Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2024-3116EPSS 65% pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers … Pgadmin 4 after 8.4 Fix from $2,3002024-04-04 CRITICAL 9.8 CVE-2024-3273 KEVEPSS 100% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to… Dns 320l Firmware Mitigation only Fix from $2,3002024-04-04 HIGH 8.0 CVE-2024-30572 Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter. R6850 Firmware No fix yet Fix from $1,9502024-04-03 HIGH 7.4 CVE-2024-22246 VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with … Mitigation only Fix from $1,9502024-04-02 HIGH 7.2 CVE-2024-29949 There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbit… Mitigation only Fix from $1,9502024-04-02 HIGH 8.8 CVE-2023-41724EPSS 13% A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlyin… Standalone Sentry 9.19.0+ Fix from $1,9502024-03-31 HIGH 8.8 CVE-2024-30637 Tenda F1202 v1.2.0.20(408) has a command injection vulnerablility in the formWriteFacMac function in the mac parameter. F1202 Firmware No fix yet Fix from $1,9502024-03-29 HIGH 7.3 CVE-2024-2947 A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, re… Mitigation only Fix from $1,9502024-03-28 HIGH 8.8 CVE-2024-25946 Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnera… Powermax Eem 9.2.4.6 / 9.2.4.9+ Fix from $1,9502024-03-28 HIGH 8.8 CVE-2024-25955 Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnera… Powermax Eem 9.2.4.6 / 9.2.4.9+ Fix from $1,9502024-03-28 HIGH 8.8 CVE-2024-3009EPSS 8% A vulnerability has been found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected by this vulnerability is the function formWriteFacMa… Fh1205 Firmware No fix yet Fix from $1,9502024-03-28 HIGH 8.8 CVE-2024-2991EPSS 8% A vulnerability has been found in Tenda FH1203 2.0.1.6 and classified as critical. This vulnerability affects the function formWriteFacMac of the fil… Fh1203 Firmware No fix yet Fix from $1,9502024-03-27 HIGH 8.1 CVE-2024-29946 In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let atta… Splunk 9.0.9 / 9.1.4+ Fix from $1,9502024-03-27 HIGH 8.8 CVE-2024-2982EPSS 8% A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this vulnerability is the function formWriteFacM… Fh1202 Firmware No fix yet Fix from $1,9502024-03-27 HIGH 8.2 CVE-2024-1540 A command injection vulnerability exists in the deploy+test-visual.yml workflow of the gradio-app/gradio repository, due to improper neutralization o… Gradio 2024-02-09+ Fix from $1,9502024-03-27 CRITICAL 9.8 CVE-2024-28545 Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload function. Ac18 Firmware No fix yet Fix from $2,3002024-03-26 HIGH 7.8 CVE-2023-52624 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before executing GPINT commands [Why] DMCUB can be … Linux Kernel 6.7.3+ Fix from $1,9502024-03-26 HIGH 8.1 CVE-2024-24897 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in openEuler A-Tune-Collector on Linux allows Comma… Mitigation only Fix from $1,9502024-03-25 HIGH 8.8 CVE-2024-28041 HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command. Mitigation only Fix from $1,9502024-03-25 HIGH 8.8 CVE-2024-29366 A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03. Dir 845l Firmware after 1.01krb03 Fix from $1,9502024-03-22 CRITICAL 9.0 CVE-2024-29385 DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function. Dir 845l Firmware after 1.01krb03 Fix from $2,3002024-03-22 CRITICAL 9.8 CVE-2024-29864 Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables. Distrobox 1.7.0.1+ Fix from $2,3002024-03-21 HIGH 7.3 CVE-2024-2642 A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been declared as critical. Affected by this vulnerability is an unknown func… Rg Nbs2009g P Firmware Mitigation only Fix from $1,9502024-03-19 HIGH 8.4 CVE-2023-41334 Astropy is a project for astronomy in Python that fosters interoperability between Python astronomy packages. Version 5.3.2 of the Astropy core packa… Astropy Patch available Fix from $1,9502024-03-18 CRITICAL 10.0 CVE-2024-28354 There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the … Tew 827dru Firmware Mitigation only Fix from $2,3002024-03-15 HIGH 8.8 CVE-2024-28353 There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the … Tew 827dru Firmware No fix yet Fix from $1,9502024-03-15 HIGH 8.8 CVE-2024-25228EPSS 26% Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in Manoeuv… Vinchin Backup And Recovery after 7.2 Fix from $1,9502024-03-14 HIGH 7.5 CVE-2024-26204 Outlook for Android Information Disclosure Vulnerability Outlook 4.2404.0+ Fix from $1,9502024-03-12 HIGH 7.3 CVE-2024-25998 An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation. Charx Sec 3000 Firmware 1.5.1+ Fix from $1,9502024-03-12 CRITICAL 9.1 CVE-2024-22127 SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially … Netweaver Application Server Java Mitigation only Fix from $2,3002024-03-12