Vulnerabilities (CVE)

Filtered by CWE-77
Total 2764 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-61045 1 Totolink 2 X18, X18 Firmware 2025-10-21 N/A 9.8 CRITICAL
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function.
CVE-2025-58132 1 Zoom 4 Meeting Software Development Kit, Rooms, Workplace Desktop and 1 more 2025-10-21 N/A 4.1 MEDIUM
Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.
CVE-2025-60855 2025-10-21 N/A 5.1 MEDIUM
Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious firmware images, resulting in arbitrary code execution with root privileges. NOTE: this is disputed by the Supplier because the integrity of updates is instead assured via a "private encryption algorithm" and other "tamper-proof verification."
CVE-2025-61514 2025-10-21 N/A 6.5 MEDIUM
An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploading a crafted SVG file.
CVE-2025-62696 2025-10-21 N/A N/A
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Foundation Mediawiki Foundation - Springboard Extension allows Command Injection.This issue affects Mediawiki Foundation - Springboard Extension: master.
CVE-2025-31644 1 F5 21 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Advanced Web Application Firewall and 18 more 2025-10-21 N/A 8.7 HIGH
When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2025-55637 1 Reolink 2 Smart 2k\+ Plug-in Wi-fi Video Doorbell With Chime, Smart 2k\+ Plug-in Wi-fi Video Doorbell With Chime Firmware 2025-10-21 N/A 9.8 CRITICAL
Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a command injection vulnerability via the setddns_pip_system() function.
CVE-2025-9161 1 Rockwellautomation 1 Factorytalk Optix 2025-10-20 N/A 8.8 HIGH
A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, which can be used to achieve remote code execution.
CVE-2022-35518 1 Wavlink 10 Wn530h4, Wn530h4 Firmware, Wn531p3 and 7 more 2025-10-20 N/A 9.8 CRITICAL
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to command injection in page /nas_disk.shtml.
CVE-2022-20345 1 Google 1 Android 2025-10-20 N/A 8.8 HIGH
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-230494481
CVE-2023-51126 1 Flir 2 Flir Ax8, Flir Ax8 Firmware 2025-10-17 N/A 9.8 CRITICAL
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.
CVE-2025-3983 1 Amttgroup 1 Hibos 2025-10-17 5.8 MEDIUM 4.7 MEDIUM
A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manager/system/nlog_down.php. The manipulation of the argument ProtocolType leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-2701 1 Amttgroup 1 Hibos 2025-10-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical was found in AMTT Hotel Broadband Operation System 1.0. This vulnerability affects the function popen of the file /manager/network/port_setup.php. The manipulation of the argument SwitchVersion/SwitchWrite/SwitchIP/SwitchIndex/SwitchState leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-54794 1 Eng 1 Spagobi 2025-10-17 N/A 9.1 CRITICAL
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
CVE-2025-59252 1 Microsoft 1 365 Word Copilot 2025-10-17 N/A 6.5 MEDIUM
M365 Copilot Spoofing Vulnerability
CVE-2025-59286 1 Microsoft 1 365 Copilot Chat 2025-10-17 N/A 6.5 MEDIUM
Copilot Spoofing Vulnerability
CVE-2025-59272 1 Microsoft 1 365 Copilot Chat 2025-10-17 N/A 6.5 MEDIUM
Copilot Spoofing Vulnerability
CVE-2025-45326 1 Magdesign 2 Pocketvj Control Panel, Pocketvj Control Panel Firmware 2025-10-17 N/A 6.5 MEDIUM
An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component.
CVE-2025-61044 1 Totolink 2 X18, X18 Firmware 2025-10-16 N/A 9.8 CRITICAL
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentCfg function.
CVE-2025-61787 2 Deno, Microsoft 2 Deno, Windows 2025-10-16 N/A 8.1 HIGH
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows. Versions 2.5.3 and 2.2.15 fix the issue.