Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Spring Boot Admin HIGH 7.5
CVE-2023-38286

Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via cra…

Fix: after 3.1.1
Fix from $1,950 2023-07-14
Wrc 1167ghbk3 A Firmware HIGH 8.0
CVE-2023-37566

Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a network-adjacent authenticated attacker to execute an arbitrary c…

Fix: after 1.24
Fix from $1,950 2023-07-13
Wrc 1167ghbk3 A Firmware CRITICAL 9.8
CVE-2023-37567

Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary command b…

Fix: after 1.24
Fix from $2,300 2023-07-13
Wrc 1167ghbk S Firmware HIGH 8.0
CVE-2023-37568

ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, and WRC-1167GEBK-S v1.03 and earlier allow a network-adjacent authenticated attacker to…

Fix: after 1.03
Fix from $1,950 2023-07-13
Ruggedcom Rox Mx5000 Firmware HIGH 7.2
CVE-2023-36750

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX …

Fix: 2.16.0+
Fix from $1,950 2023-07-11
Ruggedcom Rox Mx5000 Firmware HIGH 7.2
CVE-2023-36751

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX …

Fix: 2.16.0+
Fix from $1,950 2023-07-11
Ruggedcom Rox Mx5000 Firmware HIGH 7.2
CVE-2023-36752

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX …

Fix: 2.16.0+
Fix from $1,950 2023-07-11
Ruggedcom Rox Mx5000 Firmware HIGH 7.2
CVE-2023-36753

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX …

Fix: 2.16.0+
Fix from $1,950 2023-07-11
Ruggedcom Rox Mx5000 Firmware HIGH 7.2
CVE-2023-36754

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX …

Fix: 2.16.0+
Fix from $1,950 2023-07-11
Ruggedcom Rox Mx5000 Firmware HIGH 7.2
CVE-2023-36755

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX …

Fix: 2.16.0+
Fix from $1,950 2023-07-11
Quantastor HIGH 7.2
CVE-2021-4406

An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab *…

Fix: 6.0.0.355+
Fix from $1,950 2023-07-10
Ac10 Firmware CRITICAL 9.8
CVE-2023-37144

Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.

No fix yet
Fix from $2,300 2023-07-07
Lr350 Firmware CRITICAL 9.8
CVE-2023-37145

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg func…

No fix yet
Fix from $2,300 2023-07-07
Lr350 Firmware CRITICAL 9.8
CVE-2023-37146

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFil…

No fix yet
Fix from $2,300 2023-07-07
Lr350 Firmware CRITICAL 9.8
CVE-2023-37148

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.

No fix yet
Fix from $2,300 2023-07-07
Lr350 Firmware CRITICAL 9.8
CVE-2023-37149

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting …

No fix yet
Fix from $2,300 2023-07-07
Ur32l Firmware HIGH 8.8
CVE-2023-24519

Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-craf…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 8.8
CVE-2023-24520

Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-craf…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 8.8
CVE-2023-24582

Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted ne…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 8.8
CVE-2023-24583

Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted ne…

No fix yet
Fix from $1,950 2023-07-06
Milesightvpn HIGH 8.1
CVE-2023-22371

An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2. A specially-crafted network…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 7.2
CVE-2023-22659

An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted netwo…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 7.2
CVE-2023-23550

An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5. A specially crafted network…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 7.2
CVE-2023-22306

An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5. A specially crafted network …

No fix yet
Fix from $1,950 2023-07-06
1panel HIGH 8.8
CVE-2023-36457

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malic…

Fix: 1.3.6+
Fix from $1,950 2023-07-05
1panel HIGH 8.8
CVE-2023-36458

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malic…

Fix: 1.3.6+
Fix from $1,950 2023-07-05
Arubaos HIGH 7.2
CVE-2023-35972

An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnera…

Fix: 8.6.0.21 / 8.10.0.7+
Fix from $1,950 2023-07-05
Arubaos HIGH 7.2
CVE-2023-35973

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result …

Fix: 8.6.0.21 / 8.10.0.7+
Fix from $1,950 2023-07-05
Arubaos HIGH 7.2
CVE-2023-35974

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result …

Fix: 8.6.0.21 / 8.10.0.7+
Fix from $1,950 2023-07-05
Unifi Network Application CRITICAL 9.1
CVE-2023-28365

A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administra…

Fix: 7.4.156+
Fix from $2,300 2023-07-01