Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2024-45824 CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Comm… Factorytalk View after 14.0 Fix from $2,3002024-09-12 HIGH 8.8 CVE-2024-44570 RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php. Rely Pcie Firmware after 23.1.0 Fix from $1,9502024-09-11 HIGH 8.8 CVE-2024-44572 RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function. Rely Pcie Firmware after 23.1.0 Fix from $1,9502024-09-11 HIGH 8.8 CVE-2024-44574 RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function. Rely Pcie Firmware after 23.1.0 Fix from $1,9502024-09-11 HIGH 8.8 CVE-2024-44577 RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function. Rely Pcie Firmware after 23.1.0 Fix from $1,9502024-09-11 CRITICAL 9.8 CVE-2024-44466EPSS 11% COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and… Cf Xr11 Firmware No fix yet Fix from $2,3002024-09-11 HIGH 7.2 CVE-2024-38227EPSS 8% Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Server Patch available Fix from $1,9502024-09-10 HIGH 7.2 CVE-2024-38228 Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Server Patch available Fix from $1,9502024-09-10 CRITICAL 9.8 CVE-2023-36103 Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via craft… Ac15 Firmware No fix yet Fix from $2,3002024-09-10 HIGH 7.3 CVE-2024-33508 An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 throug… Forticlient Enterprise Management Server 7.0.13 / 7.2.5+ Fix from $1,9502024-09-10 HIGH 7.6 CVE-2024-42427 Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An… Wyse Thinos Mitigation only Fix from $1,9502024-09-10 CRITICAL 9.8 CVE-2024-44410 D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function. Di 8300 Firmware No fix yet Fix from $2,3002024-09-09 HIGH 8.8 CVE-2024-44334EPSS 32% D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.… Mitigation only Fix from $1,9502024-09-09 HIGH 8.8 CVE-2024-44335EPSS 12% D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1… Mitigation only Fix from $1,9502024-09-09 HIGH 8.1 CVE-2024-36138 Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.… Mitigation only Fix from $1,9502024-09-07 HIGH 8.8 CVE-2024-44844 DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command funct… Vigor3900 Firmware No fix yet Fix from $1,9502024-09-06 HIGH 8.8 CVE-2024-44845 DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string fu… Vigor3900 Firmware No fix yet Fix from $1,9502024-09-06 HIGH 7.8 CVE-2024-38641 An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… Qts Mitigation only Fix from $1,9502024-09-06 HIGH 8.8 CVE-2023-47563 An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to e… Video Station 5.8.2+ Fix from $1,9502024-09-06 CRITICAL 9.8 CVE-2024-44401 D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file Di 8100g Firmware No fix yet Fix from $2,3002024-09-06 CRITICAL 9.8 CVE-2024-44402 D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm. Di 8100g Firmware No fix yet Fix from $2,3002024-09-06 HIGH 8.8 CVE-2024-38486 Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used i… Smartfabric Os10 10.5.6.4+ Fix from $1,9502024-09-06 MEDIUM 6.8 CVE-2024-44383 WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm. Fbm 291w Firmware No fix yet Fix from $1,6002024-09-04 CRITICAL 9.8 CVE-2024-44400EPSS 14% A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in th… Di 8400 Firmware No fix yet Fix from $2,3002024-09-04 HIGH 7.2 CVE-2024-44916 Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php f… Seacms No fix yet Fix from $1,9502024-08-30 CRITICAL 9.8 CVE-2024-42905EPSS 15% Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device … Mitigation only Fix from $2,3002024-08-28 HIGH 7.2 CVE-2021-38120 A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to i… Netiq Advanced Authentication 6.3+ Fix from $1,9502024-08-28 CRITICAL 9.8 CVE-2024-8212EPSS 7% A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L… Dns 315l Firmware No fix yet Fix from $2,3002024-08-27 CRITICAL 9.8 CVE-2024-8213EPSS 7% A vulnerability classified as critical has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323… Dns 315l Firmware No fix yet Fix from $2,3002024-08-27 CRITICAL 9.8 CVE-2024-8214EPSS 5% A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS… Dns 315l Firmware No fix yet Fix from $2,3002024-08-27