Total
2551 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2025-11096 | 1 Dlink | 2 Dir-823x, Dir-823x Firmware | 2025-10-02 | 6.5 MEDIUM | 6.3 MEDIUM |
A flaw has been found in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/diag_traceroute. Executing manipulation of the argument target_addr can lead to command injection. The attack can be executed remotely. The exploit has been published and may be used. | |||||
CVE-2025-11097 | 1 Dlink | 2 Dir-823x, Dir-823x Firmware | 2025-10-02 | 6.5 MEDIUM | 6.3 MEDIUM |
A vulnerability has been found in D-Link DIR-823X 250416. Impacted is an unknown function of the file /goform/set_device_name. The manipulation of the argument mac leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-11098 | 1 Dlink | 2 Dir-823x, Dir-823x Firmware | 2025-10-02 | 6.5 MEDIUM | 6.3 MEDIUM |
A vulnerability was found in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_wifi_blacklists. The manipulation of the argument macList results in command injection. The attack may be performed from remote. The exploit has been made public and could be used. | |||||
CVE-2025-11099 | 1 Dlink | 2 Dir-823x, Dir-823x Firmware | 2025-10-02 | 6.5 MEDIUM | 6.3 MEDIUM |
A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_del of the file /goform/delete_prohibiting. This manipulation of the argument delvalue causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |||||
CVE-2025-11100 | 1 Dlink | 2 Dir-823x, Dir-823x Firmware | 2025-10-02 | 6.5 MEDIUM | 6.3 MEDIUM |
A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |||||
CVE-2025-45512 | 1 Denx | 1 U-boot | 2025-10-02 | N/A | 6.5 MEDIUM |
A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution. | |||||
CVE-2025-57105 | 1 Dlink | 2 Di-7400g\+, Di-7400g\+ Firmware | 2025-10-02 | N/A | 9.8 CRITICAL |
The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the device. The sub_478D28 function in in mng_platform.asp, and sub_4A12DC function in wayos_ac_server.asp of the jhttpd program, with the parameter ac_mng_srv_host. | |||||
CVE-2025-9727 | 1 Dlink | 2 Dir-816l, Dir-816l Firmware | 2025-10-01 | 6.5 MEDIUM | 6.3 MEDIUM |
A weakness has been identified in D-Link DIR-816L 206b01. Affected by this issue is the function soapcgi_main of the file /soap.cgi. This manipulation of the argument service causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. This vulnerability only affects products that are no longer supported by the maintainer. | |||||
CVE-2025-29523 | 1 Dlink | 2 Dsl-7740c, Dsl-7740c Firmware | 2025-10-01 | N/A | 7.2 HIGH |
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping6 function. | |||||
CVE-2025-43012 | 1 Jetbrains | 1 Toolbox | 2025-10-01 | N/A | 8.3 HIGH |
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible | |||||
CVE-2025-3816 | 1 Westboy | 1 Cicadascms | 2025-10-01 | 5.8 MEDIUM | 4.7 MEDIUM |
A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of the file /system/schedule/save of the component Scheduled Task Handler. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2024-8983 | 1 Smashballoon | 1 Custom Twitter Feeds | 2025-09-30 | N/A | 4.8 MEDIUM |
Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |||||
CVE-2024-23971 | 1 Chargepoint | 6 Home Flex Hardwired, Home Flex Hardwired Firmware, Home Flex Nema 14-50 Plug and 3 more | 2025-09-30 | N/A | 8.8 HIGH |
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OCPP messages. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. | |||||
CVE-2025-59689 | 1 Libraesva | 1 Email Security Gateway | 2025-09-30 | N/A | 6.1 MEDIUM |
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7. | |||||
CVE-2025-10035 | 1 Fortra | 1 Goanywhere Managed File Transfer | 2025-09-30 | N/A | 10.0 CRITICAL |
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection. | |||||
CVE-2025-11073 | 2025-09-29 | 5.8 MEDIUM | 4.7 MEDIUM | ||
A vulnerability was detected in Keyfactor RG-EW5100BE EW_3.0B11P280_EW5100BE-PRO_12183019. The affected element is an unknown function of the file /cgi-bin/luci/api/cmd of the component HTTP POST Request Handler. The manipulation of the argument url results in command injection. The attack can be launched remotely. The exploit is now public and may be used. | |||||
CVE-2025-11141 | 2025-09-29 | 5.8 MEDIUM | 4.7 MEDIUM | ||
A security flaw has been discovered in Ruijie NBR2100G-E up to 20250919. Affected by this issue is the function listAction of the file /itbox_pi/branch_passw.php?a=list. Performing manipulation of the argument city results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
CVE-2025-11138 | 2025-09-29 | 6.5 MEDIUM | 6.3 MEDIUM | ||
A vulnerability was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used. | |||||
CVE-2025-11045 | 2025-09-29 | 7.5 HIGH | 7.3 HIGH | ||
A vulnerability was identified in WAYOS LQ_04, LQ_05, LQ_06, LQ_07 and LQ_09 22.03.17. This affects an unknown function of the file /usb_paswd.asp. The manipulation of the argument Name leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used. | |||||
CVE-2025-41250 | 2025-09-29 | N/A | 8.5 HIGH | ||
VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks. |