Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Factorytalk View CRITICAL 9.8
CVE-2024-45824

CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Comm…

Fix: after 14.0
Fix from $2,300 2024-09-12
Rely Pcie Firmware HIGH 8.8
CVE-2024-44570

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.

Fix: after 23.1.0
Fix from $1,950 2024-09-11
Rely Pcie Firmware HIGH 8.8
CVE-2024-44572

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.

Fix: after 23.1.0
Fix from $1,950 2024-09-11
Rely Pcie Firmware HIGH 8.8
CVE-2024-44574

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.

Fix: after 23.1.0
Fix from $1,950 2024-09-11
Rely Pcie Firmware HIGH 8.8
CVE-2024-44577

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.

Fix: after 23.1.0
Fix from $1,950 2024-09-11
Cf Xr11 Firmware CRITICAL 9.8
CVE-2024-44466EPSS 11%

COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and…

No fix yet
Fix from $2,300 2024-09-11
Sharepoint Server HIGH 7.2
CVE-2024-38227EPSS 8%

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-09-10
Sharepoint Server HIGH 7.2
CVE-2024-38228

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-09-10
Ac15 Firmware CRITICAL 9.8
CVE-2023-36103

Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via craft…

No fix yet
Fix from $2,300 2024-09-10
Forticlient Enterprise Management Server HIGH 7.3
CVE-2024-33508

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 throug…

Fix: 7.0.13 / 7.2.5+
Fix from $1,950 2024-09-10
Wyse Thinos HIGH 7.6
CVE-2024-42427

Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An…

Mitigation only
Fix from $1,950 2024-09-10
Di 8300 Firmware CRITICAL 9.8
CVE-2024-44410

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

No fix yet
Fix from $2,300 2024-09-09
Unclassified HIGH 8.8
CVE-2024-44334EPSS 32%

D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.…

Mitigation only
Fix from $1,950 2024-09-09
Unclassified HIGH 8.8
CVE-2024-44335EPSS 12%

D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1…

Mitigation only
Fix from $1,950 2024-09-09
Unclassified HIGH 8.1
CVE-2024-36138

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.…

Mitigation only
Fix from $1,950 2024-09-07
Vigor3900 Firmware HIGH 8.8
CVE-2024-44844

DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command funct…

No fix yet
Fix from $1,950 2024-09-06
Vigor3900 Firmware HIGH 8.8
CVE-2024-44845

DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string fu…

No fix yet
Fix from $1,950 2024-09-06
Qts HIGH 7.8
CVE-2024-38641

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $1,950 2024-09-06
Video Station HIGH 8.8
CVE-2023-47563

An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to e…

Fix: 5.8.2+
Fix from $1,950 2024-09-06
Di 8100g Firmware CRITICAL 9.8
CVE-2024-44401

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file

No fix yet
Fix from $2,300 2024-09-06
Di 8100g Firmware CRITICAL 9.8
CVE-2024-44402

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.

No fix yet
Fix from $2,300 2024-09-06
Smartfabric Os10 HIGH 8.8
CVE-2024-38486

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used i…

Fix: 10.5.6.4+
Fix from $1,950 2024-09-06
Fbm 291w Firmware MEDIUM 6.8
CVE-2024-44383

WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.

No fix yet
Fix from $1,600 2024-09-04
Di 8400 Firmware CRITICAL 9.8
CVE-2024-44400EPSS 14%

A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in th…

No fix yet
Fix from $2,300 2024-09-04
Seacms HIGH 7.2
CVE-2024-44916

Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php f…

No fix yet
Fix from $1,950 2024-08-30
Unclassified CRITICAL 9.8
CVE-2024-42905EPSS 15%

Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device …

Mitigation only
Fix from $2,300 2024-08-28
Netiq Advanced Authentication HIGH 7.2
CVE-2021-38120

A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to i…

Fix: 6.3+
Fix from $1,950 2024-08-28
Dns 315l Firmware CRITICAL 9.8
CVE-2024-8212EPSS 7%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-27
Dns 315l Firmware CRITICAL 9.8
CVE-2024-8213EPSS 7%

A vulnerability classified as critical has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323…

No fix yet
Fix from $2,300 2024-08-27
Dns 315l Firmware CRITICAL 9.8
CVE-2024-8214EPSS 5%

A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS…

No fix yet
Fix from $2,300 2024-08-27