Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Dns 315l Firmware CRITICAL 9.8
CVE-2024-8210EPSS 7%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-27
Dns 315l Firmware CRITICAL 9.8
CVE-2024-8211EPSS 5%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-27
Ax9000 Firmware HIGH 8.8
CVE-2023-26315EPSS 19%

The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allo…

Fix: 1.0.174+
Fix from $1,950 2024-08-26
Web Application Firewall CRITICAL 9.8
CVE-2024-8073

Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issu…

Mitigation only
Fix from $2,300 2024-08-26
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8134EPSS 8%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-24
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8133EPSS 8%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-24
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8131EPSS 8%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-24
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8132EPSS 23%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-24
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8130EPSS 8%

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS…

No fix yet
Fix from $2,300 2024-08-24
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8129EPSS 23%

A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, …

No fix yet
Fix from $2,300 2024-08-24
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8128EPSS 8%

A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-3…

No fix yet
Fix from $2,300 2024-08-24
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8127EPSS 7%

A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS…

No fix yet
Fix from $2,300 2024-08-24
Di 8004w Firmware CRITICAL 9.8
CVE-2024-44381

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

No fix yet
Fix from $2,300 2024-08-23
Di 8004w Firmware CRITICAL 9.8
CVE-2024-44382

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.

No fix yet
Fix from $2,300 2024-08-23
Dedecms HIGH 7.2
CVE-2024-42636

DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.

Mitigation only
Fix from $1,950 2024-08-23
GitLab MEDIUM 6.4
CVE-2024-7110

An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 allows an attacke…

Fix: 17.1.6 / 17.2.4+
Fix from $1,600 2024-08-22
Vigor300b Firmware HIGH 8.0
CVE-2024-43027

DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_Beta were discovered to conta…

Fix: 1.5.1.5+
Fix from $1,950 2024-08-21
Dns 120 Firmware CRITICAL 9.8
CVE-2024-7922EPSS 19%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-19
X6000r Firmware CRITICAL 9.8
CVE-2024-7907EPSS 6%

A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719. This issue affects the function setSyslogC…

No fix yet
Fix from $2,300 2024-08-18
Online Store Management System HIGH 8.8
CVE-2024-7897

A vulnerability classified as critical has been found in Tosei Online Store Management System ネット店舗管理システム 4.02/4.03/4.04. This affects an …

Mitigation only
Fix from $1,950 2024-08-17
Online Store Management System HIGH 8.8
CVE-2024-7896

A vulnerability was found in Tosei Online Store Management System ネット店舗管理システム 4.02/4.03/4.04. It has been rated as critical. Affected by t…

Mitigation only
Fix from $1,950 2024-08-17
Fh1201 Firmware CRITICAL 9.8
CVE-2024-42947

An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP …

No fix yet
Fix from $2,300 2024-08-15
Di 8100 Firmware CRITICAL 9.8
CVE-2024-7833

A vulnerability was found in D-Link DI-8100 16.07. It has been classified as critical. This affects the function upgrade_filter_asp of the file upgra…

Mitigation only
Fix from $2,300 2024-08-15
Sequenceserver CRITICAL 9.8
CVE-2024-42360

SequenceServer lets you rapidly set up a BLAST+ server with an intuitive user interface for personal or group use. Several HTTP endpoints did not pro…

Fix: 3.1.2+
Fix from $2,300 2024-08-14
Cortex Xsoar Commonscripts CRITICAL 9.8
CVE-2024-5914

A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands with…

Fix: 1.12.33+
Fix from $2,300 2024-08-14
Unclassified MEDIUM 6.3
CVE-2024-7715EPSS 25%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS…

Mitigation only
Fix from $1,600 2024-08-13
Foreman MEDIUM 6.5
CVE-2024-7700

A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Ho…

Mitigation only
Fix from $1,600 2024-08-12
Ic 6220dc Firmware CRITICAL 9.8
CVE-2024-7616

A vulnerability was found in Edimax IC-6220DC and IC-5150W up to 3.06. It has been rated as critical. Affected by this issue is the function cgiFormS…

Fix: after 3.06
Fix from $2,300 2024-08-12
Var1200 H Firmware CRITICAL 9.9
CVE-2024-37023

Multiple OS command injection vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.…

Fix: after 3.3.23.6.9
Fix from $2,300 2024-08-12
Zabbix CRITICAL 9.1
CVE-2024-22122

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web …

Fix: after 6.4.15
Fix from $2,300 2024-08-12