Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Wn530h4 Firmware HIGH 7.2
CVE-2024-10429EPSS 18%

A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected is the function set_ipv6 of …

No fix yet
Fix from $1,950 2024-10-27
Unclassified HIGH 7.5
CVE-2024-48139

A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat dat…

Mitigation only
Fix from $1,950 2024-10-24
Unclassified HIGH 7.5
CVE-2024-48140

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to acc…

Mitigation only
Fix from $1,950 2024-10-24
Unclassified HIGH 7.5
CVE-2024-48141

A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent ch…

Mitigation only
Fix from $1,950 2024-10-24
Unclassified HIGH 7.5
CVE-2024-48142

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltr…

Mitigation only
Fix from $1,950 2024-10-24
Unclassified CRITICAL 9.1
CVE-2024-48144

A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate a…

Mitigation only
Fix from $2,300 2024-10-24
Unclassified CRITICAL 9.1
CVE-2024-48145

A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all prev…

Mitigation only
Fix from $2,300 2024-10-24
Unclassified HIGH 8.8
CVE-2024-48440

Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection…

Mitigation only
Fix from $1,950 2024-10-24
Unclassified HIGH 8.8
CVE-2024-48441

Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerab…

Mitigation only
Fix from $1,950 2024-10-24
Cloud Edge CRITICAL 9.8
CVE-2024-48904

An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Pleas…

Fix: 5.6.3228 / 7.0.1081+
Fix from $2,300 2024-10-22
Python HIGH 7.8
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted pro…

Fix: 3.9.21 / 3.10.16+
Fix from $1,950 2024-10-22
Vilo 5 Firmware CRITICAL 9.1
CVE-2024-40089

A Command Injection vulnerability in Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, authenticated attackers to execute arbitrary code by injecti…

Fix: after 5.16.1.33
Fix from $2,300 2024-10-21
Micollab CRITICAL 9.8
CVE-2024-35285

A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attac…

Fix: after 9.8.0.33
Fix from $2,300 2024-10-21
Dcme 320 L Firmware CRITICAL 9.8
CVE-2024-48659

An issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component.

Fix: after 9.3.2.114
Fix from $2,300 2024-10-21
Wn530h4 Firmware HIGH 7.2
CVE-2024-10193EPSS 15%

A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028 and classified as critical. This issue affects the function ping_d…

Fix: after 20221028
Fix from $1,950 2024-10-20
Grafana HIGH 8.8
CVE-2024-9264EPSS 95%

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficie…

Mitigation only
Fix from $1,950 2024-10-18
Unclassified HIGH 7.2
CVE-2024-6333

Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.

No fix yet
Fix from $1,950 2024-10-17
Ex6120 Firmware MEDIUM 6.8
CVE-2024-35518

Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.

Fix: after 1.0.0.68
Fix from $1,600 2024-10-14
Ex3700 Firmware MEDIUM 6.8
CVE-2024-35519

Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap…

Fix: after 1.0.2.28
Fix from $1,600 2024-10-14
R7000 Firmware MEDIUM 6.8
CVE-2024-35520EPSS 9%

Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.

Mitigation only
Fix from $1,600 2024-10-14
Vigor3900 Firmware CRITICAL 9.8
CVE-2024-48153

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subco…

Mitigation only
Fix from $2,300 2024-10-14
Ex3700 Firmware HIGH 7.2
CVE-2024-35522

Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injection in operating_mode.cgi via t…

Fix: 1.0.0.98+
Fix from $1,950 2024-10-11
Xr1000 Firmware HIGH 7.2
CVE-2024-35517EPSS 15%

Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.

Mitigation only
Fix from $1,950 2024-10-11
Unclassified HIGH 8.8
CVE-2024-44413

A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in th…

Mitigation only
Fix from $1,950 2024-10-11
Junos Space HIGH 7.3
CVE-2024-39563

A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted reque…

Mitigation only
Fix from $1,950 2024-10-11
Ac1206 Firmware CRITICAL 9.8
CVE-2024-9793EPSS 23%

A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconf…

No fix yet
Fix from $2,300 2024-10-10
Unclassified MEDIUM 6.7
CVE-2024-38817

VMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious pa…

Mitigation only
Fix from $1,600 2024-10-09
Telerik Reporting HIGH 7.8
CVE-2024-7840

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hype…

Fix: after 18.2.24.924
Fix from $1,950 2024-10-09
Android MEDIUM 6.7
CVE-2024-39437

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,600 2024-10-09
Android MEDIUM 6.7
CVE-2024-39438

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,600 2024-10-09