Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
It7 Lcs Firmware CRITICAL 9.8
CVE-2023-23080

Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<…

Fix: after 20220906024_2025
Fix from $2,300 2023-02-27
Asmb8 Ikvm Firmware CRITICAL 9.8
CVE-2023-26602EPSS 17%

ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snm…

Fix: after 1.14.51
Fix from $2,300 2023-02-26
Jetwave 2212g Firmware HIGH 8.8
CVE-2023-23294

Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter t…

Fix: 1.5 / 1.6+
Fix from $1,950 2023-02-23
Jetwave 2212g Firmware HIGH 8.8
CVE-2023-23295

Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the…

Fix: 1.5 / 1.6+
Fix from $1,950 2023-02-23
Rocket.chat HIGH 8.8
CVE-2023-23917

A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can c…

Fix: 5.2.0+
Fix from $1,950 2023-02-23
Wmb250ac Firmware HIGH 8.8
CVE-2022-45600

Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in …

No fix yet
Fix from $1,950 2023-02-22
A7100ru Firmware CRITICAL 9.8
CVE-2023-24184

TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability.

Mitigation only
Fix from $2,300 2023-02-21
Emacs HIGH 7.3
CVE-2022-48338

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. …

Fix: after 28.2
Fix from $1,950 2023-02-20
Versionn CRITICAL 9.8
CVE-2023-25805

versionn, software for changing version information across multiple files, has a command injection vulnerability in all versions prior to version 1.1…

Fix: 1.1.0+
Fix from $2,300 2023-02-20
Amino A140 Firmware CRITICAL 9.8
CVE-2022-40021

QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vulnerability.

Fix: 1.0.0-283+
Fix from $2,300 2023-02-17
Arris Tg2482a Firmware HIGH 8.8
CVE-2022-45701EPSS 42%

Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.

Fix: after 9.1.103
Fix from $1,950 2023-02-17
A7100ru Firmware CRITICAL 9.8
CVE-2023-24238

TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRu…

No fix yet
Fix from $2,300 2023-02-16
A7100ru Firmware CRITICAL 9.8
CVE-2023-24236

TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDh…

No fix yet
Fix from $2,300 2023-02-16
Netmodule Router Software HIGH 8.8
CVE-2023-0861EPSS 29%

NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authe…

Fix: 4.3.0.119 / 4.4.0.118+
Fix from $1,950 2023-02-16
Wndr3700 Firmware CRITICAL 9.8
CVE-2023-0849

A vulnerability has been found in Netgear WNDR3700v2 1.0.1.14 and classified as critical. This vulnerability affects unknown code of the component We…

Mitigation only
Fix from $2,300 2023-02-15
Dynamics 365 HIGH 8.0
CVE-2023-21778

Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability

Fix: 4.2.0.51+
Fix from $1,950 2023-02-14
Windows 10 HIGH 7.8
CVE-2023-21805

Windows MSHTML Platform Remote Code Execution Vulnerability

Fix: 10.0.10240.19747 / 10.0.14393.5717+
Fix from $1,950 2023-02-14
Splunk HIGH 8.8
CVE-2023-22935

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass S…

Fix: 8.1.13 / 8.2.10+
Fix from $1,950 2023-02-14
Easynas HIGH 8.8
CVE-2023-0830EPSS 21%

A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation lead…

No fix yet
Fix from $1,950 2023-02-14
Ca300 Poe Firmware CRITICAL 9.8
CVE-2023-24159

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function.

No fix yet
Fix from $2,300 2023-02-14
Ca300 Poe Firmware CRITICAL 9.8
CVE-2023-24160

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.

No fix yet
Fix from $2,300 2023-02-14
Ca300 Poe Firmware CRITICAL 9.8
CVE-2023-24161

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.

No fix yet
Fix from $2,300 2023-02-14
Syncserver S650 Firmware CRITICAL 9.8
CVE-2022-40022EPSS 92%

Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.

No fix yet
Fix from $2,300 2023-02-13
Phpmyfaq CRITICAL 9.8
CVE-2023-0789

Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

Fix: 3.1.11+
Fix from $2,300 2023-02-12
Dwl 2600ap Firmware HIGH 7.8
CVE-2023-0127

A command injection vulnerability in the firmware_update command, in the device's restricted telnet interface, allows an authenticated attacker to ex…

No fix yet
Fix from $1,950 2023-02-11
Neutrino 430 Firmware CRITICAL 10.0
CVE-2023-0776

Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell co…

Patch available
Fix from $2,300 2023-02-11
Evasa Provider Virtual Appliance HIGH 8.8
CVE-2022-45104

Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low priv…

Fix: 9.2.3.6 / 9.2.4.15+
Fix from $1,950 2023-02-11
Jitsi CRITICAL 9.8
CVE-2022-43550

A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which cou…

Fix: 2022-09-14+
Fix from $2,300 2023-02-09
En7580 Firmware CRITICAL 9.8
CVE-2021-31573

In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a p…

Mitigation only
Fix from $2,300 2023-02-06
En7580 Firmware CRITICAL 9.8
CVE-2021-31574

In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a p…

Mitigation only
Fix from $2,300 2023-02-06