VulnSea

CWE-77

CVEs classified under CWE-77, newest first.

271 CVEsRSS

CVE-2026-23814High· 8.8
6mo ago

A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.

A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.

▾ Twilighthpe · arubaos-cxEPSS 0.56%via NVD
CVE-2025-12107High· 8.4
7mo ago

The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input

The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary …

▾ Twilightwso2 · identity_serverEPSS 0.65%via NVD
CVE-2026-2670High· 7.2PoC
7mo ago

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

▾ MidnightEPSS 3.6%via NVD
CVE-2025-24293High· 8.1PoC
8mo ago

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…

▾ MidnightEPSS 5.4%via NVD
CVE-2025-15366None
8mo ago

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

▾ SunlitEPSS 0.42%via NVD
CVE-2025-15391Medium· 6.3
9mo ago

A weakness has been identified in D-Link DIR-806A 100CNb11

A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP Request Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit has be…

▾ Sunlitdlink · dir-806a_firmwareEPSS 4.2%via NVD
CVE-2024-46060High· 7.8
9mo ago

Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory

Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. Thi…

▾ Twilightanaconda · anaconda3EPSS 0.20%via NVD
CVE-2025-65293Medium· 6.6
9mo ago

Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.

Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.

▾ Sunlitaqara · camera_hub_g3_firmwareEPSS 1.1%via NVD
CVE-2025-65292High· 7.3
9mo ago

Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands with root privileges through malicious domain names.

Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands with root privileges through malicious domain names.

▾ Twilightaqara · hub_m2_firmwareEPSS 0.80%via NVD
CVE-2025-65363High· 7.2
9mo ago

Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the …

Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the …

▾ Twilightruijie · rg-ap720-l_firmwareEPSS 6.7%via NVD
CVE-2025-14188High· 7.2
9mo ago

A security vulnerability has been detected in UGREEN DH2100+ up to 5.3.0.251125

A security vulnerability has been detected in UGREEN DH2100+ up to 5.3.0.251125. This impacts the function handler_file_backup_create of the file /v1/file/backup/create of the component nas_svr. The manipulation of the argument path lead…

▾ TwilightEPSS 2.7%via NVD
CVE-2025-14108High· 8.8
9mo ago

A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050

A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.OpenSafe of the file /v2/file/safe/open of the component HTTP POST Request Handler. This manipulation of the argument …

▾ Twilightzspace · q2c_nas_firmwareEPSS 10%via NVD
CVE-2025-14107High· 8.8
9mo ago

A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050

A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this vulnerability is the function zfilev2_api.SafeStatus of the file /v2/file/safe/status of the component HTTP POST Request Handler. The manipulation …

▾ Twilightzspace · q2c_nas_firmwareEPSS 12%via NVD
CVE-2025-14106High· 8.8
9mo ago

A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050

A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of the file /v2/file/safe/close of the component HTTP POST Request Handler. The manipulation of the argument safe_dir lead…

▾ Twilightzspace · q2c_nas_firmwareEPSS 12%via NVD
CVE-2025-1910NonePoC
9mo ago

The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows machine where the VPN Client is installed.

The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows machine where the VPN Client is installed.

▾ TwilightEPSS 0.26%via NVD
CVE-2025-57201High· 8.8
9mo ago

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server function

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server function. This vulnerability allows attackers to execute arbitrary commands via …

▾ Twilightavtech · dgm1104_firmwareEPSS 17%via NVD
CVE-2025-57199High· 8.8PoC
9mo ago

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetectD binary

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetectD binary. This vulnerability allows attackers to execute arbitrary commands vi…

▾ Midnightavtech · dgm1104_firmwareEPSS 3.3%via NVD
CVE-2025-57198High· 8.8
9mo ago

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Machine.cgi endpoint

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Machine.cgi endpoint. This vulnerability allows attackers to execute arbitrary commands via…

▾ Twilightavtech · dgm1104_firmwareEPSS 2.8%via NVD
CVE-2025-57200Medium· 6.5
9mo ago

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the test_mail function

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the test_mail function. This vulnerability allows attackers to execute arbitrary commands via a…

▾ Sunlitavtech · dgm1104_firmwareEPSS 2.4%via NVD
CVE-2025-13800Medium· 6.3
10mo ago

A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c

A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the file /send_order.cgi. The manipulation of the argument mac results in command injection. It is possible to launch th…

▾ Sunlitadslr · b-qe2w401_firmwareEPSS 9.4%via NVD
CVE-2025-13799Medium· 6.3
10mo ago

A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c

A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_del of the file /send_order.cgi. The manipulation of the argument mac leads to command injection. It is possible to i…

▾ Sunlitadslr · b-qe2w401_firmwareEPSS 9.4%via NVD
CVE-2025-13797Medium· 6.3
10mo ago

A vulnerability was detected in ADSLR B-QE2W401 250814-r037c

A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifimac of the file /send_order.cgi. Performing manipulation of the argument del_swifimac results in command injection. Th…

▾ Sunlitadslr · b-qe2w401_firmwareEPSS 7.1%via NVD
CVE-2025-63674Medium· 6.8
10mo ago

An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.

An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.

▾ Sunlitblurams · a31c_firmwareEPSS 0.29%via NVD
CVE-2025-60689Medium· 5.4PoC
10mo ago

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz)

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl…

▾ Twilightlinksys · e1200_firmwareEPSS 18%via NVD
CVE-2025-9223High· 8.8PoC
10mo ago

Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.

Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.

▾ MidnightEPSS 4.2%via NVD
CVE-2025-34267Critical· 9.9
11mo ago

Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) w…

Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) w…

▾ Midnightflowiseai · flowiseEPSS 6.6%via NVD
CVE-2025-20334High· 8.8
1y ago

A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root privileges into the underlying operating system. This vulnerability is due to insufficient…

A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root privileges into the underlying operating system. This vulnerability is due to insufficient…

▾ TwilightEPSS 0.50%via NVD
CVE-2025-10035Critical· 10.0CISA KEVPoC
1y ago

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

▾ Hadalfortra · goanywhere_managed_file_transferEPSS 100%via NVD
CVE-2025-10619Medium· 6.3
1y ago

A vulnerability was detected in sequa-ai sequa-mcp up to 1.0.13

A vulnerability was detected in sequa-ai sequa-mcp up to 1.0.13. This affects the function redirectToAuthorization of the file src/helpers/node-oauth-client-provider.ts of the component OAuth Server Discovery. Performing manipulation res…

▾ SunlitEPSS 1.6%via NVD
CVE-2025-30264High· 8.8
1y ago

A command injection vulnerability has been reported to affect several QNAP operating system versions

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixe…

▾ Twilightqnap · qtsEPSS 0.91%via NVD
CWE-77 vulnerabilities (CVEs) — page 8 · VulnSea