Vulnerabilities (CVE)

Filtered by CWE-77
Total 3432 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-5000 1 Linksys 4 Fgw3000-ah, Fgw3000-ah Firmware, Fgw3000-hk and 1 more 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000. It has been classified as critical. This affects the function control_panel_sw of the file /cgi-bin/sysconf.cgi of the component HTTP POST Request Handler. The manipulation of the argument filename leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-59834 1 Srmorete 1 Adb Mcp Server 2026-06-17 N/A 9.8 CRITICAL
ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. This issue has been patched via commit 041729c.
CVE-2025-59831 1 Riceball 1 Git-commiters 2026-06-17 N/A 8.8 HIGH
git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection vulnerability in git-commiters. This vulnerability manifests with the library's primary exported API: gitCommiters(options, callback) which allows specifying options such as cwd for current working directory and revisionRange as a revision pointer, such as HEAD. However, the library does not sanitize for user input or practice secure process execution API to separate commands from their arguments and as such, uncontrolled user input is concatenated into command execution. This issue has been patched in version 0.1.2.
CVE-2025-59818 1 Zenitel 2 Tcis-3, Tcis-3 Firmware 2026-06-17 N/A 10.0 CRITICAL
This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
CVE-2025-59817 2026-06-17 N/A 8.4 HIGH
This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, successful exploitation grants full control over the device, potentially compromising its availability, confidentiality, and integrity.
CVE-2025-59815 2026-06-17 N/A 8.4 HIGH
This vulnerability allows malicious actors to execute arbitrary commands on the underlying system of the Zenitel ICX500 and ICX510 Gateway, granting shell access. Exploitation can compromise the device’s availability, confidentiality, and integrity.
CVE-2025-59741 1 Andsoft 1 E-tms 2026-06-17 N/A 9.8 CRITICAL
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/CLT/LOGINERRORFRM.ASP'.
CVE-2025-59740 1 Andsoft 1 E-tms 2026-06-17 N/A 9.8 CRITICAL
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM_CAT.ASP'.
CVE-2025-59739 1 Andsoft 1 E-tms 2026-06-17 N/A 9.8 CRITICAL
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM_original.ASP'.
CVE-2025-59738 1 Andsoft 1 E-tms 2026-06-17 N/A 9.8 CRITICAL
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM_BET.ASP'.
CVE-2025-59737 1 Andsoft 1 E-tms 2026-06-17 N/A 9.8 CRITICAL
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM_LXA.ASP'.
CVE-2025-59736 1 Andsoft 1 E-tms 2026-06-17 N/A 9.8 CRITICAL
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM_DJO.ASP'.
CVE-2025-59735 1 Andsoft 1 E-tms 2026-06-17 N/A 9.8 CRITICAL
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM.ASP'.
CVE-2025-59689 1 Libraesva 1 Email Security Gateway 2026-06-17 N/A 6.1 MEDIUM
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
CVE-2025-59470 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 9.0 CRITICAL
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
CVE-2025-59468 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 9.0 CRITICAL
This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.
CVE-2025-59458 1 Jetbrains 1 Junie 2026-06-17 N/A 8.3 HIGH
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command validation
CVE-2025-59376 1 Feisky 1 Mcp-kubernetes-server 2026-06-17 N/A 3.7 LOW
feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g., it allows a "kubectl version; kubectl delete pod" command because the first word (i.e., "version") is not a write or delete operation.
CVE-2025-59337 1 Discourse 1 Discourse 2026-06-17 N/A 6.8 MEDIUM
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be embedded in a backup dump and executed during restore. In multisite setups, this allowed an admin of one site to access data or credentials from other sites. This issue is fixed in version 3.5.1.
CVE-2025-59286 1 Microsoft 1 365 Copilot Chat 2026-06-17 N/A 9.3 CRITICAL
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.