Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
MEDIUM 6.5 CVE-2024-42922 AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability. Aapanel after 7.0.7 Fix from $1,6002025-05-21 MEDIUM 6.5 CVE-2025-27804 Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishing a specially crafted messag… Mitigation only Fix from $1,6002025-05-21 CRITICAL 9.8 CVE-2025-44880 A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a c… Wl Wn579a3 Firmware No fix yet Fix from $2,3002025-05-20 CRITICAL 9.8 CVE-2025-44882 A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands vi… Wl Wn579a3 Firmware No fix yet Fix from $2,3002025-05-20 HIGH 8.8 CVE-2025-41225 The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run sc… Mitigation only Fix from $1,9502025-05-20 HIGH 7.2 CVE-2024-6486 The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" param… Imagemagick Engine 1.7.11+ Fix from $1,9502025-05-15 CRITICAL 9.8 CVE-2025-32002 Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA network attached hard disk 'HDL-T… Mitigation only Fix from $2,3002025-05-15 HIGH 8.9 CVE-2025-47782 motionEye is an online interface for the software motion, a video surveillance program with motion detection. In versions 0.43.1b1 through 0.43.1b3, … Patch available Fix from $1,9502025-05-14 HIGH 8.5 CVE-2025-24022 iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend o… Itop 2.7.12 / 3.1.3+ Fix from $1,9502025-05-14 CRITICAL 9.1 CVE-2025-43562EPSS 45% ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co… Coldfusion Mitigation only Fix from $2,3002025-05-13 CRITICAL 9.8 CVE-2025-45858EPSS 11% TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function. A3002r Firmware No fix yet Fix from $2,3002025-05-13 HIGH 7.8 CVE-2025-40582 A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Edge Client installed). Affecte… Scalance Lpe9403 Firmware Mitigation only Fix from $1,9502025-05-13 CRITICAL 9.8 CVE-2025-26389 A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does not sanit… Ozw672 Firmware 8.0+ Fix from $2,3002025-05-13 HIGH 7.2 CVE-2025-32821EPSS 20% A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command argu… Sma 100 Firmware 10.2.1.15-81sv+ Fix from $1,9502025-05-07 MEDIUM 5.5 CVE-2025-20213 A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite… Catalyst Sd Wan Manager Mitigation only Fix from $1,6002025-05-07 MEDIUM 6.5 CVE-2025-20193 A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perfo… Ios Xe Mitigation only Fix from $1,6002025-05-07 MEDIUM 5.4 CVE-2025-20194 A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perfo… Ios Xe Mitigation only Fix from $1,6002025-05-07 HIGH 8.8 CVE-2025-20186 A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software could allow an authenticated, r… Ios Xe Mitigation only Fix from $1,9502025-05-07 CRITICAL 9.8 CVE-2025-45491 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parame… E5600 Firmware No fix yet Fix from $2,3002025-05-06 CRITICAL 9.8 CVE-2025-45042 Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function. Ac9 Firmware No fix yet Fix from $2,3002025-05-05 HIGH 8.8 CVE-2025-2605EPSS 13% Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abus… Mb Secure Firmware 03.09 / 12.53+ Fix from $1,9502025-05-02 HIGH 7.8 CVE-2024-6032 Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code… Model S Firmware 2024.8+ Fix from $1,9502025-04-30 HIGH 8.8 CVE-2025-24351 A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to e… Mitigation only Fix from $1,9502025-04-30 HIGH 8.1 CVE-2025-4032 A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as critical. This issue affects the… Aworld after 2025-04-24 Fix from $1,9502025-04-28 HIGH 8.8 CVE-2022-41871 SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context… Seppmail after 12.1.17 Fix from $1,9502025-04-28 CRITICAL 9.1 CVE-2025-46271 UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data. Mitigation only Fix from $2,3002025-04-24 CRITICAL 9.1 CVE-2025-46272 WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacker to execute OS commands on … Mitigation only Fix from $2,3002025-04-24 CRITICAL 9.2 CVE-2025-43858 YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, a… Patch available Fix from $2,3002025-04-24 MEDIUM 6.7 CVE-2025-1976 KEV Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary… Fabric Operating System 9.1.1d7+ Fix from $1,6002025-04-24 HIGH 7.2 CVE-2025-2773 BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu… Router Firmware Mitigation only Fix from $1,9502025-04-23