Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Sterling Secure Proxy CRITICAL 9.1
CVE-2024-41783

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlyi…

Fix: 6.0.3.1+
Fix from $2,300 2025-01-19
Ac8 Firmware HIGH 7.2
CVE-2025-0528EPSS 6%

A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown fun…

No fix yet
Fix from $1,950 2025-01-17
Unclassified HIGH 8.7
CVE-2024-54660

A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can in…

Mitigation only
Fix from $1,950 2025-01-16
Ac18 Firmware CRITICAL 9.8
CVE-2024-57583

Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.

Mitigation only
Fix from $2,300 2025-01-16
Re11s Firmware CRITICAL 9.8
CVE-2025-22912

RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.

No fix yet
Fix from $2,300 2025-01-16
Unclassified HIGH 7.2
CVE-2025-23052

Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerab…

Mitigation only
Fix from $1,950 2025-01-14
Wl Wn533a8 Firmware HIGH 7.2
CVE-2024-39782

Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially craft…

No fix yet
Fix from $1,950 2025-01-14
Wl Wn533a8 Firmware HIGH 7.2
CVE-2024-39783

Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially craft…

No fix yet
Fix from $1,950 2025-01-14
Wl Wn533a8 Firmware HIGH 7.2
CVE-2024-39781

Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially craft…

No fix yet
Fix from $1,950 2025-01-14
Wl Wn533a8 Firmware CRITICAL 9.8
CVE-2024-39759EPSS 8%

Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially c…

No fix yet
Fix from $2,300 2025-01-14
Wl Wn533a8 Firmware CRITICAL 9.8
CVE-2024-39760EPSS 17%

Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially c…

No fix yet
Fix from $2,300 2025-01-14
Wl Wn533a8 Firmware CRITICAL 9.8
CVE-2024-39761EPSS 8%

Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially c…

No fix yet
Fix from $2,300 2025-01-14
Wl Wn533a8 Firmware HIGH 7.2
CVE-2024-39762EPSS 6%

Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A speci…

No fix yet
Fix from $1,950 2025-01-14
Wl Wn533a8 Firmware HIGH 7.2
CVE-2024-39763

Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A speci…

No fix yet
Fix from $1,950 2025-01-14
Wl Wn533a8 Firmware HIGH 7.2
CVE-2024-39764

Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A speci…

No fix yet
Fix from $1,950 2025-01-14
Wl Wn533a8 Firmware HIGH 7.2
CVE-2024-39765EPSS 5%

Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A speci…

No fix yet
Fix from $1,950 2025-01-14
Wl Wn533a8 Firmware HIGH 7.2
CVE-2024-39360EPSS 12%

An os command injection vulnerability exists in the nas.cgi remove_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP…

No fix yet
Fix from $1,950 2025-01-14
Wl Wn533a8 Firmware HIGH 7.2
CVE-2024-39367EPSS 8%

An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A specia…

No fix yet
Fix from $1,950 2025-01-14
Wl Wn533a8 Firmware HIGH 7.2
CVE-2024-37186EPSS 23%

An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HT…

No fix yet
Fix from $1,950 2025-01-14
Wl Wn533a8 Firmware CRITICAL 9.8
CVE-2024-34166EPSS 16%

An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A speciall…

No fix yet
Fix from $2,300 2025-01-14
Unclassified HIGH 7.8
CVE-2025-0396

A vulnerability, which was classified as critical, has been found in exelban stats up to 2.11.21. This issue affects the function shouldAcceptNewConn…

Mitigation only
Fix from $1,950 2025-01-12
E7350 Firmware CRITICAL 9.8
CVE-2024-57223

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

No fix yet
Fix from $2,300 2025-01-10
E7350 Firmware CRITICAL 9.8
CVE-2024-57224

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

No fix yet
Fix from $2,300 2025-01-10
E7350 Firmware CRITICAL 9.8
CVE-2024-57225

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.

No fix yet
Fix from $2,300 2025-01-10
E7350 Firmware HIGH 8.0
CVE-2024-57226

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.

No fix yet
Fix from $1,950 2025-01-10
E7350 Firmware HIGH 8.0
CVE-2024-57227

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.

No fix yet
Fix from $1,950 2025-01-10
E7350 Firmware HIGH 8.0
CVE-2024-57228

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.

No fix yet
Fix from $1,950 2025-01-10
E7350 Firmware MEDIUM 6.3
CVE-2024-57222

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

No fix yet
Fix from $1,600 2025-01-10
A6000r Firmware MEDIUM 6.3
CVE-2024-57213

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_passwd fu…

No fix yet
Fix from $1,600 2025-01-10
A6000r Firmware MEDIUM 6.3
CVE-2024-57214

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi functio…

No fix yet
Fix from $1,600 2025-01-10