Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Tew 411brpplus Firmware HIGH 8.1
CVE-2023-51833

A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the …

No fix yet
Fix from $1,950 2024-01-25
Nvr 504 Firmware CRITICAL 9.8
CVE-2023-7227

SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DD…

Mitigation only
Fix from $2,300 2024-01-25
X2000r Firmware CRITICAL 9.8
CVE-2024-22529

TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.

No fix yet
Fix from $2,300 2024-01-25
Mw5360 Firmware CRITICAL 9.8
CVE-2024-22729EPSS 71%

NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.

No fix yet
Fix from $2,300 2024-01-25
X6000r Firmware CRITICAL 9.8
CVE-2023-52038

An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.

No fix yet
Fix from $2,300 2024-01-24
X6000r Firmware CRITICAL 9.8
CVE-2023-52039

An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.

No fix yet
Fix from $2,300 2024-01-24
X6000r Firmware CRITICAL 9.8
CVE-2023-52040

An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.

No fix yet
Fix from $2,300 2024-01-24
Mathtex CRITICAL 9.8
CVE-2023-51887

Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.

Fix: after 1.05
Fix from $2,300 2024-01-24
Dir 815 Firmware CRITICAL 9.8
CVE-2024-22651EPSS 20%

There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.

Fix: after 1.04
Fix from $2,300 2024-01-24
Oneview HIGH 7.8
CVE-2023-50274

HPE OneView may allow command injection with local privilege escalation.

Fix: 8.70+
Fix from $1,950 2024-01-23
A3700r Firmware CRITICAL 9.8
CVE-2024-22663

TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg

No fix yet
Fix from $2,300 2024-01-23
Eagle 1200ac Firmware HIGH 7.8
CVE-2023-24135

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the function formWriteFacMac. This …

No fix yet
Fix from $1,950 2024-01-22
Wap371 Firmware HIGH 7.2
CVE-2024-20287

A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point Setup could al…

Mitigation only
Fix from $1,950 2024-01-17
X6000r Firmware CRITICAL 9.8
CVE-2023-52042

An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parame…

No fix yet
Fix from $2,300 2024-01-16
Enterprise Server HIGH 8.8
CVE-2024-0507EPSS 66%

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability…

Fix: 3.8.13 / 3.9.8+
Fix from $1,950 2024-01-16
X2000r Firmware CRITICAL 9.8
CVE-2024-0579

A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDe…

Mitigation only
Fix from $2,300 2024-01-16
Newsletters HIGH 7.2
CVE-2023-4797

The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell com…

Fix: 4.9.3+
Fix from $1,950 2024-01-16
Paydroid HIGH 7.8
CVE-2023-42136

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system …

Fix: after 8.1.0_sagittarius_11.1.50_20230614
Fix from $1,950 2024-01-15
Connect Secure CRITICAL 9.1
CVE-2024-21887 KEVEPSS 100%

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticate…

Mitigation only
Fix from $2,300 2024-01-12
Nginx Ui HIGH 8.8
CVE-2024-22198

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. Th…

Fix: 2.0.0+
Fix from $1,950 2024-01-11
Nginx Ui HIGH 8.8
CVE-2024-22197

Nginx-ui is online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Prefere…

Fix: 2.0.0+
Fix from $1,950 2024-01-11
Learnpress CRITICAL 9.8
CVE-2023-6634EPSS 9%

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. Th…

Fix: after 4.2.5.7
Fix from $2,300 2024-01-11
A3700r Firmware CRITICAL 9.8
CVE-2023-52027

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.

No fix yet
Fix from $2,300 2024-01-11
Flir Ax8 Firmware CRITICAL 9.8
CVE-2023-51126EPSS 31%

Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOT…

Fix: after 1.46.16
Fix from $2,300 2024-01-10
Ax1803 Firmware CRITICAL 9.8
CVE-2023-51972

Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.

No fix yet
Fix from $2,300 2024-01-10
Xc1000 Firmware CRITICAL 9.8
CVE-2023-31446EPSS 61%

In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads…

No fix yet
Fix from $2,300 2024-01-10
Azure Storage Mover HIGH 8.0
CVE-2024-20676

Azure Storage Mover Remote Code Execution Vulnerability

Fix: 3.0.430+
Fix from $1,950 2024-01-09
Tv Ip1314pi Firmware CRITICAL 9.8
CVE-2023-49237EPSS 19%

An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to u…

No fix yet
Fix from $2,300 2024-01-09
Discord Recon HIGH 8.8
CVE-2024-21663

Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is…

Fix: 0.0.8+
Fix from $1,950 2024-01-09
Lr1200gb Firmware HIGH 8.8
CVE-2024-0291

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function UploadFirmwareFi…

No fix yet
Fix from $1,950 2024-01-08