Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
A6000r Firmware HIGH 8.0
CVE-2024-57211

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh funct…

No fix yet
Fix from $1,950 2025-01-10
A6000r Firmware MEDIUM 5.1
CVE-2024-57212

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot funct…

No fix yet
Fix from $1,600 2025-01-10
Ac9 Firmware CRITICAL 9.8
CVE-2025-22949

Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution.

No fix yet
Fix from $2,300 2025-01-10
Unclassified HIGH 7.3
CVE-2025-0328

A vulnerability, which was classified as critical, has been found in KaiYuanTong ECT Platform up to 2.0.0. Affected by this issue is some unknown fun…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified HIGH 8.1
CVE-2024-27980

Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary …

Mitigation only
Fix from $1,950 2025-01-09
Composio MEDIUM 6.4
CVE-2024-53526

composio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.

No fix yet
Fix from $1,600 2025-01-08
Unclassified HIGH 8.8
CVE-2024-51442

Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf con…

Mitigation only
Fix from $1,950 2025-01-08
Unclassified HIGH 7.2
CVE-2024-54006

Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote comm…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified HIGH 7.2
CVE-2024-54007

Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote comm…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified CRITICAL 9.8
CVE-2024-55414

A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memo…

Mitigation only
Fix from $2,300 2025-01-07
Unclassified HIGH 8.8
CVE-2024-13129EPSS 18%

A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of …

Patch available
Fix from $1,950 2025-01-03
Unclassified HIGH 7.2
CVE-2024-13062

An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. Refer to the '…

Mitigation only
Fix from $1,950 2025-01-02
Unclassified HIGH 7.2
CVE-2024-12912

An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. Refer to the '01/02/2025 ASUS …

Mitigation only
Fix from $1,950 2025-01-02
Vigor300b Firmware CRITICAL 9.8
CVE-2024-12987 KEVEPSS 98%

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file …

Mitigation only
Fix from $2,300 2024-12-27
Vigor300b Firmware CRITICAL 9.8
CVE-2024-12986EPSS 33%

A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown…

Fix: 1.5.1.5+
Fix from $2,300 2024-12-27
Unclassified MEDIUM 6.3
CVE-2024-12985

A vulnerability classified as critical was found in Overtek OT-E801G OTE801G65.1.1.0. This vulnerability affects unknown code of the file /diag_ping.…

Mitigation only
Fix from $1,600 2024-12-27
Unclassified HIGH 7.8
CVE-2020-13712

A command injection is possible through the user interface, allowing arbitrary command execution as the root user. oMG2000 running MGOS 3.15.1 or ea…

Mitigation only
Fix from $1,950 2024-12-20
Cv81 Wdm Firmware CRITICAL 9.8
CVE-2022-32203

There is a command injection vulnerability in Huawei terminal printer product. Successful exploitation could result in the highest privileges of the …

Mitigation only
Fix from $2,300 2024-12-20
Unclassified HIGH 8.0
CVE-2024-12111

In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows auth…

Mitigation only
Fix from $1,950 2024-12-19
Qufirewall HIGH 7.2
CVE-2023-23356

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow rem…

Fix: 2.3.3+
Fix from $1,950 2024-12-19
Seacms CRITICAL 9.8
CVE-2024-55461

SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().

Fix: after 13.0
Fix from $2,300 2024-12-18
Unclassified HIGH 8.8
CVE-2024-39703

In ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary commands by sending a crafted request to an API endpoint.

Mitigation only
Fix from $1,950 2024-12-18
Unclassified HIGH 7.3
CVE-2024-49194

Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL parameter.…

Mitigation only
Fix from $1,950 2024-12-17
Privileged Remote Access CRITICAL 9.8
CVE-2024-12356 KEVEPSS 88%

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated at…

Fix: after 24.3.1
Fix from $2,300 2024-12-17
Universal Normalizer HIGH 7.1
CVE-2024-56084

An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. Th…

Fix: 5.7.0+
Fix from $1,950 2024-12-16
Siem MEDIUM 5.9
CVE-2024-56085

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are execute…

Fix: 7.5.0+
Fix from $1,600 2024-12-16
Siem HIGH 7.1
CVE-2024-56086

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup pro…

Fix: 7.5.0+
Fix from $1,950 2024-12-16
Siem MEDIUM 5.9
CVE-2024-56087

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are execute…

Fix: 7.5.0+
Fix from $1,600 2024-12-16
Harmony CRITICAL 9.8
CVE-2024-55956 KEVEPSS 94%

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash…

Fix: 5.8.0.24+
Fix from $2,300 2024-12-13
Thinos HIGH 8.4
CVE-2024-53290

Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenti…

Mitigation only
Fix from $1,950 2024-12-11