Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Imanager CRITICAL 9.8
CVE-2024-3483

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserializat…

Fix: after 3.2.6
Fix from $2,300 2024-05-15
Cam Firmware HIGH 8.8
CVE-2023-6321

A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root…

Fix: 4.2.10 / 4.2.11+
Fix from $1,950 2024-05-15
X5000r Firmware CRITICAL 9.8
CVE-2024-32353

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer funct…

No fix yet
Fix from $2,300 2024-05-14
X5000r Firmware MEDIUM 6.0
CVE-2024-32354

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer fu…

No fix yet
Fix from $1,600 2024-05-14
X5000r Firmware HIGH 8.0
CVE-2024-32355

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer f…

No fix yet
Fix from $1,950 2024-05-14
X5000r Firmware MEDIUM 6.0
CVE-2024-32349

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" paramet…

No fix yet
Fix from $1,600 2024-05-14
Unclassified HIGH 7.2
CVE-2024-31485

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.30), SICORE Base system (All versions < V1.3.0). Th…

Mitigation only
Fix from $1,950 2024-05-14
Charx Sec 3000 Firmware HIGH 7.8
CVE-2024-28136

A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCP…

Fix: after 1.5.1
Fix from $1,950 2024-05-14
Charx Sec 3000 Firmware MEDIUM 5.0
CVE-2024-28135

A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due t…

Fix: after 1.5.1
Fix from $1,600 2024-05-14
Papercut Mf HIGH 7.8
CVE-2024-4712

An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists…

Fix: 23.0.9+
Fix from $1,950 2024-05-14
1panel HIGH 7.5
CVE-2024-34352

1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the pro…

Fix: 1.10.3-lts+
Fix from $1,950 2024-05-14
O3 Firmware HIGH 7.2
CVE-2024-34338

Tenda O3V2 with firmware versions V1.0.0.10 and V1.0.0.12 was discovered to contain a Blind Command Injection via dest parameter in /goform/getTracer…

No fix yet
Fix from $1,950 2024-05-14
Cp450 Firmware MEDIUM 6.5
CVE-2024-34206

TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the w…

No fix yet
Fix from $1,600 2024-05-14
Cp450 Firmware CRITICAL 9.8
CVE-2024-34204

TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the Fi…

No fix yet
Fix from $2,300 2024-05-14
Unclassified CRITICAL 10.0
CVE-2024-29895EPSS 94%

Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthe…

Patch available
Fix from $2,300 2024-05-14
Ipados HIGH 7.8
CVE-2024-27818

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14…

Fix: 14.5 / 16.7.8+
Fix from $1,950 2024-05-14
Unclassified HIGH 8.3
CVE-2024-34347

@hoppscotch/cli is a CLI to run Hoppscotch Test Scripts in CI environments. Prior to 0.8.0, the @hoppscotch/js-sandbox package provides a Javascript …

Patch available
Fix from $1,950 2024-05-08
Dir 845l Firmware HIGH 7.5
CVE-2024-33112EPSS 6%

D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.

Fix: after 1.01krb03
Fix from $1,950 2024-05-06
Dir 845l Firmware MEDIUM 5.3
CVE-2024-33113

D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.

Fix: after 1.01krb03
Fix from $1,600 2024-05-06
E5600 Firmware HIGH 8.0
CVE-2024-33788

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.

No fix yet
Fix from $1,950 2024-05-06
E5600 Firmware CRITICAL 9.8
CVE-2024-33789

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.

No fix yet
Fix from $2,300 2024-05-03
Axiom HIGH 8.0
CVE-2023-42128

Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitra…

Mitigation only
Fix from $1,950 2024-05-03
Tl Wr841n Firmware HIGH 8.8
CVE-2023-39471

TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbi…

Fix: 231119 / 231121+
Fix from $1,950 2024-05-03
Sr400ac Firmware HIGH 8.8
CVE-2023-38120

Adtran SR400ac ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af…

Mitigation only
Fix from $1,950 2024-05-03
Tew 815dap Firmware MEDIUM 6.4
CVE-2024-22546

TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges ca…

No fix yet
Fix from $1,600 2024-04-30
Unclassified MEDIUM 6.3
CVE-2023-1000

A vulnerability was found in cyanomiko dcnnt-py up to 0.9.0. It has been classified as critical. Affected is the function main of the file dcnnt/plug…

Patch available
Fix from $1,600 2024-04-27
Unclassified MEDIUM 6.4
CVE-2024-32884

gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program wou…

Mitigation only
Fix from $1,600 2024-04-26
Dir 822\+ Firmware HIGH 7.5
CVE-2024-33342

D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows remote attackers to execute ar…

No fix yet
Fix from $1,950 2024-04-26
Dir 822\+ Firmware CRITICAL 9.8
CVE-2024-33344EPSS 20%

D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute ar…

No fix yet
Fix from $2,300 2024-04-26
Unclassified MEDIUM 5.4
CVE-2024-28328

CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name paramet…

Mitigation only
Fix from $1,600 2024-04-26