Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
A7100ru Firmware CRITICAL 9.8
CVE-2023-27232

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /setting/setWanIe…

No fix yet
Fix from $2,300 2023-03-28
A7100ru Firmware CRITICAL 9.8
CVE-2023-27229

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at /setting/setWanIeCfg.

No fix yet
Fix from $2,300 2023-03-28
A7100ru Firmware CRITICAL 9.8
CVE-2023-27231

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg.

No fix yet
Fix from $2,300 2023-03-28
Osprey Pump Controller Firmware CRITICAL 9.8
CVE-2023-28712

Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system access with www-data permissi…

Mitigation only
Fix from $2,300 2023-03-28
React Native Onesignal HIGH 8.1
CVE-2023-28430

OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is triggered on issues (types: [clo…

Fix: 4.5.1+
Fix from $1,950 2023-03-27
Cocos Engine HIGH 8.8
CVE-2023-26493

Cocos Engine is an open-source framework for building 2D & 3D real-time rendering and interactive content. In the github repo for Cocos Engine the `w…

Fix: 2023-02-20+
Fix from $1,950 2023-03-27
Infrasuite Device Master HIGH 8.8
CVE-2023-1141

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an attacker to inject a…

Fix: 1.0.5+
Fix from $1,950 2023-03-27
Bl Lte300 Firmware CRITICAL 9.8
CVE-2023-26801EPSS 70%

LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command inje…

No fix yet
Fix from $2,300 2023-03-26
Rg Ew1800gx Pro Firmware HIGH 8.8
CVE-2023-27796

RG-EW1200G PRO Wireless Routers EW_3.0(1)B11P204, RG-EW1800GX PRO Wireless Routers EW_3.0(1)B11P204, and RG-EW3200GX PRO Wireless Routers EW_3.0(1)B1…

No fix yet
Fix from $1,950 2023-03-26
Rg Ew1200r Firmware CRITICAL 9.8
CVE-2023-26800

Ruijie Networks RG-EW1200 Wireless Routers EW_3.0(1)B11P204 was discovered to contain a command injetion vulnerability via the params.path parameter …

No fix yet
Fix from $2,300 2023-03-26
Edgerouter X Firmware CRITICAL 9.8
CVE-2023-1458

A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical. Affected by this vulnerability is an unknown funct…

No fix yet
Fix from $2,300 2023-03-25
Edgerouter X Firmware CRITICAL 9.8
CVE-2023-1456

A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6. This issue affects some unknown processing…

Mitigation only
Fix from $2,300 2023-03-25
Edgerouter X Firmware CRITICAL 9.8
CVE-2023-1457

A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6. Affected is an unknown function of the componen…

Mitigation only
Fix from $2,300 2023-03-25
Dek 1705 Firmware CRITICAL 9.8
CVE-2023-23149

DEK-1705 <=Firmware:34.23.1 device was discovered to have a command execution vulnerability.

Mitigation only
Fix from $2,300 2023-03-24
Wireless Lan Controller Software MEDIUM 6.7
CVE-2023-20097

A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with …

Fix: 8.10.183.0 / 16.12.8+
Fix from $1,600 2023-03-23
Cp900 Firmware CRITICAL 9.8
CVE-2022-28496

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminus…

Mitigation only
Fix from $2,300 2023-03-23
Cp900 Firmware CRITICAL 9.8
CVE-2022-28497

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via th…

Mitigation only
Fix from $2,300 2023-03-23
Tl Mr3020 Firmware CRITICAL 9.8
CVE-2023-27078

A command injection issue was found in TP-Link MR3020 v.1_150921 that allows a remote attacker to execute arbitrary commands via a crafted request to…

No fix yet
Fix from $2,300 2023-03-23
A7100ru Firmware CRITICAL 9.8
CVE-2023-27135

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at /setting/setWanIeCfg.

No fix yet
Fix from $2,300 2023-03-23
G103 Firmware HIGH 7.5
CVE-2023-27079

Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package

No fix yet
Fix from $1,950 2023-03-23
Nginx Proxy Manager CRITICAL 9.8
CVE-2023-27224

An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file.

No fix yet
Fix from $2,300 2023-03-22
Arubaos Cx HIGH 8.8
CVE-2023-1168

An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerabi…

Fix: 10.06.0240 / 10.10.1030+
Fix from $1,950 2023-03-22
Redis MEDIUM 5.5
CVE-2023-28425EPSS 55%

Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX c…

Fix: 7.0.10+
Fix from $1,600 2023-03-20
Irc Twitter Announcer Bot HIGH 8.1
CVE-2015-10096

A vulnerability, which was classified as critical, was found in Zarthus IRC Twitter Announcer Bot up to 1.1.0. This affects the function get_tweets o…

Patch available
Fix from $1,950 2023-03-20
Koko CRITICAL 9.9
CVE-2023-28110

Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP serv…

Fix: 2.28.8+
Fix from $2,300 2023-03-16
Octopus Server HIGH 8.8
CVE-2022-4009

In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation

Fix: 2022.2.8552 / 2022.3.10750+
Fix from $1,950 2023-03-16
Array Os HIGH 7.2
CVE-2023-28460

A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted packet after logging into the a…

Fix: after 10.4.2.58
Fix from $1,950 2023-03-15
Archer Ax21 Firmware HIGH 8.8
CVE-2023-1389 KEVEPSS 100%

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cg…

Fix: 1.1.4+
Fix from $1,950 2023-03-15
Vigor2960 Firmware HIGH 7.8
CVE-2023-24229EPSS 7%

DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands v…

No fix yet
Fix from $1,950 2023-03-15
Ax3 Firmware CRITICAL 9.8
CVE-2023-27240

Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip.

No fix yet
Fix from $2,300 2023-03-15