Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.0 CVE-2024-51186 D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 … Dir 820l Firmware No fix yet Fix from $1,9502024-11-11 CRITICAL 9.8 CVE-2024-11046 A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been classified as critical. Affected is the function upgrade_filter_asp of the file /… Di 8003 Firmware No fix yet Fix from $2,3002024-11-10 HIGH 7.8 CVE-2024-50591 An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a comm… Mitigation only Fix from $1,9502024-11-08 HIGH 8.8 CVE-2024-10966 A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown func… X18 Firmware No fix yet Fix from $1,9502024-11-07 CRITICAL 9.8 CVE-2024-51736 Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.… Symfony 5.4.46 / 6.4.14+ Fix from $2,3002024-11-06 CRITICAL 10.0 CVE-2024-20418 A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB)… Mitigation only Fix from $2,3002024-11-06 CRITICAL 9.8 CVE-2024-48746 An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language processing co… Mitigation only Fix from $2,3002024-11-05 CRITICAL 9.8 CVE-2024-51115 DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability. Dcme 320 Firmware No fix yet Fix from $2,3002024-11-05 CRITICAL 9.8 CVE-2024-42509 Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packet… Mitigation only Fix from $2,3002024-11-05 CRITICAL 9.0 CVE-2024-47460 Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packet… Mitigation only Fix from $2,3002024-11-05 HIGH 7.2 CVE-2024-47461 An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vul… Mitigation only Fix from $1,9502024-11-05 HIGH 7.5 CVE-2024-9579 A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exp… Poly Tc8 Firmware 4.3.2 / 6.3.2+ Fix from $1,9502024-11-05 HIGH 8.0 CVE-2024-52022 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in … R8500 Firmware Mitigation only Fix from $1,9502024-11-05 CRITICAL 9.8 CVE-2024-10035 Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Impro… Coslat after 3.1069 Fix from $2,3002024-11-04 CRITICAL 9.8 CVE-2024-10697EPSS 26% A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of… Ac6 Firmware No fix yet Fix from $2,3002024-11-02 CRITICAL 9.8 CVE-2024-51255 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_… Vigor3900 Firmware Mitigation only Fix from $2,3002024-10-31 CRITICAL 9.8 CVE-2024-51260 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_proc… Vigor3900 Firmware Mitigation only Fix from $2,3002024-10-31 HIGH 8.8 CVE-2024-51254 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cace… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-31 CRITICAL 9.8 CVE-2024-51259 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cac… Vigor3900 Firmware Mitigation only Fix from $2,3002024-10-31 HIGH 8.4 CVE-2024-48214 KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulne… Mitigation only Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-51258 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunn… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-51257 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertifi… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-51296 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace f… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-51299 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog … Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-51300 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd fun… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-51301 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_moni… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-51304 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 HIGH 7.2 CVE-2024-41153 Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If … Tro610 Firmware 9.2.0.5+ Fix from $1,9502024-10-29 MEDIUM 6.3 CVE-2024-10435 A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cov/trigge… Mitigation only Fix from $1,6002024-10-28 HIGH 7.2 CVE-2024-10428EPSS 15% A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function se… Wn530h4 Firmware No fix yet Fix from $1,9502024-10-27