Total
5994 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-60964 | 1 Endruntechnologies | 2 Sonoma D12, Sonoma D12 Firmware | 2026-07-05 | N/A | 9.1 CRITICAL |
| OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive information, and possibly other unspecified impacts. | |||||
| CVE-2025-60963 | 1 Endruntechnologies | 2 Sonoma D12, Sonoma D12 Firmware | 2026-07-05 | N/A | 8.2 HIGH |
| OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information. | |||||
| CVE-2025-60962 | 1 Endruntechnologies | 2 Sonoma D12, Sonoma D12 Firmware | 2026-07-05 | N/A | 8.2 HIGH |
| OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and possibly other unspecified impacts. | |||||
| CVE-2025-60960 | 1 Endruntechnologies | 2 Sonoma D12, Sonoma D12 Firmware | 2026-07-05 | N/A | 8.2 HIGH |
| OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information. | |||||
| CVE-2025-60959 | 1 Endruntechnologies | 2 Sonoma D12, Sonoma D12 Firmware | 2026-07-05 | N/A | 8.2 HIGH |
| OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information. | |||||
| CVE-2025-60957 | 1 Endruntechnologies | 2 Sonoma D12, Sonoma D12 Firmware | 2026-07-05 | N/A | 9.9 CRITICAL |
| OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information. | |||||
| CVE-2025-29269 | 1 Allnet | 2 All-rut22gw, All-rut22gw Firmware | 2026-07-05 | N/A | 9.8 CRITICAL |
| ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint. | |||||
| CVE-2024-38889 | 1 Horizoncloud | 1 Caterease | 2026-07-05 | N/A | 9.8 CRITICAL |
| An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command. | |||||
| CVE-2024-38887 | 1 Horizoncloud | 1 Caterease | 2026-07-05 | N/A | 9.8 CRITICAL |
| An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges. | |||||
| CVE-2024-38882 | 1 Horizoncloud | 1 Caterease | 2026-07-05 | N/A | 9.8 CRITICAL |
| An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command. | |||||
| CVE-2026-31019 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-05 | N/A | 8.8 HIGH |
| In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions related to system command execution. An authenticated user with permission to edit PHP content can bypass this filtering, resulting in full remote code execution with the ability to execute arbitrary operating system commands on the server. | |||||
| CVE-2025-67264 | 1 Doogee | 6 Note59, Note59 Firmware, Note59 Pro and 3 more | 2026-07-05 | N/A | 7.8 HIGH |
| An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pro+ allows a local attacker to execute arbitrary code and escalate privileges via the EngineerMode ADB shell, due to incomplete patching of CVE-2025-31710 | |||||
| CVE-2025-65882 | 1 Openmptcprouter | 1 Openmptcprouter | 2026-07-05 | N/A | 9.8 CRITICAL |
| An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ipad_opad allowing attackers to potentially write arbitrary files or execute arbitrary commands. | |||||
| CVE-2025-65480 | 2026-07-05 | N/A | 8.8 HIGH | ||
| An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Templates which are executed when certain script conditions are fulfilled, leading to Remote Code Execution. | |||||
| CVE-2025-60787 | 1 Motioneye Project | 1 Motioneye | 2026-07-05 | N/A | 7.2 HIGH |
| MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted. | |||||
| CVE-2025-57457 | 2026-07-05 | N/A | 8.8 HIGH | ||
| An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the "IP Addr" parameter. | |||||
| CVE-2025-56590 | 1 Apryse | 1 Html2pdf | 2026-07-05 | N/A | 9.8 CRITICAL |
| An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker to execute arbitrary operating system commands on the local server. | |||||
| CVE-2025-51390 | 1 Totolink | 2 N600r, N600r Firmware | 2026-07-05 | N/A | 9.8 CRITICAL |
| TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig function. | |||||
| CVE-2025-29534 | 2026-07-05 | N/A | 8.8 HIGH | ||
| An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker with valid credentials to execute arbitrary commands with root privileges. The issue stems from insufficient sanitization of user-supplied input in the /cgi-bin/cgi_vista.cgi executable, which is passed to a system-level function call. | |||||
| CVE-2024-52723 | 1 Totolink | 2 X6000r, X6000r Firmware | 2026-07-05 | N/A | 9.8 CRITICAL |
| In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload. | |||||
