Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 7.2 CVE-2024-10429EPSS 18% A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected is the function set_ipv6 of … Wn530h4 Firmware No fix yet Fix from $1,9502024-10-27 HIGH 7.5 CVE-2024-48139 A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat dat… Mitigation only Fix from $1,9502024-10-24 HIGH 7.5 CVE-2024-48140 A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to acc… Mitigation only Fix from $1,9502024-10-24 HIGH 7.5 CVE-2024-48141 A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent ch… Mitigation only Fix from $1,9502024-10-24 HIGH 7.5 CVE-2024-48142 A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltr… Mitigation only Fix from $1,9502024-10-24 CRITICAL 9.1 CVE-2024-48144 A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate a… Mitigation only Fix from $2,3002024-10-24 CRITICAL 9.1 CVE-2024-48145 A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all prev… Mitigation only Fix from $2,3002024-10-24 HIGH 8.8 CVE-2024-48440 Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection… Mitigation only Fix from $1,9502024-10-24 HIGH 8.8 CVE-2024-48441 Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerab… Mitigation only Fix from $1,9502024-10-24 CRITICAL 9.8 CVE-2024-48904 An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Pleas… Cloud Edge 5.6.3228 / 7.0.1081+ Fix from $2,3002024-10-22 HIGH 7.8 CVE-2024-9287 A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted pro… Python 3.9.21 / 3.10.16+ Fix from $1,9502024-10-22 CRITICAL 9.1 CVE-2024-40089 A Command Injection vulnerability in Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, authenticated attackers to execute arbitrary code by injecti… Vilo 5 Firmware after 5.16.1.33 Fix from $2,3002024-10-21 CRITICAL 9.8 CVE-2024-35285 A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attac… Micollab after 9.8.0.33 Fix from $2,3002024-10-21 CRITICAL 9.8 CVE-2024-48659 An issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component. Dcme 320 L Firmware after 9.3.2.114 Fix from $2,3002024-10-21 HIGH 7.2 CVE-2024-10193EPSS 15% A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028 and classified as critical. This issue affects the function ping_d… Wn530h4 Firmware after 20221028 Fix from $1,9502024-10-20 HIGH 8.8 CVE-2024-9264EPSS 95% The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficie… Grafana Mitigation only Fix from $1,9502024-10-18 HIGH 7.2 CVE-2024-6333 Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products. No fix yet Fix from $1,9502024-10-17 MEDIUM 6.8 CVE-2024-35518 Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter. Ex6120 Firmware after 1.0.0.68 Fix from $1,6002024-10-14 MEDIUM 6.8 CVE-2024-35519 Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap… Ex3700 Firmware after 1.0.2.28 Fix from $1,6002024-10-14 MEDIUM 6.8 CVE-2024-35520EPSS 9% Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter. R7000 Firmware Mitigation only Fix from $1,6002024-10-14 CRITICAL 9.8 CVE-2024-48153 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subco… Vigor3900 Firmware Mitigation only Fix from $2,3002024-10-14 HIGH 7.2 CVE-2024-35522 Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injection in operating_mode.cgi via t… Ex3700 Firmware 1.0.0.98+ Fix from $1,9502024-10-11 HIGH 7.2 CVE-2024-35517EPSS 15% Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter. Xr1000 Firmware Mitigation only Fix from $1,9502024-10-11 HIGH 8.8 CVE-2024-44413 A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in th… Mitigation only Fix from $1,9502024-10-11 HIGH 7.3 CVE-2024-39563 A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted reque… Junos Space Mitigation only Fix from $1,9502024-10-11 CRITICAL 9.8 CVE-2024-9793EPSS 23% A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconf… Ac1206 Firmware No fix yet Fix from $2,3002024-10-10 MEDIUM 6.7 CVE-2024-38817 VMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious pa… Mitigation only Fix from $1,6002024-10-09 HIGH 7.8 CVE-2024-7840 In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hype… Telerik Reporting after 18.2.24.924 Fix from $1,9502024-10-09 MEDIUM 6.7 CVE-2024-39437 In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege … Android Mitigation only Fix from $1,6002024-10-09 MEDIUM 6.7 CVE-2024-39438 In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege … Android Mitigation only Fix from $1,6002024-10-09