Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2024-3483 Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserializat… Imanager after 3.2.6 Fix from $2,3002024-05-15 HIGH 8.8 CVE-2023-6321 A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root… Cam Firmware 4.2.10 / 4.2.11+ Fix from $1,9502024-05-15 CRITICAL 9.8 CVE-2024-32353 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer funct… X5000r Firmware No fix yet Fix from $2,3002024-05-14 MEDIUM 6.0 CVE-2024-32354 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer fu… X5000r Firmware No fix yet Fix from $1,6002024-05-14 HIGH 8.0 CVE-2024-32355 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer f… X5000r Firmware No fix yet Fix from $1,9502024-05-14 MEDIUM 6.0 CVE-2024-32349 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" paramet… X5000r Firmware No fix yet Fix from $1,6002024-05-14 HIGH 7.2 CVE-2024-31485 A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.30), SICORE Base system (All versions < V1.3.0). Th… Mitigation only Fix from $1,9502024-05-14 HIGH 7.8 CVE-2024-28136 A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCP… Charx Sec 3000 Firmware after 1.5.1 Fix from $1,9502024-05-14 MEDIUM 5.0 CVE-2024-28135 A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due t… Charx Sec 3000 Firmware after 1.5.1 Fix from $1,6002024-05-14 HIGH 7.8 CVE-2024-4712 An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists… Papercut Mf 23.0.9+ Fix from $1,9502024-05-14 HIGH 7.5 CVE-2024-34352 1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the pro… 1panel 1.10.3-lts+ Fix from $1,9502024-05-14 HIGH 7.2 CVE-2024-34338 Tenda O3V2 with firmware versions V1.0.0.10 and V1.0.0.12 was discovered to contain a Blind Command Injection via dest parameter in /goform/getTracer… O3 Firmware No fix yet Fix from $1,9502024-05-14 MEDIUM 6.5 CVE-2024-34206 TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the w… Cp450 Firmware No fix yet Fix from $1,6002024-05-14 CRITICAL 9.8 CVE-2024-34204 TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the Fi… Cp450 Firmware No fix yet Fix from $2,3002024-05-14 CRITICAL 10.0 CVE-2024-29895EPSS 94% Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthe… Patch available Fix from $2,3002024-05-14 HIGH 7.8 CVE-2024-27818 The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14… Ipados 14.5 / 16.7.8+ Fix from $1,9502024-05-14 HIGH 8.3 CVE-2024-34347 @hoppscotch/cli is a CLI to run Hoppscotch Test Scripts in CI environments. Prior to 0.8.0, the @hoppscotch/js-sandbox package provides a Javascript … Patch available Fix from $1,9502024-05-08 HIGH 7.5 CVE-2024-33112EPSS 6% D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func. Dir 845l Firmware after 1.01krb03 Fix from $1,9502024-05-06 MEDIUM 5.3 CVE-2024-33113 D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php. Dir 845l Firmware after 1.01krb03 Fix from $1,6002024-05-06 HIGH 8.0 CVE-2024-33788 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint. E5600 Firmware No fix yet Fix from $1,9502024-05-06 CRITICAL 9.8 CVE-2024-33789 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint. E5600 Firmware No fix yet Fix from $2,3002024-05-03 HIGH 8.0 CVE-2023-42128 Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitra… Axiom Mitigation only Fix from $1,9502024-05-03 HIGH 8.8 CVE-2023-39471 TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbi… Tl Wr841n Firmware 231119 / 231121+ Fix from $1,9502024-05-03 HIGH 8.8 CVE-2023-38120 Adtran SR400ac ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af… Sr400ac Firmware Mitigation only Fix from $1,9502024-05-03 MEDIUM 6.4 CVE-2024-22546 TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges ca… Tew 815dap Firmware No fix yet Fix from $1,6002024-04-30 MEDIUM 6.3 CVE-2023-1000 A vulnerability was found in cyanomiko dcnnt-py up to 0.9.0. It has been classified as critical. Affected is the function main of the file dcnnt/plug… Patch available Fix from $1,6002024-04-27 MEDIUM 6.4 CVE-2024-32884 gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program wou… Mitigation only Fix from $1,6002024-04-26 HIGH 7.5 CVE-2024-33342 D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows remote attackers to execute ar… Dir 822\+ Firmware No fix yet Fix from $1,9502024-04-26 CRITICAL 9.8 CVE-2024-33344EPSS 20% D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute ar… Dir 822\+ Firmware No fix yet Fix from $2,3002024-04-26 MEDIUM 5.4 CVE-2024-28328 CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name paramet… Mitigation only Fix from $1,6002024-04-26