Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
A6000r Firmware CRITICAL 9.8
CVE-2024-41319EPSS 6%

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.

No fix yet
Fix from $2,300 2024-07-23
A6000r Firmware CRITICAL 9.8
CVE-2024-41316

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps fu…

No fix yet
Fix from $2,300 2024-07-22
A6000r Firmware CRITICAL 9.8
CVE-2024-41318

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pinco…

No fix yet
Fix from $2,300 2024-07-22
A6000r Firmware HIGH 8.8
CVE-2024-41320

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the get_apcli_conn_info…

No fix yet
Fix from $1,950 2024-07-22
Ax9 Firmware HIGH 8.0
CVE-2024-39963

AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contai…

No fix yet
Fix from $1,950 2024-07-19
Unclassified CRITICAL 9.4
CVE-2024-38492

This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted…

Mitigation only
Fix from $2,300 2024-07-15
Unclassified HIGH 8.8
CVE-2024-30213

StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to…

Mitigation only
Fix from $1,950 2024-07-12
Poultry Farm Management System CRITICAL 9.8
CVE-2024-40110

Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the productimage paramet…

No fix yet
Fix from $2,300 2024-07-12
Fogproject CRITICAL 9.8
CVE-2024-39914EPSS 23%

FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected…

Fix: 1.5.10.41+
Fix from $2,300 2024-07-12
Sinema Remote Connect Client HIGH 7.8
CVE-2024-39567

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnera…

Fix: 3.2+
Fix from $1,950 2024-07-09
Sinema Remote Connect Client HIGH 7.8
CVE-2024-39568

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnera…

Fix: 3.2+
Fix from $1,950 2024-07-09
Sinema Remote Connect Client HIGH 7.2
CVE-2024-39569

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnera…

Fix: 3.2+
Fix from $1,950 2024-07-09
Sinema Remote Connect Server HIGH 8.8
CVE-2024-39570

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command inject…

Fix: 3.2+
Fix from $1,950 2024-07-09
Sinema Remote Connect Server HIGH 8.8
CVE-2024-39571

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command inject…

Fix: 3.2+
Fix from $1,950 2024-07-09
Mobile Vpn With Ssl HIGH 7.8
CVE-2024-4944

A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands …

Fix: 12.10.4+
Fix from $1,950 2024-07-09
Khoj HIGH 7.5
CVE-2024-25639

Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize the AI model's response and …

Fix: 1.13.0+
Fix from $1,950 2024-07-08
Seacms CRITICAL 9.8
CVE-2024-39028

An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.

Fix: after 12.9
Fix from $2,300 2024-07-05
Splunk HIGH 8.8
CVE-2024-36983

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated…

Fix: 9.0.10 / 9.1.5+
Fix from $1,950 2024-07-01
Unclassified HIGH 7.2
CVE-2024-36073

Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadowing compo…

Mitigation only
Fix from $1,950 2024-06-27
Unclassified HIGH 8.4
CVE-2024-4578

This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as…

Mitigation only
Fix from $1,950 2024-06-27
Markoni D \(compact\) Firmware HIGH 7.2
CVE-2024-39373

TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker t…

Fix: 2.0.1+
Fix from $1,950 2024-06-27
Whatsup Gold CRITICAL 9.8
CVE-2024-4883EPSS 65%

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauth…

Fix: 23.1.3+
Fix from $2,300 2024-06-25
Whatsup Gold CRITICAL 9.8
CVE-2024-4884EPSS 24%

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.…

Fix: 23.1.3+
Fix from $2,300 2024-06-25
Go Getter HIGH 8.8
CVE-2024-6257

HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to …

Fix: 1.7.5+
Fix from $1,950 2024-06-25
Oncell G3470a Lte Us T Firmware HIGH 8.8
CVE-2024-4639

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configura…

Fix: after 1.7.7
Fix from $1,950 2024-06-25
Oncell G3470a Lte Eu T Firmware HIGH 8.8
CVE-2024-4638

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upl…

Fix: after 1.7.7
Fix from $1,950 2024-06-25
Wn551k1 Firmware MEDIUM 5.3
CVE-2024-38894

WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.

No fix yet
Fix from $1,600 2024-06-24
Wn551k1 Firmware MEDIUM 5.3
CVE-2024-38896

WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.

No fix yet
Fix from $1,600 2024-06-24
Consulting Elementor Widgets HIGH 8.8
CVE-2024-37091

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, Sty…

Fix: 1.3.1+
Fix from $1,950 2024-06-24
Bludit HIGH 8.8
CVE-2024-24551

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulner…

Fix: after 3.15.0
Fix from $1,950 2024-06-24