Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Qumagie HIGH 8.8
CVE-2023-47560

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute…

Mitigation only
Fix from $1,950 2024-01-05
Ax3 Firmware CRITICAL 9.8
CVE-2023-51812

Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.

No fix yet
Fix from $2,300 2024-01-04
Verify Changed Files HIGH 8.8
CVE-2023-52137

The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames,…

Fix: 17.0.0+
Fix from $1,950 2023-12-29
Gl Mt1300 Firmware HIGH 7.8
CVE-2023-50445EPSS 9%

Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N…

No fix yet
Fix from $1,950 2023-12-28
Changed Files CRITICAL 9.8
CVE-2023-51664

tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows fo…

Fix: 41.0.0+
Fix from $2,300 2023-12-27
Balance Two Firmware HIGH 7.2
CVE-2023-49226

An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users w…

Fix: 8.4.0+
Fix from $1,950 2023-12-25
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51014

TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig in…

No fix yet
Fix from $2,300 2023-12-22
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51016

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .…

No fix yet
Fix from $2,300 2023-12-22
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51025

TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCf…

No fix yet
Fix from $2,300 2023-12-22
Arrayos Ag CRITICAL 9.8
CVE-2023-51707

MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffe…

Fix: 9.4.0.505+
Fix from $2,300 2023-12-22
I29 Firmware CRITICAL 9.8
CVE-2023-50989

Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.

Mitigation only
Fix from $2,300 2023-12-20
I29 Firmware CRITICAL 9.8
CVE-2023-50983

Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.

Mitigation only
Fix from $2,300 2023-12-20
Mlflow HIGH 8.8
CVE-2023-6940

with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.

Fix: 2.9.2+
Fix from $1,950 2023-12-19
Cpp13 Firmware HIGH 7.2
CVE-2023-39509

A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands o…

Fix: after 8.90
Fix from $1,950 2023-12-18
Kodbox CRITICAL 9.8
CVE-2023-6848

A vulnerability was found in kalcaddle kodbox up to 1.48. It has been declared as critical. Affected by this vulnerability is the function check of t…

Fix: 1.48.04+
Fix from $2,300 2023-12-16
Wnr2000 Firmware CRITICAL 9.8
CVE-2023-50089

A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs dur…

No fix yet
Fix from $2,300 2023-12-15
Majordomo CRITICAL 9.8
CVE-2023-50917EPSS 38%

MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majo…

Fix: 2023-11-15+
Fix from $2,300 2023-12-15
Streampark HIGH 7.2
CVE-2023-49898

In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of …

Fix: 2.1.2+
Fix from $1,950 2023-12-15
Gradio HIGH 8.1
CVE-2023-6572

Command Injection in GitHub repository gradio-app/gradio prior to main.

Fix: 4.14.0+
Fix from $1,950 2023-12-14
Mc801a Firmware HIGH 8.8
CVE-2023-25643

There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters,…

Mitigation only
Fix from $1,950 2023-12-14
Jellyfin HIGH 7.2
CVE-2023-48702

Jellyfin is a system for managing and streaming media. Prior to version 10.8.13, the `/System/MediaEncoder/Path` endpoint executes an arbitrary file …

Fix: 10.8.13+
Fix from $1,950 2023-12-13
Fortiportal HIGH 8.8
CVE-2023-48791

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7…

Fix: after 7.0.6
Fix from $1,950 2023-12-13
Rely Pcie Firmware HIGH 8.8
CVE-2023-47576

An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web interface.

Mitigation only
Fix from $1,950 2023-12-13
Flash Tool CRITICAL 9.8
CVE-2013-2513

The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.

Fix: after 0.6.0
Fix from $2,300 2023-12-12
Solution Manager MEDIUM 6.4
CVE-2023-49587

SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of sam…

Mitigation only
Fix from $1,600 2023-12-12
Ngeniuspulse CRITICAL 9.8
CVE-2023-40301

NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability.

Mitigation only
Fix from $2,300 2023-12-07
Ax9 Firmware CRITICAL 9.8
CVE-2023-49431

Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.

No fix yet
Fix from $2,300 2023-12-07
Ax9 Firmware CRITICAL 9.8
CVE-2023-49435

Tenda AX9 V22.03.01.46 is vulnerable to command injection.

No fix yet
Fix from $2,300 2023-12-07
Ax9 Firmware CRITICAL 9.8
CVE-2023-49436

Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.

No fix yet
Fix from $2,300 2023-12-07
Ax12 Firmware CRITICAL 9.8
CVE-2023-49428

Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.

No fix yet
Fix from $2,300 2023-12-07