Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 10.0 CVE-2024-32766 An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… Qts 4.5.4.2627 / 5.1.3.2578+ Fix from $2,3002024-04-26 CRITICAL 9.8 CVE-2024-0740 Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vulnerability that does not requi… Target Management after 4.5.400 Fix from $2,3002024-04-26 HIGH 7.2 CVE-2024-3154 A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary … Patch available Fix from $1,9502024-04-26 HIGH 7.5 CVE-2022-35503 Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module con… Mitigation only Fix from $1,9502024-04-22 CRITICAL 9.8 CVE-2024-22061 A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arb… Avalanche 6.4.3.528+ Fix from $2,3002024-04-19 HIGH 8.8 CVE-2024-32292 Tenda W30E v1.0 V1.0.1.25(633) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter. W30e Firmware No fix yet Fix from $1,9502024-04-17 MEDIUM 6.3 CVE-2024-32282 Tenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter. Fh1202 Firmware Mitigation only Fix from $1,6002024-04-17 HIGH 7.3 CVE-2024-32283 Tenda FH1203 V2.0.1.6 firmware has a command injection vulnerablility in formexeCommand function via the cmdinput parameter. Fh1203 Firmware No fix yet Fix from $1,9502024-04-17 HIGH 8.8 CVE-2024-32281 Tenda AC7V1.0 v15.03.06.44 firmware contains a command injection vulnerablility in formexeCommand function via the cmdinput parameter. Ac7 Firmware No fix yet Fix from $1,9502024-04-17 CRITICAL 9.8 CVE-2023-40146 A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command lin… Smart Reader Firmware No fix yet Fix from $2,3002024-04-17 CRITICAL 9.8 CVE-2024-3908EPSS 9% A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is the function formWriteFacMac of the file /goform/Writ… Ac500 Firmware No fix yet Fix from $2,3002024-04-17 MEDIUM 5.3 CVE-2024-21117 Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affe… Outside In Technology Mitigation only Fix from $1,6002024-04-16 CRITICAL 9.1 CVE-2024-32025 Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `group_images_gui.py`. This vulnerability i… Kohya Ss 24.0.1+ Fix from $2,3002024-04-16 CRITICAL 9.8 CVE-2024-32026 Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_gui.py`. This vulnerability is… Kohya Ss 24.0.1+ Fix from $2,3002024-04-16 CRITICAL 9.8 CVE-2024-32027 Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetune_gui.py` This vulnerability … Kohya Ss 24.0.1+ Fix from $2,3002024-04-16 CRITICAL 9.8 CVE-2024-32022 Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_gui.py. This vulnerability is … Kohya Ss 23.1.15+ Fix from $2,3002024-04-16 CRITICAL 9.8 CVE-2024-3871 The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affec… Mitigation only Fix from $2,3002024-04-16 CRITICAL 9.8 CVE-2024-3271 A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval function. Attackers can bypass th… Llamaindex 0.10.26+ Fix from $2,3002024-04-16 HIGH 7.8 CVE-2023-33806 Insecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to execute arbitrary commands. Ds D5b86rb\/b Firmware Mitigation only Fix from $1,9502024-04-15 HIGH 8.8 CVE-2024-30220 Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute an arbitr… Mzk Mf300n Firmware after 1.18 Fix from $1,9502024-04-15 CRITICAL 10.0 CVE-2024-3400 KEVEPSS 100% A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for speci… Pan Os Mitigation only Fix from $2,3002024-04-12 HIGH 8.8 CVE-2024-29269EPSS 6% An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter. Tlr 2005ksh Firmware No fix yet Fix from $1,9502024-04-10 CRITICAL 9.8 CVE-2024-3566EPSS 7% A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess fu… Node.js 1.6.19.0 / 1.77.2+ Fix from $2,3002024-04-10 HIGH 8.8 CVE-2023-6999 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and incl… Pods 2.7.31.2 / 2.8.23.2+ Fix from $1,9502024-04-09 HIGH 7.2 CVE-2024-21322 Microsoft Defender for IoT Remote Code Execution Vulnerability Defender For Iot 24.1.3+ Fix from $1,9502024-04-09 CRITICAL 9.8 CVE-2023-49133 A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 … Eap225 Firmware No fix yet Fix from $2,3002024-04-09 CRITICAL 9.8 CVE-2023-49134 A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 … Eap225 Firmware No fix yet Fix from $2,3002024-04-09 HIGH 8.0 CVE-2024-31811 TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLang… Ex200 Firmware No fix yet Fix from $1,9502024-04-08 HIGH 8.8 CVE-2024-30891 A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters fo… Ac18 Firmware No fix yet Fix from $1,9502024-04-05 CRITICAL 9.8 CVE-2024-27981 A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) al… Mitigation only Fix from $2,3002024-04-04