Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 7.2 CVE-2024-11634 Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated att… Connect Secure 22.7+ Fix from $1,9502024-12-10 HIGH 7.2 CVE-2024-11772EPSS 8% Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve… Cloud Services Appliance 5.0.3+ Fix from $1,9502024-12-10 CRITICAL 9.8 CVE-2024-55547EPSS 17% SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e. Iap 420 Firmware after 2.01e Fix from $2,3002024-12-10 HIGH 8.8 CVE-2024-55544EPSS 12% Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.… Iap 420 Firmware after 2.01e Fix from $1,9502024-12-10 HIGH 7.6 CVE-2024-53919 An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physi… Mitigation only Fix from $1,9502024-12-10 HIGH 8.8 CVE-2024-12358 A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. … Datax Web No fix yet Fix from $1,9502024-12-09 HIGH 8.8 CVE-2024-12350 A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the file \src\main\java\c… Jfinalcms No fix yet Fix from $1,9502024-12-09 CRITICAL 9.8 CVE-2024-50388 An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attack… Hybrid Backup Sync Mitigation only Fix from $2,3002024-12-06 HIGH 8.0 CVE-2024-51772 An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary … Clearpass Policy Manager 6.11.10 / 6.12.3+ Fix from $1,9502024-12-03 MEDIUM 6.3 CVE-2024-53672 A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the und… Clearpass Policy Manager 6.11.10 / 6.12.3+ Fix from $1,6002024-12-03 HIGH 8.8 CVE-2024-51114 An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via the code/fun… Mitigation only Fix from $1,9502024-12-03 HIGH 8.8 CVE-2024-51771 A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor … Clearpass Policy Manager 6.11.10 / 6.12.3+ Fix from $1,9502024-12-03 HIGH 7.8 CVE-2024-29404 An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter o… Mitigation only Fix from $1,9502024-12-03 HIGH 7.2 CVE-2024-11013 Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14… Mitigation only Fix from $1,9502024-11-29 HIGH 7.8 CVE-2024-38831 VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malici… Aria Operations 8.18.2+ Fix from $1,9502024-11-26 HIGH 7.2 CVE-2024-11659EPSS 28% A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this issue is some u… Enh1350ext Firmware No fix yet Fix from $1,9502024-11-25 HIGH 7.2 CVE-2024-11657EPSS 28% A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. Affected is an unknown f… Enh1350ext Firmware No fix yet Fix from $1,9502024-11-25 HIGH 7.2 CVE-2024-11658EPSS 28% A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this vulnerabil… Enh1350ext Firmware No fix yet Fix from $1,9502024-11-25 HIGH 7.2 CVE-2024-11656EPSS 27% A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This issue affects … Enh1350ext Firmware No fix yet Fix from $1,9502024-11-25 HIGH 7.2 CVE-2024-11655EPSS 27% A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vulnerability affects unknown c… Enh1350ext Firmware No fix yet Fix from $1,9502024-11-25 HIGH 7.2 CVE-2024-11653EPSS 28% A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical. Affected by this issue is so… Enh1350ext Firmware No fix yet Fix from $1,9502024-11-25 HIGH 7.2 CVE-2024-11654EPSS 28% A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This affects an unknown part of… Enh1350ext Firmware No fix yet Fix from $1,9502024-11-25 HIGH 7.2 CVE-2024-11652EPSS 29% A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critical. Affected by this vulnerab… Enh1350ext Firmware No fix yet Fix from $1,9502024-11-25 HIGH 7.2 CVE-2024-11651EPSS 26% A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been classified as critical. Affected is an unknown … Enh1350ext Firmware No fix yet Fix from $1,9502024-11-25 HIGH 8.8 CVE-2024-11665 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Comm… Salia Plcc Firmware after 2.0.4 Fix from $1,9502024-11-24 HIGH 7.8 CVE-2024-53899 virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted co… Virtualenv 20.26.6+ Fix from $1,9502024-11-24 CRITICAL 9.8 CVE-2024-37782 An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbi… Mitigation only Fix from $2,3002024-11-22 CRITICAL 9.8 CVE-2024-48860 An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attack… Qurouter Mitigation only Fix from $2,3002024-11-22 HIGH 7.8 CVE-2024-48861 An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network… Qurouter Mitigation only Fix from $1,9502024-11-22 HIGH 8.8 CVE-2024-38644 An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated a… Notes Station 3 3.9.7+ Fix from $1,9502024-11-22