation only Fix from $2,3002025-07-15 HIGH 8.7 CVE-2025-34113 An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET param… No fix yet Fix from $1,9502025-07-15 HIGH 8.7 CVE-2025-34115 An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endp… No fix yet Fix from $1,9502025-07-15 CRITICAL 9.3 CVE-2025-34103 An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due to improper input handling i… No fix yet Fix from $2,3002025-07-15 HIGH 8.9 CVE-2025-53818 GitHub Kanban MCP Server is a Model Context Protocol (MCP) server for managing GitHub issues in Kanban board format and streamlining LLM task managem… Mitigation only Fix from $1,9502025-07-14 HIGH 8.1 CVE-2025-53623 The Job Iteration API is an an extension for ActiveJob that make jobs interruptible and resumable Versions prior to 1.11.0 have an arbitrary code exe… Patch available Fix from $1,9502025-07-14 CRITICAL 9.8 CVE-2025-7451 The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands… Mitigation only Fix from $2,3002025-07-14 HIGH 7.2 CVE-2025-7553 A vulnerability classified as critical has been found in D-Link DIR-818LW up to 20191215. This affects an unknown part of the component System Time P… Dir 818lw Firmware 20191215+ Fix from $1,9502025-07-14