Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2024-41319EPSS 6% TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function. A6000r Firmware No fix yet Fix from $2,3002024-07-23 CRITICAL 9.8 CVE-2024-41316 TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps fu… A6000r Firmware No fix yet Fix from $2,3002024-07-22 CRITICAL 9.8 CVE-2024-41318 TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pinco… A6000r Firmware No fix yet Fix from $2,3002024-07-22 HIGH 8.8 CVE-2024-41320 TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the get_apcli_conn_info… A6000r Firmware No fix yet Fix from $1,9502024-07-22 HIGH 8.0 CVE-2024-39963 AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contai… Ax9 Firmware No fix yet Fix from $1,9502024-07-19 CRITICAL 9.4 CVE-2024-38492 This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted… Mitigation only Fix from $2,3002024-07-15 HIGH 8.8 CVE-2024-30213 StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to… Mitigation only Fix from $1,9502024-07-12 CRITICAL 9.8 CVE-2024-40110 Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the productimage paramet… Poultry Farm Management System No fix yet Fix from $2,3002024-07-12 CRITICAL 9.8 CVE-2024-39914EPSS 23% FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected… Fogproject 1.5.10.41+ Fix from $2,3002024-07-12 HIGH 7.8 CVE-2024-39567 A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnera… Sinema Remote Connect Client 3.2+ Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-39568 A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnera… Sinema Remote Connect Client 3.2+ Fix from $1,9502024-07-09 HIGH 7.2 CVE-2024-39569 A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnera… Sinema Remote Connect Client 3.2+ Fix from $1,9502024-07-09 HIGH 8.8 CVE-2024-39570 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command inject… Sinema Remote Connect Server 3.2+ Fix from $1,9502024-07-09 HIGH 8.8 CVE-2024-39571 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command inject… Sinema Remote Connect Server 3.2+ Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-4944 A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands … Mobile Vpn With Ssl 12.10.4+ Fix from $1,9502024-07-09 HIGH 7.5 CVE-2024-25639 Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize the AI model's response and … Khoj 1.13.0+ Fix from $1,9502024-07-08 CRITICAL 9.8 CVE-2024-39028 An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php. Seacms after 12.9 Fix from $2,3002024-07-05 HIGH 8.8 CVE-2024-36983 In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated… Splunk 9.0.10 / 9.1.5+ Fix from $1,9502024-07-01 HIGH 7.2 CVE-2024-36073 Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadowing compo… Mitigation only Fix from $1,9502024-06-27 HIGH 8.4 CVE-2024-4578 This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as… Mitigation only Fix from $1,9502024-06-27 HIGH 7.2 CVE-2024-39373 TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker t… Markoni D \(compact\) Firmware 2.0.1+ Fix from $1,9502024-06-27 CRITICAL 9.8 CVE-2024-4883EPSS 65% In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauth… Whatsup Gold 23.1.3+ Fix from $2,3002024-06-25 CRITICAL 9.8 CVE-2024-4884EPSS 24% In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.… Whatsup Gold 23.1.3+ Fix from $2,3002024-06-25 HIGH 8.8 CVE-2024-6257 HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to … Go Getter 1.7.5+ Fix from $1,9502024-06-25 HIGH 8.8 CVE-2024-4639 OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configura… Oncell G3470a Lte Us T Firmware after 1.7.7 Fix from $1,9502024-06-25 HIGH 8.8 CVE-2024-4638 OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upl… Oncell G3470a Lte Eu T Firmware after 1.7.7 Fix from $1,9502024-06-25 MEDIUM 5.3 CVE-2024-38894 WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi. Wn551k1 Firmware No fix yet Fix from $1,6002024-06-24 MEDIUM 5.3 CVE-2024-38896 WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi. Wn551k1 Firmware No fix yet Fix from $1,6002024-06-24 HIGH 8.8 CVE-2024-37091 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, Sty… Consulting Elementor Widgets 1.3.1+ Fix from $1,9502024-06-24 HIGH 8.8 CVE-2024-24551 A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulner… Bludit after 3.15.0 Fix from $1,9502024-06-24