Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Snowflake Connector HIGH 8.8
CVE-2023-34233

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard op…

Fix: 3.0.2+
Fix from $1,950 2023-06-08
Gosnowflake HIGH 8.8
CVE-2023-34231

gosnowflake is th Snowflake Golang driver. Prior to version 1.6.19, a command injection vulnerability exists in the Snowflake Golang driver via singl…

Fix: 1.6.19+
Fix from $1,950 2023-06-08
A7100ru Firmware CRITICAL 9.8
CVE-2023-33556

TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.

No fix yet
Fix from $2,300 2023-06-07
Aria Operations For Networks CRITICAL 9.8
CVE-2023-20887 KEVEPSS 98%

Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks…

Fix: after 6.10.0
Fix from $2,300 2023-06-07
Vrealize Network Insight HIGH 7.5
CVE-2023-20889EPSS 79%

Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Ne…

Fix: after 6.10.0
Fix from $1,950 2023-06-07
Tl Wr940n Firmware HIGH 8.8
CVE-2023-33538 KEVEPSS 42%

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm…

Mitigation only
Fix from $1,950 2023-06-07
Ak3918ev300 Firmware CRITICAL 9.8
CVE-2023-30400

An issue was discovered in Anyka Microelectronics AK3918EV300 MCU v18. A command injection vulnerability in the network configuration script within t…

No fix yet
Fix from $2,300 2023-06-07
Dir 842v2 Firmware HIGH 8.8
CVE-2023-33782EPSS 37%

D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.

Mitigation only
Fix from $1,950 2023-06-07
Xtrabackup HIGH 7.8
CVE-2022-25834

In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected command sh…

Fix: after 8.0.27-19
Fix from $1,950 2023-06-07
Grafana CRITICAL 9.8
CVE-2023-34111

The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerability which allows for arbitrary…

Fix: after 2023-05-22
Fix from $2,300 2023-06-06
X5000r Firmware CRITICAL 9.8
CVE-2023-31569

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.

Mitigation only
Fix from $2,300 2023-06-06
R6250 Firmware CRITICAL 9.8
CVE-2023-33532EPSS 16%

There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges…

Mitigation only
Fix from $2,300 2023-06-06
D6220 Firmware HIGH 8.8
CVE-2023-33533

Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Ver…

No fix yet
Fix from $1,950 2023-06-06
G103 Firmware HIGH 8.8
CVE-2023-33530

There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web managemen…

Mitigation only
Fix from $1,950 2023-06-06
Aspect Ent 2 Firmware CRITICAL 9.8
CVE-2023-0636

Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S302…

Fix: 3.07.01+
Fix from $2,300 2023-06-05
Advanced Secure Gateway CRITICAL 9.8
CVE-2023-23952

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.

Fix: 3.1.6.0 / 7.3.13.1+
Fix from $2,300 2023-06-01
Br 6288acl Firmware HIGH 8.8
CVE-2023-33722

EDIMAX BR-6288ACL v1.12 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the pppUserName parameter.

No fix yet
Fix from $1,950 2023-05-31
X5000r Firmware CRITICAL 9.8
CVE-2023-33486

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allow…

No fix yet
Fix from $2,300 2023-05-31
X5000r Firmware CRITICAL 9.8
CVE-2023-33487

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability al…

No fix yet
Fix from $2,300 2023-05-31
Fedora HIGH 7.8
CVE-2023-34153

A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format opt…

Fix: 7.1.1-11+
Fix from $1,950 2023-05-30
Action Launcher MEDIUM 5.5
CVE-2022-47028

An issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of service via arbitary data injection to function inse…

No fix yet
Fix from $1,600 2023-05-30
Onewireless Network Wireless Device Manager Firmware MEDIUM 6.8
CVE-2022-46361

An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system com…

Mitigation only
Fix from $1,600 2023-05-30
Cpp Httplib HIGH 8.8
CVE-2023-26130

Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type …

Fix: 0.12.4+
Fix from $1,950 2023-05-30
Device Manager Express HIGH 7.2
CVE-2022-24630EPSS 24%

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_comm…

Fix: after 7.8.20002.47752
Fix from $1,950 2023-05-29
Webcit MEDIUM 5.9
CVE-2020-29547

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP …

Fix: after 926
Fix from $1,600 2023-05-29
Ruby Saml CRITICAL 9.8
CVE-2015-20108

xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.

Fix: 1.0.0+
Fix from $2,300 2023-05-27
N158 HIGH 7.8
CVE-2023-26127

All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function. **Note:** …

Mitigation only
Fix from $1,950 2023-05-27
Keep Module Latest HIGH 7.8
CVE-2023-26128

All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes be…

No fix yet
Fix from $1,950 2023-05-27
Bwm Ng HIGH 7.8
CVE-2023-26129

All versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check' function in the bwm-ng.js fi…

No fix yet
Fix from $1,950 2023-05-27
Mivoice Connect HIGH 7.2
CVE-2023-31460

A vulnerability in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier could allow an authenticated attacker w…

Fix: after 9.6.2208.101
Fix from $1,950 2023-05-24