Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Email Security Gateway 300 Firmware CRITICAL 9.8
CVE-2023-2868 KEVEPSS 87%

A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3…

Fix: after 9.2.0.006
Fix from $2,300 2023-05-24
E2000 Firmware HIGH 7.2
CVE-2023-31740

There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, …

No fix yet
Fix from $1,950 2023-05-23
E2000 Firmware HIGH 7.2
CVE-2023-31741

There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, …

No fix yet
Fix from $1,950 2023-05-23
Ane L6012r Firmware HIGH 8.8
CVE-2023-31996

Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Command Injection due to improper sanitization of special characters for the NAS storage test fu…

Fix: 1.41.03+
Fix from $1,950 2023-05-23
Wrt54gl Firmware HIGH 7.2
CVE-2023-31742EPSS 9%

There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privi…

No fix yet
Fix from $1,950 2023-05-22
Kaios CRITICAL 9.8
CVE-2023-33294

An issue was discovered in KaiOS 3.0 before 3.1. The /system/bin/tctweb_server binary exposes a local web server that responds to GET and POST reques…

No fix yet
Fix from $2,300 2023-05-22
Mxsecurity HIGH 8.8
CVE-2023-33235

MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH CLI program, which can be ex…

Patch available
Fix from $1,950 2023-05-22
Luatex HIGH 7.8
CVE-2023-32700

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because lu…

Fix: 1.16.2 / 23.5+
Fix from $1,950 2023-05-20
A3300r Firmware CRITICAL 9.8
CVE-2023-31729

TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.

Mitigation only
Fix from $2,300 2023-05-18
Enterprise Linux HIGH 7.8
CVE-2023-2491

A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el ca…

Mitigation only
Fix from $1,950 2023-05-17
Tl Wpa4530 Kit Firmware HIGH 8.8
CVE-2023-31700

TP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceAdd.

No fix yet
Fix from $1,950 2023-05-17
Tl Wpa4530 Kit Firmware HIGH 8.8
CVE-2023-31701

TP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceRemove.

No fix yet
Fix from $1,950 2023-05-17
Checkmk HIGH 8.8
CVE-2023-31208

Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary live…

Fix: 2.0.0+
Fix from $1,950 2023-05-17
Cp300\+ Firmware CRITICAL 9.8
CVE-2023-31856

A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers …

No fix yet
Fix from $2,300 2023-05-16
Br 6428ns Firmware CRITICAL 9.8
CVE-2023-31986EPSS 8%

A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN funct…

No fix yet
Fix from $2,300 2023-05-15
Br 6428ns Firmware CRITICAL 9.8
CVE-2023-31983EPSS 25%

A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function …

No fix yet
Fix from $2,300 2023-05-12
Avideo HIGH 8.8
CVE-2023-32073EPSS 6%

WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.j…

Fix: after 12.4
Fix from $1,950 2023-05-12
Caton Live MEDIUM 6.3
CVE-2023-2682

A vulnerability was found in Caton Live up to 2023-04-26 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/…

Fix: after 2023-04-26
Fix from $1,600 2023-05-12
Br 6428ns Firmware CRITICAL 9.8
CVE-2023-31985EPSS 8%

A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept f…

No fix yet
Fix from $2,300 2023-05-12
Cx2l Firmware HIGH 8.8
CVE-2023-31528

Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the staticroute_list parameter.

No fix yet
Fix from $1,950 2023-05-11
Cx2l Firmware HIGH 8.8
CVE-2023-31529

Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the system_time_timezone parameter.

No fix yet
Fix from $1,950 2023-05-11
Cx2l Firmware HIGH 8.8
CVE-2023-31530

Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter.

No fix yet
Fix from $1,950 2023-05-11
Cx2l Firmware HIGH 8.8
CVE-2023-31531

Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter.

No fix yet
Fix from $1,950 2023-05-11
Go CRITICAL 9.8
CVE-2023-24540

Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character s…

Fix: 1.19.9 / 1.20.4+
Fix from $2,300 2023-05-11
E Office HIGH 8.8
CVE-2023-2647EPSS 7%

A vulnerability was found in Weaver E-Office 9.5 and classified as critical. Affected by this issue is some unknown functionality of the file /webroo…

No fix yet
Fix from $1,950 2023-05-11
Ac23 Firmware HIGH 8.8
CVE-2023-2649EPSS 10%

A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unknown code of the file /bin/at…

No fix yet
Fix from $1,950 2023-05-11
My Cloud Os CRITICAL 9.8
CVE-2022-29842

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the…

Fix: 5.26.119+
Fix from $2,300 2023-05-10
Cp3 Firmware CRITICAL 9.8
CVE-2023-30353

Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.

Mitigation only
Fix from $2,300 2023-05-10
Gl Mv1000w Firmware HIGH 7.5
CVE-2023-31476

An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almo…

Fix: after 3.215
Fix from $1,950 2023-05-09
6gk1411 1ac00 Firmware HIGH 7.2
CVE-2023-28832

A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2…

Patch available
Fix from $1,950 2023-05-09