Vulnerabilities (CVE)

Filtered by CWE-78
Total 6025 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-43879 2026-06-17 N/A 9.8 CRITICAL
WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in the telnet function. If a remote unauthenticated attacker sends a specially crafted request to the affected product, an arbitrary OS command may be executed.
CVE-2025-43876 2026-06-17 N/A N/A
Under certain circumstances a successful exploitation could result in access to the device.
CVE-2025-43875 2026-06-17 N/A N/A
Under certain circumstances a successful exploitation could result in access to the device.
CVE-2025-43873 2026-06-17 N/A N/A
Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the device.
CVE-2025-43858 2026-06-17 N/A 9.2 CRITICAL
YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS with the `UseWindowsEncodingWorkaround` value defined to true (default behavior). If a user is using built-in methods from the YoutubeDL.cs file, the value is true by default and a user cannot disable it from these methods. This issue has been patched in version 1.1.2.
CVE-2025-43562 1 Adobe 1 Coldfusion 2026-06-17 N/A 9.1 CRITICAL
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
CVE-2025-43020 1 Hp 1 Poly Clariti Manager 2026-06-17 N/A 6.8 MEDIUM
A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a privileged user to submit arbitrary input. HP has addressed the issue in the latest software update.
CVE-2025-42892 1 Sap 1 Business Connector 2026-06-17 N/A 6.8 MEDIUM
Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of arbitrary operating system commands. Successful exploitation could lead to full compromise of the system�s confidentiality, integrity, and availability.
CVE-2025-41709 2026-06-17 N/A 9.8 CRITICAL
An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device.
CVE-2025-41684 2026-06-17 N/A 8.8 HIGH
An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint tls_iotgen_setting).
CVE-2025-41683 2026-06-17 N/A 8.8 HIGH
An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint event_mail_test).
CVE-2025-41675 1 Mbconnectline 2 Mbnet.mini, Mbnet.mini Firmware 2026-06-17 N/A 7.2 HIGH
A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command.
CVE-2025-41674 1 Mbconnectline 2 Mbnet.mini, Mbnet.mini Firmware 2026-06-17 N/A 7.2 HIGH
A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command.
CVE-2025-41673 1 Mbconnectline 2 Mbnet.mini, Mbnet.mini Firmware 2026-06-17 N/A 7.2 HIGH
A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command.
CVE-2025-41663 2026-06-17 N/A 9.8 CRITICAL
For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary commands in responses returned by WWH servers, which are then executed with elevated privileges. To get into such a position, clients would need to use insecure proxy configurations.
CVE-2025-41427 2026-06-17 N/A 8.8 HIGH
WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Connection Diagnostics page. If a remote authenticated attacker sends a specially crafted request to the affected product, an arbitrary OS command may be executed.
CVE-2025-41385 1 Uchida 2 Wivia 5, Wivia 5 Firmware 2026-06-17 N/A 7.2 HIGH
An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS command may be executed by a logged-in administrative user.
CVE-2025-41225 2026-06-17 N/A 8.8 HIGH
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.
CVE-2025-40582 1 Siemens 2 Scalance Lpe9403, Scalance Lpe9403 Firmware 2026-06-17 N/A 7.8 HIGH
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters. This could allow a non-privileged local attacker to execute root commands on the device.
CVE-2025-3883 1 Hardy-barth 2 Cph2 Echarge, Cph2 Echarge Firmware 2026-06-17 N/A 8.8 HIGH
eCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of eCharge Hardy Barth cPH2 charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of GET parameters provided to the index.php endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the www-data user. Was ZDI-CAN-23115.