Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2023-24467 Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000. Imanager 3.2.6+ Fix from $2,3002024-11-22 HIGH 8.8 CVE-2021-38116 Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5 Imanager 3.2.5+ Fix from $1,9502024-11-22 CRITICAL 9.8 CVE-2021-38117 Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. Imanager 3.2.5+ Fix from $2,3002024-11-22 MEDIUM 6.3 CVE-2024-53333EPSS 19% TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an at… Ex200 Firmware No fix yet Fix from $1,6002024-11-21 HIGH 8.0 CVE-2024-48288EPSS 10% TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and bac… Tl Ipc42c Firmware No fix yet Fix from $1,9502024-11-21 HIGH 8.0 CVE-2024-48286EPSS 12% Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function. E3000 Firmware No fix yet Fix from $1,9502024-11-21 MEDIUM 6.8 CVE-2024-48747 An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file. Mitigation only Fix from $1,6002024-11-21 CRITICAL 9.8 CVE-2024-11320EPSS 91% Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects P… Pandora Fms 777.5+ Fix from $2,3002024-11-21 CRITICAL 9.8 CVE-2024-51151EPSS 30% D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter. Di 8200 Firmware No fix yet Fix from $2,3002024-11-21 CRITICAL 9.1 CVE-2024-33439 An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters. Mitigation only Fix from $2,3002024-11-20 HIGH 8.0 CVE-2024-52739EPSS 9% D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the fla… Di 8400 Firmware No fix yet Fix from $1,9502024-11-20 CRITICAL 9.1 CVE-2024-29292 Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbi… Mitigation only Fix from $2,3002024-11-20 HIGH 8.8 CVE-2024-51503 A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges… Deep Security Agent Mitigation only Fix from $1,9502024-11-19 HIGH 8.8 CVE-2024-45505 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerabili… Hertzbeat 1.6.1+ Fix from $1,9502024-11-18 CRITICAL 9.8 CVE-2024-10443EPSS 28% Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePho… Photos 1.0.2-10026 / 1.1.0-10053+ Fix from $2,3002024-11-15 CRITICAL 9.8 CVE-2022-1884 A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to imp… Gogs after 0.12.7 Fix from $2,3002024-11-15 CRITICAL 9.6 CVE-2024-52308 The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ss… Cli 2.62.0+ Fix from $2,3002024-11-14 MEDIUM 6.5 CVE-2024-51027EPSS 7% Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networksafe.php via the province parameter. Mitigation only Fix from $1,6002024-11-13 HIGH 8.8 CVE-2024-50852 Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function. G3 Firmware No fix yet Fix from $1,9502024-11-13 HIGH 8.8 CVE-2024-50853 Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function. G3 Firmware No fix yet Fix from $1,9502024-11-13 HIGH 8.0 CVE-2024-28726EPSS 8% An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a c… Mitigation only Fix from $1,9502024-11-12 CRITICAL 9.8 CVE-2024-28729 An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a c… Dwr 2000m Firmware No fix yet Fix from $2,3002024-11-12 HIGH 7.3 CVE-2021-27702 Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the router dashboard. No fix yet Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-49042 Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability Azure Database For Postgresql Flexible Server 12.20 / 13.16+ Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-43613 Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability Azure Database For Postgresql Flexible Server 12.20 / 13.16+ Fix from $1,9502024-11-12 HIGH 7.8 CVE-2024-49026 Microsoft Excel Remote Code Execution Vulnerability 365 Apps Patch available Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-50572 A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-… Ruggedcom Rm1224 Lte\(4g\) Eu Firmware 8.2+ Fix from $1,9502024-11-12 HIGH 7.8 CVE-2024-49557 Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization of Special Elements used in … Smartfabric Os10 10.5.4.13 / 10.5.5.12+ Fix from $1,9502024-11-12 HIGH 7.8 CVE-2024-49560 Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a command injection vulnerability. A low privileged att… Smartfabric Os10 10.5.4.13 / 10.5.5.12+ Fix from $1,9502024-11-12 CRITICAL 9.8 CVE-2024-25255 Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties report that … No fix yet Fix from $2,3002024-11-11