Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Ax12 Firmware CRITICAL 9.8
CVE-2023-49437

Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.

No fix yet
Fix from $2,300 2023-12-07
Ac21000 G6 Firmware MEDIUM 6.8
CVE-2023-24046

An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in the ping ut…

No fix yet
Fix from $1,600 2023-12-04
X6000r Firmware CRITICAL 9.8
CVE-2023-48801

In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the …

No fix yet
Fix from $2,300 2023-12-01
Go Rt Ac750 Firmware CRITICAL 9.8
CVE-2023-48842

D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.

No fix yet
Fix from $2,300 2023-12-01
X6000r Firmware CRITICAL 9.8
CVE-2023-43453

An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter…

No fix yet
Fix from $2,300 2023-12-01
X6000r Firmware CRITICAL 9.8
CVE-2023-43454

An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName par…

No fix yet
Fix from $2,300 2023-12-01
X6000r Firmware CRITICAL 9.8
CVE-2023-43455

An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the command para…

No fix yet
Fix from $2,300 2023-12-01
Enterprise Security Manager HIGH 7.2
CVE-2023-6071

An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execut…

Fix: 11.6.9+
Fix from $1,950 2023-11-30
Ax1803 Firmware CRITICAL 9.8
CVE-2023-49040

An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set…

No fix yet
Fix from $2,300 2023-11-27
Powershell Universal HIGH 8.8
CVE-2023-49213

The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests …

Fix: 3.10.2 / 4.1.10+
Fix from $1,950 2023-11-23
Node Openssl CRITICAL 9.8
CVE-2023-49210

The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, and accepts an…

Fix: after 2.0.0
Fix from $2,300 2023-11-23
Arubaos HIGH 7.2
CVE-2023-45625

Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result…

Fix: 8.6.0.23 / 8.10.0.9+
Fix from $1,950 2023-11-14
Pfsense HIGH 8.8
CVE-2023-42326EPSS 64%

An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and inter…

Fix: after 23.05.1
Fix from $1,950 2023-11-14
Qualitor CRITICAL 9.8
CVE-2023-47253EPSS 14%

Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridVal…

Fix: after 8.20
Fix from $2,300 2023-11-06
Qts CRITICAL 9.8
CVE-2023-23369EPSS 15%

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $2,300 2023-11-03
Identity Services Engine MEDIUM 6.7
CVE-2023-20170

A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlyi…

Mitigation only
Fix from $1,600 2023-11-01
Secure Firewall Management Center HIGH 8.8
CVE-2023-20219

Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote att…

Fix: after 7.3.1.1
Fix from $1,950 2023-11-01
Secure Firewall Management Center HIGH 8.8
CVE-2023-20220

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remo…

Fix: after 7.3.1.1
Fix from $1,950 2023-11-01
X6000r Firmware CRITICAL 9.8
CVE-2023-46484

An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.

No fix yet
Fix from $2,300 2023-10-31
X6000r Firmware CRITICAL 9.8
CVE-2023-46485

An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi…

No fix yet
Fix from $2,300 2023-10-31
A3300r Firmware CRITICAL 9.8
CVE-2023-46993

In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to …

No fix yet
Fix from $2,300 2023-10-31
A3300r Firmware CRITICAL 9.8
CVE-2023-46976

TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.

No fix yet
Fix from $2,300 2023-10-31
X6000r Firmware CRITICAL 9.8
CVE-2023-46979

TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function.

No fix yet
Fix from $2,300 2023-10-31
Tinyfiledialogs CRITICAL 9.8
CVE-2023-47104

tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and oth…

Fix: 3.15.0+
Fix from $2,300 2023-10-30
Nodegrid Os HIGH 8.8
CVE-2023-43322

ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 wa…

Fix: 5.0.18 / 5.2.20+
Fix from $1,950 2023-10-28
Vinchin Backup And Recovery CRITICAL 9.8
CVE-2023-45498EPSS 20%

VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.

Fix: after 7.0
Fix from $2,300 2023-10-27
X6000r Firmware CRITICAL 9.8
CVE-2023-46408

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 41DD80 function.

No fix yet
Fix from $2,300 2023-10-25
X6000r Firmware CRITICAL 9.8
CVE-2023-46409

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ 41CC04 function.

No fix yet
Fix from $2,300 2023-10-25
X6000r Firmware CRITICAL 9.8
CVE-2023-46410

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 416F60 function.

No fix yet
Fix from $2,300 2023-10-25
X6000r Firmware CRITICAL 9.8
CVE-2023-46411

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_415258 function.

No fix yet
Fix from $2,300 2023-10-25