Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.1 CVE-2024-24550 A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File… Bludit after 3.15.0 Fix from $1,9502024-06-24 HIGH 7.2 CVE-2024-6269EPSS 21% A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects the function get_ip.addr_details of the fi… Rg Uac Firmware No fix yet Fix from $1,9502024-06-23 CRITICAL 9.8 CVE-2014-5470EPSS 10% Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed t… No fix yet Fix from $2,3002024-06-21 CRITICAL 9.1 CVE-2024-37642EPSS 11% TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemC… Tew 814dap Firmware No fix yet Fix from $2,3002024-06-14 HIGH 8.8 CVE-2024-35241 Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with … Patch available Fix from $1,9502024-06-10 HIGH 8.8 CVE-2024-35242 Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/h… Patch available Fix from $1,9502024-06-10 HIGH 8.8 CVE-2024-37569 An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in the hostname … 6869i Sip Firmware after 5.0.0.1018 Fix from $1,9502024-06-09 HIGH 8.8 CVE-2024-37570 On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (se… 6869i Sip Firmware No fix yet Fix from $1,9502024-06-09 CRITICAL 9.8 CVE-2024-37385 Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue … Webmail 1.5.7 / 1.6.7+ Fix from $2,3002024-06-07 HIGH 8.8 CVE-2024-30368 A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… Advanced Core Operating System Mitigation only Fix from $1,9502024-06-06 CRITICAL 9.8 CVE-2024-36604 Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows … O3 Firmware No fix yet Fix from $2,3002024-06-04 HIGH 7.2 CVE-2024-34792 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in dexta Dextaz Ping allows Command Injection.This … Dextaz Ping after 0.65 Fix from $1,9502024-06-04 CRITICAL 9.8 CVE-2024-36783 TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function. Lr350 Firmware Mitigation only Fix from $2,3002024-06-03 MEDIUM 6.3 CVE-2024-34852 F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transceiver_sc… Datacube3 Firmware No fix yet Fix from $1,6002024-05-28 MEDIUM 5.9 CVE-2024-35401 TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFi… Cp900l Firmware Mitigation only Fix from $1,6002024-05-28 HIGH 8.8 CVE-2024-35397EPSS 15% TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime … Cp900l Firmware Mitigation only Fix from $1,9502024-05-28 HIGH 8.8 CVE-2024-5035 The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and… Mitigation only Fix from $1,9502024-05-27 CRITICAL 9.8 CVE-2024-5355 A vulnerability, which was classified as critical, has been found in anji-plus AJ-Report up to 1.4.1. This issue affects the function IGroovyHandler.… Aj Report after 1.4.1 Fix from $2,3002024-05-26 CRITICAL 9.8 CVE-2024-35374 Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute a… Mocodo Online after 4.2.6 Fix from $2,3002024-05-24 HIGH 8.6 CVE-2024-35340 Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip/goform/formexeCommand. Fh1206 Firmware No fix yet Fix from $1,9502024-05-24 CRITICAL 9.8 CVE-2024-4267 A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnera… Lollms Webui No fix yet Fix from $2,3002024-05-22 HIGH 7.2 CVE-2024-5196 A vulnerability classified as critical has been found in Arris VAP2500 08.50. This affects an unknown part of the file /tools_command.php. The manipu… Vap2500 Firmware Mitigation only Fix from $1,9502024-05-22 HIGH 7.2 CVE-2024-5195 A vulnerability was found in Arris VAP2500 08.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file /di… Vap2500 Firmware Mitigation only Fix from $1,9502024-05-22 HIGH 7.2 CVE-2024-5194 A vulnerability was found in Arris VAP2500 08.50. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the… Vap2500 Firmware Mitigation only Fix from $1,9502024-05-22 CRITICAL 9.3 CVE-2024-5023 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe allows Command Injection.This … Mitigation only Fix from $2,3002024-05-16 HIGH 7.8 CVE-2024-1417 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS a… Mitigation only Fix from $1,9502024-05-16 HIGH 7.8 CVE-2024-20326 A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attac… Confd Basic 5.4 / 5.5+ Fix from $1,9502024-05-16 CRITICAL 9.4 CVE-2024-4999EPSS 12% A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary … Mitigation only Fix from $2,3002024-05-16 CRITICAL 9.8 CVE-2024-4078 A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code execution due to insufficient sa… Patch available Fix from $2,3002024-05-16 CRITICAL 9.0 CVE-2024-2366 A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lol… Lollms Web Ui 9.5+ Fix from $2,3002024-05-16