Vulnerabilities (CVE)

Filtered by CWE-77
Total 3843 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-58178 2026-06-17 N/A 7.8 HIGH
SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In versions 4 to 5.3.0, a command injection vulnerability was discovered in the SonarQube Scan GitHub Action that allows untrusted input arguments to be processed without proper sanitization. Arguments sent to the action are treated as shell expressions, allowing potential execution of arbitrary commands. A fix has been released in SonarQube Scan GitHub Action 5.3.1.
CVE-2025-58132 1 Zoom 4 Meeting Software Development Kit, Rooms, Workplace Desktop and 1 more 2026-06-17 N/A 4.1 MEDIUM
Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.
CVE-2025-57733 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.5 MEDIUM
In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content
CVE-2025-57633 2026-06-17 N/A 9.8 CRITICAL
A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute arbitrary OS commands. The /ftp.html endpoint's "Upload File" action constructs a shell command from the ftp_file parameter and executes it using os.system() without sanitization or escaping.
CVE-2025-57521 2026-06-17 N/A 6.1 MEDIUM
Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The application loads a network plugin without validating its digital signature or verifying its authenticity. A local attacker can exploit this behavior by placing a malicious component in the expected location, which is controllable by the attacker (e.g., under %APPDATA%), resulting in code execution within the context of the user. The main application is digitally signed, which may allow a malicious component to inherit trust and evade detection by security solutions that rely on signed parent processes.
CVE-2025-57296 1 Tenda 2 Ac6, Ac6 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to the /goform/SetIPTVCfg web interface. When handling the list and vlanId parameters, the sub_ADBC0 helper function concatenates these user-supplied values into nvram set system commands using doSystemCmd, without validating or sanitizing special characters (e.g., ;, ", #). An unauthenticated or authenticated attacker can exploit this by submitting a crafted POST request, leading to arbitrary system command execution on the affected device.
CVE-2025-57293 1 Comfast 2 Cf-xr11, Cf-xr11 Firmware 2026-06-17 N/A 8.8 HIGH
A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function in /usr/bin/webmgnt. The phy_interface parameter is not sanitized, allowing attackers to inject arbitrary commands via a POST request to /cgi-bin/mbox-config?method=SET&section=multi_pppoe. When the action parameter is set to "one_click_redial", the unsanitized phy_interface is used in a system() call, enabling execution of malicious commands. This can lead to unauthorized access to sensitive files, execution of arbitrary code, or full device compromise.
CVE-2025-57285 1 Codecept 1 Codeceptjs 2026-06-17 N/A 9.8 CRITICAL
codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without sanitization or escaping, allowing attackers to execute arbitrary commands.
CVE-2025-57282 2026-06-17 N/A 8.8 HIGH
ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.
CVE-2025-57164 1 Flowiseai 1 Flowise 2026-06-17 N/A 6.5 MEDIUM
Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.
CVE-2025-56814 2026-06-17 N/A 7.8 HIGH
A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shell metacharacters.
CVE-2025-56799 1 Reolink 1 Reolink 2026-06-17 N/A 6.5 MEDIUM
Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a crafted folder name would arise only if the local user were attacking himself.
CVE-2025-56769 1 Hutool 1 Hutool 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code execution (RCE) via the QLExpressEngine class.
CVE-2025-56706 1 Edimax 2 Br-6473ax, Br-6473ax Firmware 2026-06-17 N/A 8.0 HIGH
Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter in the openwrt_getConfig function.
CVE-2025-56426 1 Webkul 1 Bagisto 2026-06-17 N/A 6.5 MEDIUM
An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calculation logic fails to validate quantity inputs properly.
CVE-2025-56425 1 Optimal-systems 1 Enaio 2026-06-17 N/A 9.1 CRITICAL
An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.183 and earlier of enaio 11.0, and in the AppConnctor component version 11.10.0.183 and earlier of enaio 11.10. The vulnerability allows authenticated remote attackers to inject arbitrary SMTP commands via crafted input to the /osrest/api/organization/sendmail endpoint
CVE-2025-56406 2026-06-17 N/A 7.5 HIGH
An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the mcp-neo4j MCP server is only intended for use in a local environment where authentication realistically would not be needed. Also, the Supplier provides middleware to help isolate the MCP server from external access (if needed).
CVE-2025-55911 1 Oxygenz 1 Clipbucket 2026-06-17 N/A 6.5 MEDIUM
An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php and the file parameter
CVE-2025-55901 1 Totolink 2 A3300r, A3300r Firmware 2026-06-17 N/A 6.5 MEDIUM
TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_time parameter.
CVE-2025-55893 1 Totolink 2 N200re, N200re Firmware 2026-06-17 N/A 6.5 MEDIUM
TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName.