Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Dir 820l Firmware HIGH 8.0
CVE-2024-51186

D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 …

No fix yet
Fix from $1,950 2024-11-11
Di 8003 Firmware CRITICAL 9.8
CVE-2024-11046

A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been classified as critical. Affected is the function upgrade_filter_asp of the file /…

No fix yet
Fix from $2,300 2024-11-10
Unclassified HIGH 7.8
CVE-2024-50591

An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a comm…

Mitigation only
Fix from $1,950 2024-11-08
X18 Firmware HIGH 8.8
CVE-2024-10966

A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown func…

No fix yet
Fix from $1,950 2024-11-07
Symfony CRITICAL 9.8
CVE-2024-51736

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.…

Fix: 5.4.46 / 6.4.14+
Fix from $2,300 2024-11-06
Unclassified CRITICAL 10.0
CVE-2024-20418

A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB)…

Mitigation only
Fix from $2,300 2024-11-06
Unclassified CRITICAL 9.8
CVE-2024-48746

An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language processing co…

Mitigation only
Fix from $2,300 2024-11-05
Dcme 320 Firmware CRITICAL 9.8
CVE-2024-51115

DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.

No fix yet
Fix from $2,300 2024-11-05
Unclassified CRITICAL 9.8
CVE-2024-42509

Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packet…

Mitigation only
Fix from $2,300 2024-11-05
Unclassified CRITICAL 9.0
CVE-2024-47460

Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packet…

Mitigation only
Fix from $2,300 2024-11-05
Unclassified HIGH 7.2
CVE-2024-47461

An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vul…

Mitigation only
Fix from $1,950 2024-11-05
Poly Tc8 Firmware HIGH 7.5
CVE-2024-9579

A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exp…

Fix: 4.3.2 / 6.3.2+
Fix from $1,950 2024-11-05
R8500 Firmware HIGH 8.0
CVE-2024-52022

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in …

Mitigation only
Fix from $1,950 2024-11-05
Coslat CRITICAL 9.8
CVE-2024-10035

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Impro…

Fix: after 3.1069
Fix from $2,300 2024-11-04
Ac6 Firmware CRITICAL 9.8
CVE-2024-10697EPSS 26%

A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of…

No fix yet
Fix from $2,300 2024-11-02
Vigor3900 Firmware CRITICAL 9.8
CVE-2024-51255

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_…

Mitigation only
Fix from $2,300 2024-10-31
Vigor3900 Firmware CRITICAL 9.8
CVE-2024-51260

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_proc…

Mitigation only
Fix from $2,300 2024-10-31
Vigor3900 Firmware HIGH 8.8
CVE-2024-51254

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cace…

Mitigation only
Fix from $1,950 2024-10-31
Vigor3900 Firmware CRITICAL 9.8
CVE-2024-51259

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cac…

Mitigation only
Fix from $2,300 2024-10-31
Unclassified HIGH 8.4
CVE-2024-48214

KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulne…

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware HIGH 8.8
CVE-2024-51258

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunn…

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware HIGH 8.8
CVE-2024-51257

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertifi…

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware HIGH 8.8
CVE-2024-51296

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace f…

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware HIGH 8.8
CVE-2024-51299

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog …

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware HIGH 8.8
CVE-2024-51300

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd fun…

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware HIGH 8.8
CVE-2024-51301

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_moni…

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware HIGH 8.8
CVE-2024-51304

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search…

Mitigation only
Fix from $1,950 2024-10-30
Tro610 Firmware HIGH 7.2
CVE-2024-41153

Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If …

Fix: 9.2.0.5+
Fix from $1,950 2024-10-29
Unclassified MEDIUM 6.3
CVE-2024-10435

A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cov/trigge…

Mitigation only
Fix from $1,600 2024-10-28
Wn530h4 Firmware HIGH 7.2
CVE-2024-10428EPSS 15%

A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function se…

No fix yet
Fix from $1,950 2024-10-27