Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Enterprise Server CRITICAL 9.1
CVE-2024-1355

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server CRITICAL 9.1
CVE-2024-1359

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Azure Devops Server HIGH 7.5
CVE-2024-20667

Azure DevOps Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-02-13
Qts HIGH 8.3
CVE-2023-47218EPSS 90%

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Fix: 5.1.5.2645+
Fix from $1,950 2024-02-13
Kitty HIGH 7.8
CVE-2024-23749

KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and v…

Fix: after 0.76.1.13
Fix from $1,950 2024-02-09
Gc370xa Firmware CRITICAL 9.8
CVE-2023-49716

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote co…

Mitigation only
Fix from $2,300 2024-02-09
Gc370xa Firmware CRITICAL 9.8
CVE-2023-46687

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root co…

Mitigation only
Fix from $2,300 2024-02-09
Openscape Voice Trace Manager HIGH 8.8
CVE-2023-40263

An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp.

Mitigation only
Fix from $1,950 2024-02-08
Dir 816 Firmware CRITICAL 9.8
CVE-2024-24321

An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 fun…

Mitigation only
Fix from $2,300 2024-02-08
Zentao CRITICAL 9.8
CVE-2024-24216

Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/rep…

Fix: after 18.10
Fix from $2,300 2024-02-08
Symphony CRITICAL 9.8
CVE-2024-23049

An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.

Fix: after 3.6.3
Fix from $2,300 2024-02-05
Gtb Central Console HIGH 7.2
CVE-2024-22107

An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React…

No fix yet
Fix from $1,950 2024-02-02
Photo Station HIGH 8.8
CVE-2023-47562

An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to e…

Fix: 6.4.2+
Fix from $1,950 2024-02-02
Qts HIGH 7.2
CVE-2023-41281

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $1,950 2024-02-02
Qts HIGH 7.2
CVE-2023-41282

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $1,950 2024-02-02
Qts HIGH 7.2
CVE-2023-41283

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $1,950 2024-02-02
Qts CRITICAL 9.8
CVE-2023-45025

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $2,300 2024-02-02
Vinchin Backup And Recovery HIGH 8.8
CVE-2024-22900

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo functi…

Fix: after 7.2
Fix from $1,950 2024-02-02
Vinchin Backup And Recovery HIGH 8.8
CVE-2024-22903

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.

Fix: after 7.2
Fix from $1,950 2024-02-02
Helix Sync HIGH 7.8
CVE-2024-0325

In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.  

Fix: 2024.1+
Fix from $1,950 2024-02-01
Web Clipper CRITICAL 9.8
CVE-2024-23745

In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary commands. Addit…

No fix yet
Fix from $2,300 2024-01-31
Network CRITICAL 9.8
CVE-2024-21488

Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without inpu…

Fix: 0.7.0+
Fix from $2,300 2024-01-30
Tew 815dap Firmware HIGH 7.2
CVE-2024-0919EPSS 23%

A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical. This affects the function do_setNTP of the component PO…

No fix yet
Fix from $1,950 2024-01-26
Tew 822dre Firmware HIGH 7.2
CVE-2024-0920EPSS 9%

A vulnerability was found in TRENDnet TEW-822DRE 1.03B02. It has been declared as critical. This vulnerability affects unknown code of the file /admi…

No fix yet
Fix from $1,950 2024-01-26
Tew 824dru Firmware HIGH 7.8
CVE-2024-22545

An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntp.server …

No fix yet
Fix from $1,950 2024-01-26
Mr2600 Firmware HIGH 8.8
CVE-2024-23627

A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vuln…

Mitigation only
Fix from $1,950 2024-01-26
Mr2600 Firmware HIGH 8.8
CVE-2024-23628

A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vu…

Mitigation only
Fix from $1,950 2024-01-26
Dap 1650 Firmware CRITICAL 9.8
CVE-2024-23624EPSS 26%

A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerabilit…

Mitigation only
Fix from $2,300 2024-01-26
Dap 1650 Firmware CRITICAL 9.8
CVE-2024-23625EPSS 23%

A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit th…

Mitigation only
Fix from $2,300 2024-01-26
Mr2600 Firmware HIGH 8.8
CVE-2024-23626

A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerabili…

Mitigation only
Fix from $1,950 2024-01-26