Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Bludit HIGH 8.1
CVE-2024-24550

A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File…

Fix: after 3.15.0
Fix from $1,950 2024-06-24
Rg Uac Firmware HIGH 7.2
CVE-2024-6269EPSS 21%

A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects the function get_ip.addr_details of the fi…

No fix yet
Fix from $1,950 2024-06-23
Unclassified CRITICAL 9.8
CVE-2014-5470EPSS 10%

Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed t…

No fix yet
Fix from $2,300 2024-06-21
Tew 814dap Firmware CRITICAL 9.1
CVE-2024-37642EPSS 11%

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemC…

No fix yet
Fix from $2,300 2024-06-14
Unclassified HIGH 8.8
CVE-2024-35241

Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with …

Patch available
Fix from $1,950 2024-06-10
Unclassified HIGH 8.8
CVE-2024-35242

Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/h…

Patch available
Fix from $1,950 2024-06-10
6869i Sip Firmware HIGH 8.8
CVE-2024-37569

An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in the hostname …

Fix: after 5.0.0.1018
Fix from $1,950 2024-06-09
6869i Sip Firmware HIGH 8.8
CVE-2024-37570

On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (se…

No fix yet
Fix from $1,950 2024-06-09
Webmail CRITICAL 9.8
CVE-2024-37385

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue …

Fix: 1.5.7 / 1.6.7+
Fix from $2,300 2024-06-07
Advanced Core Operating System HIGH 8.8
CVE-2024-30368

A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2024-06-06
O3 Firmware CRITICAL 9.8
CVE-2024-36604

Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows …

No fix yet
Fix from $2,300 2024-06-04
Dextaz Ping HIGH 7.2
CVE-2024-34792

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in dexta Dextaz Ping allows Command Injection.This …

Fix: after 0.65
Fix from $1,950 2024-06-04
Lr350 Firmware CRITICAL 9.8
CVE-2024-36783

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.

Mitigation only
Fix from $2,300 2024-06-03
Datacube3 Firmware MEDIUM 6.3
CVE-2024-34852

F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transceiver_sc…

No fix yet
Fix from $1,600 2024-05-28
Cp900l Firmware MEDIUM 5.9
CVE-2024-35401

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFi…

Mitigation only
Fix from $1,600 2024-05-28
Cp900l Firmware HIGH 8.8
CVE-2024-35397EPSS 15%

TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime …

Mitigation only
Fix from $1,950 2024-05-28
Unclassified HIGH 8.8
CVE-2024-5035

The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and…

Mitigation only
Fix from $1,950 2024-05-27
Aj Report CRITICAL 9.8
CVE-2024-5355

A vulnerability, which was classified as critical, has been found in anji-plus AJ-Report up to 1.4.1. This issue affects the function IGroovyHandler.…

Fix: after 1.4.1
Fix from $2,300 2024-05-26
Mocodo Online CRITICAL 9.8
CVE-2024-35374

Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute a…

Fix: after 4.2.6
Fix from $2,300 2024-05-24
Fh1206 Firmware HIGH 8.6
CVE-2024-35340

Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip/goform/formexeCommand.

No fix yet
Fix from $1,950 2024-05-24
Lollms Webui CRITICAL 9.8
CVE-2024-4267

A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnera…

No fix yet
Fix from $2,300 2024-05-22
Vap2500 Firmware HIGH 7.2
CVE-2024-5196

A vulnerability classified as critical has been found in Arris VAP2500 08.50. This affects an unknown part of the file /tools_command.php. The manipu…

Mitigation only
Fix from $1,950 2024-05-22
Vap2500 Firmware HIGH 7.2
CVE-2024-5195

A vulnerability was found in Arris VAP2500 08.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file /di…

Mitigation only
Fix from $1,950 2024-05-22
Vap2500 Firmware HIGH 7.2
CVE-2024-5194

A vulnerability was found in Arris VAP2500 08.50. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the…

Mitigation only
Fix from $1,950 2024-05-22
Unclassified CRITICAL 9.3
CVE-2024-5023

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe allows Command Injection.This …

Mitigation only
Fix from $2,300 2024-05-16
Unclassified HIGH 7.8
CVE-2024-1417

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS a…

Mitigation only
Fix from $1,950 2024-05-16
Confd Basic HIGH 7.8
CVE-2024-20326

A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attac…

Fix: 5.4 / 5.5+
Fix from $1,950 2024-05-16
Unclassified CRITICAL 9.4
CVE-2024-4999EPSS 12%

A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary …

Mitigation only
Fix from $2,300 2024-05-16
Unclassified CRITICAL 9.8
CVE-2024-4078

A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code execution due to insufficient sa…

Patch available
Fix from $2,300 2024-05-16
Lollms Web Ui CRITICAL 9.0
CVE-2024-2366

A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lol…

Fix: 9.5+
Fix from $2,300 2024-05-16