Vulnerabilities (CVE)

Filtered by CWE-77
Total 3421 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-37162 1 Arubanetworks 1 Arubaos 2026-06-17 N/A 6.5 MEDIUM
A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
CVE-2025-37146 2026-06-17 N/A 7.2 HIGH
A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to perform remote command execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
CVE-2025-37138 1 Arubanetworks 1 Arubaos 2026-06-17 N/A 6.2 MEDIUM
An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation of this vulnerability requires physical access to the hardware controllers. A successful attack could allow an authenticated malicious actor with physical access to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2025-37134 1 Arubanetworks 1 Arubaos 2026-06-17 N/A 7.2 HIGH
An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2025-37133 1 Arubanetworks 1 Arubaos 2026-06-17 N/A 7.2 HIGH
An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2025-37102 2026-06-17 N/A 7.2 HIGH
An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privileged user.
CVE-2025-37096 1 Hpe 1 Storeonce System 2026-06-17 N/A 9.8 CRITICAL
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37092 1 Hpe 1 Storeonce System 2026-06-17 N/A 9.8 CRITICAL
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37091 1 Hpe 1 Storeonce System 2026-06-17 N/A 7.2 HIGH
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37089 1 Hpe 1 Storeonce System 2026-06-17 N/A 9.8 CRITICAL
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-33249 1 Nvidia 1 Nemo 2026-06-17 N/A 7.8 HIGH
NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
CVE-2025-33246 1 Nvidia 1 Nemo 2026-06-17 N/A 7.8 HIGH
NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause a command injection by supplying crafted input to a configuration parameter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, or information disclosure.
CVE-2025-33181 1 Nvidia 5 Cumulus Linux, Dgx Gb200, Gb300 Nvl72 and 2 more 2026-06-17 N/A 7.3 HIGH
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges.
CVE-2025-33180 1 Nvidia 5 Cumulus Linux, Dgx Gb200, Gb300 Nvl72 and 2 more 2026-06-17 N/A 8.0 HIGH
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges.
CVE-2025-32813 1 Infoblox 1 Netmri 2026-06-17 N/A 7.2 HIGH
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
CVE-2025-32702 1 Microsoft 2 Visual Studio 2019, Visual Studio 2022 2026-06-17 N/A 7.8 HIGH
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2025-31951 2026-06-17 N/A 8.8 HIGH
HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution.
CVE-2025-31710 2 Google, Unisoc 13 Android, S8000, Sc9863a and 10 more 2026-06-17 N/A 5.9 MEDIUM
In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.
CVE-2025-31644 1 F5 21 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Advanced Web Application Firewall and 18 more 2026-06-17 N/A 8.7 HIGH
When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2025-30264 1 Qnap 2 Qts, Quts Hero 2026-06-17 N/A 8.8 HIGH
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later