Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.1 CVE-2024-41783 IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlyi… Sterling Secure Proxy 6.0.3.1+ Fix from $2,3002025-01-19 HIGH 7.2 CVE-2025-0528EPSS 6% A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown fun… Ac8 Firmware No fix yet Fix from $1,9502025-01-17 HIGH 8.7 CVE-2024-54660 A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can in… Mitigation only Fix from $1,9502025-01-16 CRITICAL 9.8 CVE-2024-57583 Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function. Ac18 Firmware Mitigation only Fix from $2,3002025-01-16 CRITICAL 9.8 CVE-2025-22912 RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept. Re11s Firmware No fix yet Fix from $2,3002025-01-16 HIGH 7.2 CVE-2025-23052 Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerab… Mitigation only Fix from $1,9502025-01-14 HIGH 7.2 CVE-2024-39782 Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially craft… Wl Wn533a8 Firmware No fix yet Fix from $1,9502025-01-14 HIGH 7.2 CVE-2024-39783 Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially craft… Wl Wn533a8 Firmware No fix yet Fix from $1,9502025-01-14 HIGH 7.2 CVE-2024-39781 Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially craft… Wl Wn533a8 Firmware No fix yet Fix from $1,9502025-01-14 CRITICAL 9.8 CVE-2024-39759EPSS 8% Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially c… Wl Wn533a8 Firmware No fix yet Fix from $2,3002025-01-14 CRITICAL 9.8 CVE-2024-39760EPSS 17% Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially c… Wl Wn533a8 Firmware No fix yet Fix from $2,3002025-01-14 CRITICAL 9.8 CVE-2024-39761EPSS 8% Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially c… Wl Wn533a8 Firmware No fix yet Fix from $2,3002025-01-14 HIGH 7.2 CVE-2024-39762EPSS 6% Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A speci… Wl Wn533a8 Firmware No fix yet Fix from $1,9502025-01-14 HIGH 7.2 CVE-2024-39763 Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A speci… Wl Wn533a8 Firmware No fix yet Fix from $1,9502025-01-14 HIGH 7.2 CVE-2024-39764 Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A speci… Wl Wn533a8 Firmware No fix yet Fix from $1,9502025-01-14 HIGH 7.2 CVE-2024-39765EPSS 5% Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A speci… Wl Wn533a8 Firmware No fix yet Fix from $1,9502025-01-14 HIGH 7.2 CVE-2024-39360EPSS 12% An os command injection vulnerability exists in the nas.cgi remove_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP… Wl Wn533a8 Firmware No fix yet Fix from $1,9502025-01-14 HIGH 7.2 CVE-2024-39367EPSS 8% An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A specia… Wl Wn533a8 Firmware No fix yet Fix from $1,9502025-01-14 HIGH 7.2 CVE-2024-37186EPSS 23% An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HT… Wl Wn533a8 Firmware No fix yet Fix from $1,9502025-01-14 CRITICAL 9.8 CVE-2024-34166EPSS 16% An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A speciall… Wl Wn533a8 Firmware No fix yet Fix from $2,3002025-01-14 HIGH 7.8 CVE-2025-0396 A vulnerability, which was classified as critical, has been found in exelban stats up to 2.11.21. This issue affects the function shouldAcceptNewConn… Mitigation only Fix from $1,9502025-01-12 CRITICAL 9.8 CVE-2024-57223 Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function. E7350 Firmware No fix yet Fix from $2,3002025-01-10 CRITICAL 9.8 CVE-2024-57224 Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function. E7350 Firmware No fix yet Fix from $2,3002025-01-10 CRITICAL 9.8 CVE-2024-57225 Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function. E7350 Firmware No fix yet Fix from $2,3002025-01-10 HIGH 8.0 CVE-2024-57226 Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function. E7350 Firmware No fix yet Fix from $1,9502025-01-10 HIGH 8.0 CVE-2024-57227 Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function. E7350 Firmware No fix yet Fix from $1,9502025-01-10 HIGH 8.0 CVE-2024-57228 Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function. E7350 Firmware No fix yet Fix from $1,9502025-01-10 MEDIUM 6.3 CVE-2024-57222 Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function. E7350 Firmware No fix yet Fix from $1,6002025-01-10 MEDIUM 6.3 CVE-2024-57213 TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_passwd fu… A6000r Firmware No fix yet Fix from $1,6002025-01-10 MEDIUM 6.3 CVE-2024-57214 TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi functio… A6000r Firmware No fix yet Fix from $1,6002025-01-10