Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Connect Secure HIGH 7.2
CVE-2024-11634

Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated att…

Fix: 22.7+
Fix from $1,950 2024-12-10
Cloud Services Appliance HIGH 7.2
CVE-2024-11772EPSS 8%

Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve…

Fix: 5.0.3+
Fix from $1,950 2024-12-10
Iap 420 Firmware CRITICAL 9.8
CVE-2024-55547EPSS 17%

SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.

Fix: after 2.01e
Fix from $2,300 2024-12-10
Iap 420 Firmware HIGH 8.8
CVE-2024-55544EPSS 12%

Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.…

Fix: after 2.01e
Fix from $1,950 2024-12-10
Unclassified HIGH 7.6
CVE-2024-53919

An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physi…

Mitigation only
Fix from $1,950 2024-12-10
Datax Web HIGH 8.8
CVE-2024-12358

A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. …

No fix yet
Fix from $1,950 2024-12-09
Jfinalcms HIGH 8.8
CVE-2024-12350

A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the file \src\main\java\c…

No fix yet
Fix from $1,950 2024-12-09
Hybrid Backup Sync CRITICAL 9.8
CVE-2024-50388

An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attack…

Mitigation only
Fix from $2,300 2024-12-06
Clearpass Policy Manager HIGH 8.0
CVE-2024-51772

An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary …

Fix: 6.11.10 / 6.12.3+
Fix from $1,950 2024-12-03
Clearpass Policy Manager MEDIUM 6.3
CVE-2024-53672

A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the und…

Fix: 6.11.10 / 6.12.3+
Fix from $1,600 2024-12-03
Unclassified HIGH 8.8
CVE-2024-51114

An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via the code/fun…

Mitigation only
Fix from $1,950 2024-12-03
Clearpass Policy Manager HIGH 8.8
CVE-2024-51771

A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor …

Fix: 6.11.10 / 6.12.3+
Fix from $1,950 2024-12-03
Unclassified HIGH 7.8
CVE-2024-29404

An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter o…

Mitigation only
Fix from $1,950 2024-12-03
Unclassified HIGH 7.2
CVE-2024-11013

Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14…

Mitigation only
Fix from $1,950 2024-11-29
Aria Operations HIGH 7.8
CVE-2024-38831

VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malici…

Fix: 8.18.2+
Fix from $1,950 2024-11-26
Enh1350ext Firmware HIGH 7.2
CVE-2024-11659EPSS 28%

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this issue is some u…

No fix yet
Fix from $1,950 2024-11-25
Enh1350ext Firmware HIGH 7.2
CVE-2024-11657EPSS 28%

A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. Affected is an unknown f…

No fix yet
Fix from $1,950 2024-11-25
Enh1350ext Firmware HIGH 7.2
CVE-2024-11658EPSS 28%

A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this vulnerabil…

No fix yet
Fix from $1,950 2024-11-25
Enh1350ext Firmware HIGH 7.2
CVE-2024-11656EPSS 27%

A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This issue affects …

No fix yet
Fix from $1,950 2024-11-25
Enh1350ext Firmware HIGH 7.2
CVE-2024-11655EPSS 27%

A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vulnerability affects unknown c…

No fix yet
Fix from $1,950 2024-11-25
Enh1350ext Firmware HIGH 7.2
CVE-2024-11653EPSS 28%

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical. Affected by this issue is so…

No fix yet
Fix from $1,950 2024-11-25
Enh1350ext Firmware HIGH 7.2
CVE-2024-11654EPSS 28%

A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This affects an unknown part of…

No fix yet
Fix from $1,950 2024-11-25
Enh1350ext Firmware HIGH 7.2
CVE-2024-11652EPSS 29%

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critical. Affected by this vulnerab…

No fix yet
Fix from $1,950 2024-11-25
Enh1350ext Firmware HIGH 7.2
CVE-2024-11651EPSS 26%

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been classified as critical. Affected is an unknown …

No fix yet
Fix from $1,950 2024-11-25
Salia Plcc Firmware HIGH 8.8
CVE-2024-11665

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Comm…

Fix: after 2.0.4
Fix from $1,950 2024-11-24
Virtualenv HIGH 7.8
CVE-2024-53899

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted co…

Fix: 20.26.6+
Fix from $1,950 2024-11-24
Unclassified CRITICAL 9.8
CVE-2024-37782

An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbi…

Mitigation only
Fix from $2,300 2024-11-22
Qurouter CRITICAL 9.8
CVE-2024-48860

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attack…

Mitigation only
Fix from $2,300 2024-11-22
Qurouter HIGH 7.8
CVE-2024-48861

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network…

Mitigation only
Fix from $1,950 2024-11-22
Notes Station 3 HIGH 8.8
CVE-2024-38644

An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated a…

Fix: 3.9.7+
Fix from $1,950 2024-11-22