Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Imanager CRITICAL 9.8
CVE-2023-24467

Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.

Fix: 3.2.6+
Fix from $2,300 2024-11-22
Imanager HIGH 8.8
CVE-2021-38116

Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5

Fix: 3.2.5+
Fix from $1,950 2024-11-22
Imanager CRITICAL 9.8
CVE-2021-38117

Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

Fix: 3.2.5+
Fix from $2,300 2024-11-22
Ex200 Firmware MEDIUM 6.3
CVE-2024-53333EPSS 19%

TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an at…

No fix yet
Fix from $1,600 2024-11-21
Tl Ipc42c Firmware HIGH 8.0
CVE-2024-48288EPSS 10%

TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and bac…

No fix yet
Fix from $1,950 2024-11-21
E3000 Firmware HIGH 8.0
CVE-2024-48286EPSS 12%

Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.

No fix yet
Fix from $1,950 2024-11-21
Unclassified MEDIUM 6.8
CVE-2024-48747

An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.

Mitigation only
Fix from $1,600 2024-11-21
Pandora Fms CRITICAL 9.8
CVE-2024-11320EPSS 91%

Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects P…

Fix: 777.5+
Fix from $2,300 2024-11-21
Di 8200 Firmware CRITICAL 9.8
CVE-2024-51151EPSS 30%

D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter.

No fix yet
Fix from $2,300 2024-11-21
Unclassified CRITICAL 9.1
CVE-2024-33439

An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters.

Mitigation only
Fix from $2,300 2024-11-20
Di 8400 Firmware HIGH 8.0
CVE-2024-52739EPSS 9%

D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the fla…

No fix yet
Fix from $1,950 2024-11-20
Unclassified CRITICAL 9.1
CVE-2024-29292

Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbi…

Mitigation only
Fix from $2,300 2024-11-20
Deep Security Agent HIGH 8.8
CVE-2024-51503

A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges…

Mitigation only
Fix from $1,950 2024-11-19
Hertzbeat HIGH 8.8
CVE-2024-45505

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerabili…

Fix: 1.6.1+
Fix from $1,950 2024-11-18
Photos CRITICAL 9.8
CVE-2024-10443EPSS 28%

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePho…

Fix: 1.0.2-10026 / 1.1.0-10053+
Fix from $2,300 2024-11-15
Gogs CRITICAL 9.8
CVE-2022-1884

A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to imp…

Fix: after 0.12.7
Fix from $2,300 2024-11-15
Cli CRITICAL 9.6
CVE-2024-52308

The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ss…

Fix: 2.62.0+
Fix from $2,300 2024-11-14
Unclassified MEDIUM 6.5
CVE-2024-51027EPSS 7%

Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networksafe.php via the province parameter.

Mitigation only
Fix from $1,600 2024-11-13
G3 Firmware HIGH 8.8
CVE-2024-50852

Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.

No fix yet
Fix from $1,950 2024-11-13
G3 Firmware HIGH 8.8
CVE-2024-50853

Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.

No fix yet
Fix from $1,950 2024-11-13
Unclassified HIGH 8.0
CVE-2024-28726EPSS 8%

An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a c…

Mitigation only
Fix from $1,950 2024-11-12
Dwr 2000m Firmware CRITICAL 9.8
CVE-2024-28729

An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a c…

No fix yet
Fix from $2,300 2024-11-12
Unclassified HIGH 7.3
CVE-2021-27702

Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the router dashboard.

No fix yet
Fix from $1,950 2024-11-12
Azure Database For Postgresql Flexible Server HIGH 7.2
CVE-2024-49042

Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability

Fix: 12.20 / 13.16+
Fix from $1,950 2024-11-12
Azure Database For Postgresql Flexible Server HIGH 7.2
CVE-2024-43613

Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability

Fix: 12.20 / 13.16+
Fix from $1,950 2024-11-12
365 Apps HIGH 7.8
CVE-2024-49026

Microsoft Excel Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-11-12
Ruggedcom Rm1224 Lte\(4g\) Eu Firmware HIGH 7.2
CVE-2024-50572

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…

Fix: 8.2+
Fix from $1,950 2024-11-12
Smartfabric Os10 HIGH 7.8
CVE-2024-49557

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization of Special Elements used in …

Fix: 10.5.4.13 / 10.5.5.12+
Fix from $1,950 2024-11-12
Smartfabric Os10 HIGH 7.8
CVE-2024-49560

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a command injection vulnerability. A low privileged att…

Fix: 10.5.4.13 / 10.5.5.12+
Fix from $1,950 2024-11-12
Unclassified CRITICAL 9.8
CVE-2024-25255

Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties report that …

No fix yet
Fix from $2,300 2024-11-11