Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Scalance Lpe9403 Firmware CRITICAL 9.9
CVE-2023-27407

A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate…

Fix: 2.1+
Fix from $2,300 2023-05-09
Arubaos HIGH 8.8
CVE-2023-22788

Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation …

Fix: 8.6.0.0+
Fix from $1,950 2023-05-08
Arubaos HIGH 8.8
CVE-2023-22789

Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation …

Fix: 8.6.0.0+
Fix from $1,950 2023-05-08
Arubaos HIGH 8.8
CVE-2023-22790

Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation …

Fix: 8.6.0.0+
Fix from $1,950 2023-05-08
Eki 1521 Firmware HIGH 8.8
CVE-2023-2573

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which c…

Fix: after 1.21
Fix from $1,950 2023-05-08
Eki 1521 Firmware HIGH 8.8
CVE-2023-2574

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which …

Fix: after 1.21
Fix from $1,950 2023-05-08
Ac18 Firmware CRITICAL 9.8
CVE-2023-30135

Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload functi…

Patch available
Fix from $2,300 2023-05-05
Caton Prime CRITICAL 9.8
CVE-2023-2520

A vulnerability was found in Caton Prime 2.1.2.51.e8d7225049(202303031001) and classified as critical. This issue affects some unknown processing of …

Mitigation only
Fix from $2,300 2023-05-04
Gin HIGH 7.3
CVE-2023-26125

Versions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially …

Fix: 1.9.0+
Fix from $1,950 2023-05-04
Spark HIGH 8.8
CVE-2023-32007EPSS 76%

** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an aut…

Fix: after 3.2.1
Fix from $1,950 2023-05-02
Er X Firmware HIGH 7.2
CVE-2023-2377EPSS 8%

A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The impacted element is an unknown function of the component Web Manageme…

Fix: 2.0.9+
Fix from $1,950 2023-04-28
Er X Firmware HIGH 7.2
CVE-2023-2378EPSS 8%

A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown function of the component Web Management Interface. This…

Fix: 2.0.9+
Fix from $1,950 2023-04-28
Er X Firmware HIGH 7.2
CVE-2023-2376EPSS 8%

A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The affected element is an unknown function of the componen…

Fix: 2.0.9+
Fix from $1,950 2023-04-28
Er X Firmware HIGH 7.2
CVE-2023-2374EPSS 7%

A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This issue affects some unknown processing of the component Web Ma…

Fix: 2.0.9+
Fix from $1,950 2023-04-28
Er X Firmware HIGH 7.2
CVE-2023-2375EPSS 9%

A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. Impacted is an unknown function of the component Web Management Interfa…

Fix: 2.0.9+
Fix from $1,950 2023-04-28
Edgemax Edgerouter Firmware HIGH 7.2
CVE-2023-2373EPSS 8%

A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This vulnerability affects unknown code of the component Web Management…

Fix: 2.0.9+
Fix from $1,950 2023-04-28
Cloud Pak For Data HIGH 7.2
CVE-2022-36769

IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed wit…

Mitigation only
Fix from $1,950 2023-04-26
Wip HIGH 8.8
CVE-2023-30623

`embano1/wip` is a GitHub Action written in Bash. Prior to version 2, the `embano1/wip` action uses the `github.event.pull_request.title` parameter …

Fix: 2.0.0+
Fix from $1,950 2023-04-24
Broccoli Compass CRITICAL 9.8
CVE-2023-27848

broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.

No fix yet
Fix from $2,300 2023-04-24
Rails Routes To Json CRITICAL 9.8
CVE-2023-27849

rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.

No fix yet
Fix from $2,300 2023-04-24
Dawnsparks Node Tesseract CRITICAL 9.8
CVE-2023-29566

huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the ch…

Patch available
Fix from $2,300 2023-04-24
Usg Flex 100 Firmware HIGH 8.1
CVE-2023-22913

A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 throu…

Fix: after 5.35
Fix from $1,950 2023-04-24
Aria Operations For Logs HIGH 7.2
CVE-2023-20865

VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operation…

Fix: 8.12.0+
Fix from $1,950 2023-04-20
Wbce Cms HIGH 7.2
CVE-2023-29855

WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php.

No fix yet
Fix from $1,950 2023-04-18
Nanoleaf Desktop CRITICAL 9.8
CVE-2022-46640

Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.

Fix: 1.3.1+
Fix from $2,300 2023-04-18
Amanda MEDIUM 6.7
CVE-2022-37704

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/…

Patch available
Fix from $1,600 2023-04-16
GitLab MEDIUM 6.5
CVE-2019-14944

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection …

Fix: 11.11.8 / 12.0.6+
Fix from $1,600 2023-04-16
Snowflake Jdbc HIGH 8.8
CVE-2023-30535

Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake …

Fix: 3.13.29+
Fix from $1,950 2023-04-14
X18 Firmware CRITICAL 9.8
CVE-2023-29800

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile…

No fix yet
Fix from $2,300 2023-04-14
X18 Firmware CRITICAL 9.8
CVE-2023-29801

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parame…

No fix yet
Fix from $2,300 2023-04-14