Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Qts CRITICAL 10.0
CVE-2024-32766

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Fix: 4.5.4.2627 / 5.1.3.2578+
Fix from $2,300 2024-04-26
Target Management CRITICAL 9.8
CVE-2024-0740

Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vulnerability that does not requi…

Fix: after 4.5.400
Fix from $2,300 2024-04-26
Unclassified HIGH 7.2
CVE-2024-3154

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary …

Patch available
Fix from $1,950 2024-04-26
Unclassified HIGH 7.5
CVE-2022-35503

Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module con…

Mitigation only
Fix from $1,950 2024-04-22
Avalanche CRITICAL 9.8
CVE-2024-22061

A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arb…

Fix: 6.4.3.528+
Fix from $2,300 2024-04-19
W30e Firmware HIGH 8.8
CVE-2024-32292

Tenda W30E v1.0 V1.0.1.25(633) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.

No fix yet
Fix from $1,950 2024-04-17
Fh1202 Firmware MEDIUM 6.3
CVE-2024-32282

Tenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.

Mitigation only
Fix from $1,600 2024-04-17
Fh1203 Firmware HIGH 7.3
CVE-2024-32283

Tenda FH1203 V2.0.1.6 firmware has a command injection vulnerablility in formexeCommand function via the cmdinput parameter.

No fix yet
Fix from $1,950 2024-04-17
Ac7 Firmware HIGH 8.8
CVE-2024-32281

Tenda AC7V1.0 v15.03.06.44 firmware contains a command injection vulnerablility in formexeCommand function via the cmdinput parameter.

No fix yet
Fix from $1,950 2024-04-17
Smart Reader Firmware CRITICAL 9.8
CVE-2023-40146

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command lin…

No fix yet
Fix from $2,300 2024-04-17
Ac500 Firmware CRITICAL 9.8
CVE-2024-3908EPSS 9%

A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is the function formWriteFacMac of the file /goform/Writ…

No fix yet
Fix from $2,300 2024-04-17
Outside In Technology MEDIUM 5.3
CVE-2024-21117

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affe…

Mitigation only
Fix from $1,600 2024-04-16
Kohya Ss CRITICAL 9.1
CVE-2024-32025

Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `group_images_gui.py`. This vulnerability i…

Fix: 24.0.1+
Fix from $2,300 2024-04-16
Kohya Ss CRITICAL 9.8
CVE-2024-32026

Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_gui.py`. This vulnerability is…

Fix: 24.0.1+
Fix from $2,300 2024-04-16
Kohya Ss CRITICAL 9.8
CVE-2024-32027

Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetune_gui.py` This vulnerability …

Fix: 24.0.1+
Fix from $2,300 2024-04-16
Kohya Ss CRITICAL 9.8
CVE-2024-32022

Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_gui.py. This vulnerability is …

Fix: 23.1.15+
Fix from $2,300 2024-04-16
Unclassified CRITICAL 9.8
CVE-2024-3871

The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affec…

Mitigation only
Fix from $2,300 2024-04-16
Llamaindex CRITICAL 9.8
CVE-2024-3271

A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval function. Attackers can bypass th…

Fix: 0.10.26+
Fix from $2,300 2024-04-16
Ds D5b86rb\/b Firmware HIGH 7.8
CVE-2023-33806

Insecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to execute arbitrary commands.

Mitigation only
Fix from $1,950 2024-04-15
Mzk Mf300n Firmware HIGH 8.8
CVE-2024-30220

Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute an arbitr…

Fix: after 1.18
Fix from $1,950 2024-04-15
Pan Os CRITICAL 10.0
CVE-2024-3400 KEVEPSS 100%

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for speci…

Mitigation only
Fix from $2,300 2024-04-12
Tlr 2005ksh Firmware HIGH 8.8
CVE-2024-29269EPSS 6%

An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.

No fix yet
Fix from $1,950 2024-04-10
Node.js CRITICAL 9.8
CVE-2024-3566EPSS 7%

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess fu…

Fix: 1.6.19.0 / 1.77.2+
Fix from $2,300 2024-04-10
Pods HIGH 8.8
CVE-2023-6999

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and incl…

Fix: 2.7.31.2 / 2.8.23.2+
Fix from $1,950 2024-04-09
Defender For Iot HIGH 7.2
CVE-2024-21322

Microsoft Defender for IoT Remote Code Execution Vulnerability

Fix: 24.1.3+
Fix from $1,950 2024-04-09
Eap225 Firmware CRITICAL 9.8
CVE-2023-49133

A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 …

No fix yet
Fix from $2,300 2024-04-09
Eap225 Firmware CRITICAL 9.8
CVE-2023-49134

A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 …

No fix yet
Fix from $2,300 2024-04-09
Ex200 Firmware HIGH 8.0
CVE-2024-31811

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLang…

No fix yet
Fix from $1,950 2024-04-08
Ac18 Firmware HIGH 8.8
CVE-2024-30891

A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters fo…

No fix yet
Fix from $1,950 2024-04-05
Unclassified CRITICAL 9.8
CVE-2024-27981

A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) al…

Mitigation only
Fix from $2,300 2024-04-04