Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Iq Gateway Firmware CRITICAL 9.8
CVE-2024-21878

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) all…

Fix: 8.2.4225+
Fix from $2,300 2024-08-12
Iq Gateway Firmware HIGH 8.8
CVE-2024-21879

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoin…

Fix: 8.2.4225+
Fix from $1,950 2024-08-12
Iq Gateway Firmware HIGH 7.2
CVE-2024-21880

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint i…

Fix: after 7.3.120
Fix from $1,950 2024-08-12
Ar2140 Firmware HIGH 7.2
CVE-2024-3659

Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one…

Fix: 4.2.16+
Fix from $1,950 2024-08-08
Koha HIGH 7.2
CVE-2024-28739EPSS 19%

An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.

Fix: after 23.05.00
Fix from $1,950 2024-08-06
Mt6000 Firmware CRITICAL 9.8
CVE-2024-39226EPSS 21%

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4…

No fix yet
Fix from $2,300 2024-08-06
Unclassified CRITICAL 9.3
CVE-2024-7397

Improper filering of special characters result in a command ('command injection') vulnerability in Korenix JetPort 5601v3.This issue affects JetPort …

Mitigation only
Fix from $2,300 2024-08-05
Cp900 Firmware CRITICAL 9.8
CVE-2024-7464EPSS 20%

A vulnerability, which was classified as critical, has been found in TOTOLINK CP900 6.3c.566. This issue affects the function setTelnetCfg of the com…

No fix yet
Fix from $2,300 2024-08-05
Ib8367a Firmware CRITICAL 9.8
CVE-2024-7443

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Vivotek IB8367A VVTK-0100b. Affected is the function getenv …

Mitigation only
Fix from $2,300 2024-08-03
Sd9364 Firmware CRITICAL 9.8
CVE-2024-7442

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been rated as critical. This issue affects the functio…

Mitigation only
Fix from $2,300 2024-08-03
Cc8160 Firmware CRITICAL 9.8
CVE-2024-7440

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d. It has been classified as critical. This affects the function…

Mitigation only
Fix from $2,300 2024-08-03
Di 8100 Firmware HIGH 8.8
CVE-2024-7436EPSS 8%

A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07. This issue affects the function msp_info_htm of the file m…

No fix yet
Fix from $1,950 2024-08-03
Fogproject HIGH 8.6
CVE-2024-42348

FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a comput…

Fix: 1.5.10.41.3+
Fix from $1,950 2024-08-02
Avm1203 Firmware CRITICAL 9.8
CVE-2024-7029EPSS 39%

Commands can be injected over the network and executed without authentication.

No fix yet
Fix from $2,300 2024-08-02
Q14 Firmware HIGH 7.2
CVE-2022-4002

A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

Fix: 1.5.0.16+
Fix from $1,950 2024-07-31
Lr1200 Firmware HIGH 8.8
CVE-2024-7215

A vulnerability was found in TOTOLINK LR1200 9.3.1cu.2832 and classified as critical. Affected by this issue is the function NTPSyncWithHost of the f…

No fix yet
Fix from $1,950 2024-07-30
Lr350 Firmware HIGH 8.8
CVE-2024-7214

A vulnerability has been found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. Affected by this vulnerability is the function set…

No fix yet
Fix from $1,950 2024-07-30
Ipados HIGH 7.8
CVE-2023-40396

The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. An app may …

Fix: 10.0 / 14.0+
Fix from $1,950 2024-07-29
Unclassified HIGH 8.3
CVE-2024-41637

RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo…

Mitigation only
Fix from $1,950 2024-07-29
A3600r Firmware HIGH 8.8
CVE-2024-7181

A vulnerability classified as critical was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This vulnerability affects the function setTelnetCfg of t…

No fix yet
Fix from $1,950 2024-07-29
A3600r Firmware HIGH 8.8
CVE-2024-7177

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been classified as critical. Affected is the function setLanguageCfg of t…

No fix yet
Fix from $1,950 2024-07-29
A3600r Firmware HIGH 8.8
CVE-2024-7174

A vulnerability, which was classified as critical, was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This affects the function setdeviceName of th…

No fix yet
Fix from $1,950 2024-07-29
A3700r Firmware HIGH 8.8
CVE-2024-7160

A vulnerability classified as critical has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWanCfg of the file /cgi-b…

No fix yet
Fix from $1,950 2024-07-28
A3100r Firmware HIGH 8.8
CVE-2024-7158

A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been declared as critical. This vulnerability affects the function setTel…

No fix yet
Fix from $1,950 2024-07-28
Starship HIGH 7.0
CVE-2024-41815

Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quotin…

Fix: 1.20.0+
Fix from $1,950 2024-07-26
Turbomeeting HIGH 7.2
CVE-2024-38288

A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers wit…

Fix: 8.0+
Fix from $1,950 2024-07-25
Edgeconnect Sd Wan Orchestrator HIGH 8.8
CVE-2024-41136

An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful ex…

Fix: after 9.2.9
Fix from $1,950 2024-07-24
Unclassified HIGH 7.2
CVE-2024-41133

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run …

Mitigation only
Fix from $1,950 2024-07-24
Unclassified HIGH 7.2
CVE-2024-41134

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run …

Mitigation only
Fix from $1,950 2024-07-24
Unclassified HIGH 7.2
CVE-2024-41135

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run …

Mitigation only
Fix from $1,950 2024-07-24