Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Android MEDIUM 6.7
CVE-2024-39436

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,600 2024-10-09
Unclassified HIGH 8.4
CVE-2023-37154

check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. T…

Patch available
Fix from $1,950 2024-10-09
Azure Command Line Interface CRITICAL 9.1
CVE-2024-43591

Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability

Fix: 2.65.0+
Fix from $2,300 2024-10-08
Visual Studio Code HIGH 7.8
CVE-2024-43601

Visual Studio Code for Linux Remote Code Execution Vulnerability

Fix: 1.94.1+
Fix from $1,950 2024-10-08
Deepspeed HIGH 7.8
CVE-2024-43497

DeepSpeed Remote Code Execution Vulnerability

Fix: 0.15.1+
Fix from $1,950 2024-10-08
Endpoint Manager Cloud Services Appliance HIGH 7.2
CVE-2024-9380 KEVEPSS 63%

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin p…

Fix: 5.0.2+
Fix from $1,950 2024-10-08
Sinec Security Monitor HIGH 8.8
CVE-2024-47562

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special …

Fix: 4.9.0+
Fix from $1,950 2024-10-08
Telepresence Video Communication Server MEDIUM 6.7
CVE-2024-20492

A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perform command injection attacks …

Mitigation only
Fix from $1,600 2024-10-02
Nexus Dashboard Fabric Controller HIGH 8.8
CVE-2024-20432

A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote att…

Fix: 12.2.2+
Fix from $1,950 2024-10-02
Unified Computing System HIGH 7.2
CVE-2024-20365

A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers could allow an authenticated, re…

Mitigation only
Fix from $1,950 2024-10-02
Scriptcase HIGH 8.0
CVE-2024-46084

Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.

Fix: after 9.10.023
Fix from $1,950 2024-10-01
Unclassified MEDIUM 5.6
CVE-2024-44610

PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via shell metacharacters in a Softw…

Mitigation only
Fix from $1,600 2024-10-01
Unclassified HIGH 7.1
CVE-2024-9145

Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in versions 0.13.0 up to 0.17.8 are…

Mitigation only
Fix from $1,950 2024-10-01
Nginx Proxy Manager CRITICAL 9.8
CVE-2024-46256

A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.

Patch available
Fix from $2,300 2024-09-27
Smartfabric Os10 HIGH 8.8
CVE-2024-39577

Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of Special Elements used in a Co…

Fix: 10.5.3.11 / 10.5.4.12+
Fix from $1,950 2024-09-26
Papercut Mf MEDIUM 5.5
CVE-2024-8405

An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists…

Fix: 23.0.9+
Fix from $1,600 2024-09-26
Ui For Wpf HIGH 7.8
CVE-2024-7679

In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of…

Fix: 2024.3.924+
Fix from $1,950 2024-09-25
Ui For Wpf CRITICAL 9.8
CVE-2024-7575

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hype…

Fix: 2024.3.924+
Fix from $2,300 2024-09-25
Progauge Maglink Lx Console Firmware CRITICAL 9.8
CVE-2024-43693

A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.

Fix: after 4.17.9e
Fix from $2,300 2024-09-25
Progauge Maglink Lx Console Firmware CRITICAL 9.8
CVE-2024-45066

A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.

Fix: after 4.17.9e
Fix from $2,300 2024-09-25
Unclassified CRITICAL 9.8
CVE-2024-42505

Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted pack…

Mitigation only
Fix from $2,300 2024-09-25
Unclassified CRITICAL 9.8
CVE-2024-42506

Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted pack…

Mitigation only
Fix from $2,300 2024-09-25
Unclassified CRITICAL 9.8
CVE-2024-42507

Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted pack…

Mitigation only
Fix from $2,300 2024-09-25
Purity\/\/fa HIGH 8.8
CVE-2024-0005

A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically craf…

Fix: after 6.4.10
Fix from $1,950 2024-09-23
Ax9000 Firmware HIGH 8.8
CVE-2024-45348

Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, …

Fix: 1.0.174+
Fix from $1,950 2024-09-23
Dedecms HIGH 8.8
CVE-2024-9076EPSS 21%

A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/artic…

Fix: after 5.7.115
Fix from $1,950 2024-09-22
Proroute H685t W Firmware CRITICAL 9.8
CVE-2024-45682

There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system.

No fix yet
Fix from $2,300 2024-09-17
Unifi Network Application HIGH 7.8
CVE-2024-42025

A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) al…

Fix: 8.4.59+
Fix from $1,950 2024-09-13
Fh451 Firmware CRITICAL 9.8
CVE-2024-46048EPSS 11%

Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i

No fix yet
Fix from $2,300 2024-09-13
GitLab HIGH 8.8
CVE-2024-8640

An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior …

Fix: 17.1.7 / 17.2.5+
Fix from $1,950 2024-09-12