Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
1panel CRITICAL 9.8
CVE-2024-2352

A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDe…

Fix: 1.10.2-lts+
Fix from $2,300 2024-03-10
Idrac8 HIGH 8.0
CVE-2024-25951

A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.

Fix: 2.85.85.85+
Fix from $1,950 2024-03-09
macOS HIGH 7.8
CVE-2024-23247

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Process…

Fix: 12.7.4 / 13.6.5+
Fix from $1,950 2024-03-08
Paddlepaddle HIGH 7.8
CVE-2024-0817

Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0

No fix yet
Fix from $1,950 2024-03-07
Arubaos HIGH 7.2
CVE-2024-25612

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result …

Fix: 8.10.0.10 / 8.11.2.1+
Fix from $1,950 2024-03-05
Arubaos HIGH 7.2
CVE-2024-25613

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result …

Fix: 8.10.0.10 / 8.11.2.1+
Fix from $1,950 2024-03-05
Arubaos HIGH 7.2
CVE-2024-1356

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result …

Fix: after 10.5.0.1
Fix from $1,950 2024-03-05
Arubaos HIGH 7.2
CVE-2024-25611

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result …

Fix: 8.10.0.10 / 8.11.2.1+
Fix from $1,950 2024-03-05
Tew 822dre Firmware MEDIUM 6.8
CVE-2023-51835EPSS 7%

An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping in the /boafrm/formSystemChe…

No fix yet
Fix from $1,600 2024-02-29
Clearpass Policy Manager HIGH 8.8
CVE-2024-26295

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.13 / 6.10.8+
Fix from $1,950 2024-02-27
Clearpass Policy Manager HIGH 8.8
CVE-2024-26296

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.13 / 6.10.8+
Fix from $1,950 2024-02-27
Clearpass Policy Manager HIGH 8.8
CVE-2024-26297

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.13 / 6.10.8+
Fix from $1,950 2024-02-27
Clearpass Policy Manager HIGH 8.8
CVE-2024-26298

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.13 / 6.10.8+
Fix from $1,950 2024-02-27
Clearpass Policy Manager HIGH 8.8
CVE-2024-26294

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.13 / 6.10.8+
Fix from $1,950 2024-02-27
E1700 Firmware HIGH 8.0
CVE-2024-22544EPSS 9%

An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTim…

No fix yet
Fix from $1,950 2024-02-27
Debian Linux MEDIUM 6.5
CVE-2024-25082

Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

Fix: after 20230101
Fix from $1,600 2024-02-26
Profinet Inspektor Nt CRITICAL 9.8
CVE-2023-49959

In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers…

Fix: 2.4.1+
Fix from $2,300 2024-02-26
X6000r Firmware CRITICAL 9.8
CVE-2024-1781EPSS 15%

A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg…

No fix yet
Fix from $2,300 2024-02-23
Wf2780 Firmware CRITICAL 9.8
CVE-2024-25850EPSS 19%

Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter

No fix yet
Fix from $2,300 2024-02-22
Dir 882 Firmware HIGH 8.8
CVE-2023-24330

Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST…

No fix yet
Fix from $1,950 2024-02-21
Dir 816 Firmware CRITICAL 9.8
CVE-2023-24331

Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlA…

No fix yet
Fix from $2,300 2024-02-21
Pymatgen HIGH 7.8
CVE-2024-23346

Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesF…

Fix: 2024.2.20+
Fix from $1,950 2024-02-21
Idocview CRITICAL 9.8
CVE-2024-24377

An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script.

Fix: after 14.1.3_20231228
Fix from $2,300 2024-02-16
Eap 767 Firmware HIGH 8.8
CVE-2024-24301

Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid crede…

No fix yet
Fix from $1,950 2024-02-14
Big Ip Access Policy Manager HIGH 8.7
CVE-2024-22093

When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-blad…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2024-02-14
Enterprise Server CRITICAL 9.1
CVE-2024-1369

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server CRITICAL 9.1
CVE-2024-1372

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server CRITICAL 9.1
CVE-2024-1374

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server CRITICAL 9.1
CVE-2024-1378

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server HIGH 8.0
CVE-2024-1354

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $1,950 2024-02-13