Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Pgadmin 4 CRITICAL 9.8
CVE-2024-3116EPSS 65%

pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers …

Fix: after 8.4
Fix from $2,300 2024-04-04
Dns 320l Firmware CRITICAL 9.8
CVE-2024-3273 KEVEPSS 100%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to…

Mitigation only
Fix from $2,300 2024-04-04
R6850 Firmware HIGH 8.0
CVE-2024-30572

Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.

No fix yet
Fix from $1,950 2024-04-03
Unclassified HIGH 7.4
CVE-2024-22246

VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with …

Mitigation only
Fix from $1,950 2024-04-02
Unclassified HIGH 7.2
CVE-2024-29949

There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbit…

Mitigation only
Fix from $1,950 2024-04-02
Standalone Sentry HIGH 8.8
CVE-2023-41724EPSS 13%

A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlyin…

Fix: 9.19.0+
Fix from $1,950 2024-03-31
F1202 Firmware HIGH 8.8
CVE-2024-30637

Tenda F1202 v1.2.0.20(408) has a command injection vulnerablility in the formWriteFacMac function in the mac parameter.

No fix yet
Fix from $1,950 2024-03-29
Unclassified HIGH 7.3
CVE-2024-2947

A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, re…

Mitigation only
Fix from $1,950 2024-03-28
Powermax Eem HIGH 8.8
CVE-2024-25946

Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnera…

Fix: 9.2.4.6 / 9.2.4.9+
Fix from $1,950 2024-03-28
Powermax Eem HIGH 8.8
CVE-2024-25955

Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnera…

Fix: 9.2.4.6 / 9.2.4.9+
Fix from $1,950 2024-03-28
Fh1205 Firmware HIGH 8.8
CVE-2024-3009EPSS 8%

A vulnerability has been found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected by this vulnerability is the function formWriteFacMa…

No fix yet
Fix from $1,950 2024-03-28
Fh1203 Firmware HIGH 8.8
CVE-2024-2991EPSS 8%

A vulnerability has been found in Tenda FH1203 2.0.1.6 and classified as critical. This vulnerability affects the function formWriteFacMac of the fil…

No fix yet
Fix from $1,950 2024-03-27
Splunk HIGH 8.1
CVE-2024-29946

In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let atta…

Fix: 9.0.9 / 9.1.4+
Fix from $1,950 2024-03-27
Fh1202 Firmware HIGH 8.8
CVE-2024-2982EPSS 8%

A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this vulnerability is the function formWriteFacM…

No fix yet
Fix from $1,950 2024-03-27
Gradio HIGH 8.2
CVE-2024-1540

A command injection vulnerability exists in the deploy+test-visual.yml workflow of the gradio-app/gradio repository, due to improper neutralization o…

Fix: 2024-02-09+
Fix from $1,950 2024-03-27
Ac18 Firmware CRITICAL 9.8
CVE-2024-28545

Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload function.

No fix yet
Fix from $2,300 2024-03-26
Linux Kernel HIGH 7.8
CVE-2023-52624

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before executing GPINT commands [Why] DMCUB can be …

Fix: 6.7.3+
Fix from $1,950 2024-03-26
Unclassified HIGH 8.1
CVE-2024-24897

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in openEuler A-Tune-Collector on Linux allows Comma…

Mitigation only
Fix from $1,950 2024-03-25
Unclassified HIGH 8.8
CVE-2024-28041

HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.

Mitigation only
Fix from $1,950 2024-03-25
Dir 845l Firmware HIGH 8.8
CVE-2024-29366

A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.

Fix: after 1.01krb03
Fix from $1,950 2024-03-22
Dir 845l Firmware CRITICAL 9.0
CVE-2024-29385

DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function.

Fix: after 1.01krb03
Fix from $2,300 2024-03-22
Distrobox CRITICAL 9.8
CVE-2024-29864

Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables.

Fix: 1.7.0.1+
Fix from $2,300 2024-03-21
Rg Nbs2009g P Firmware HIGH 7.3
CVE-2024-2642

A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been declared as critical. Affected by this vulnerability is an unknown func…

Mitigation only
Fix from $1,950 2024-03-19
Astropy HIGH 8.4
CVE-2023-41334

Astropy is a project for astronomy in Python that fosters interoperability between Python astronomy packages. Version 5.3.2 of the Astropy core packa…

Patch available
Fix from $1,950 2024-03-18
Tew 827dru Firmware CRITICAL 10.0
CVE-2024-28354

There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the …

Mitigation only
Fix from $2,300 2024-03-15
Tew 827dru Firmware HIGH 8.8
CVE-2024-28353

There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the …

No fix yet
Fix from $1,950 2024-03-15
Vinchin Backup And Recovery HIGH 8.8
CVE-2024-25228EPSS 26%

Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in Manoeuv…

Fix: after 7.2
Fix from $1,950 2024-03-14
Outlook HIGH 7.5
CVE-2024-26204

Outlook for Android Information Disclosure Vulnerability

Fix: 4.2404.0+
Fix from $1,950 2024-03-12
Charx Sec 3000 Firmware HIGH 7.3
CVE-2024-25998

An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.

Fix: 1.5.1+
Fix from $1,950 2024-03-12
Netweaver Application Server Java CRITICAL 9.1
CVE-2024-22127

SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially …

Mitigation only
Fix from $2,300 2024-03-12