Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2024-2352 A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDe… 1panel 1.10.2-lts+ Fix from $2,3002024-03-10 HIGH 8.0 CVE-2024-25951 A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system. Idrac8 2.85.85.85+ Fix from $1,9502024-03-09 HIGH 7.8 CVE-2024-23247 The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Process… macOS 12.7.4 / 13.6.5+ Fix from $1,9502024-03-08 HIGH 7.8 CVE-2024-0817 Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0 Paddlepaddle No fix yet Fix from $1,9502024-03-07 HIGH 7.2 CVE-2024-25612 Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result … Arubaos 8.10.0.10 / 8.11.2.1+ Fix from $1,9502024-03-05 HIGH 7.2 CVE-2024-25613 Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result … Arubaos 8.10.0.10 / 8.11.2.1+ Fix from $1,9502024-03-05 HIGH 7.2 CVE-2024-1356 Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result … Arubaos after 10.5.0.1 Fix from $1,9502024-03-05 HIGH 7.2 CVE-2024-25611 Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result … Arubaos 8.10.0.10 / 8.11.2.1+ Fix from $1,9502024-03-05 MEDIUM 6.8 CVE-2023-51835EPSS 7% An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping in the /boafrm/formSystemChe… Tew 822dre Firmware No fix yet Fix from $1,6002024-02-29 HIGH 8.8 CVE-2024-26295 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.13 / 6.10.8+ Fix from $1,9502024-02-27 HIGH 8.8 CVE-2024-26296 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.13 / 6.10.8+ Fix from $1,9502024-02-27 HIGH 8.8 CVE-2024-26297 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.13 / 6.10.8+ Fix from $1,9502024-02-27 HIGH 8.8 CVE-2024-26298 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.13 / 6.10.8+ Fix from $1,9502024-02-27 HIGH 8.8 CVE-2024-26294 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.13 / 6.10.8+ Fix from $1,9502024-02-27 HIGH 8.0 CVE-2024-22544EPSS 9% An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTim… E1700 Firmware No fix yet Fix from $1,9502024-02-27 MEDIUM 6.5 CVE-2024-25082 Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. Debian Linux after 20230101 Fix from $1,6002024-02-26 CRITICAL 9.8 CVE-2023-49959 In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers… Profinet Inspektor Nt 2.4.1+ Fix from $2,3002024-02-26 CRITICAL 9.8 CVE-2024-1781EPSS 15% A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg… X6000r Firmware No fix yet Fix from $2,3002024-02-23 CRITICAL 9.8 CVE-2024-25850EPSS 19% Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter Wf2780 Firmware No fix yet Fix from $2,3002024-02-22 HIGH 8.8 CVE-2023-24330 Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST… Dir 882 Firmware No fix yet Fix from $1,9502024-02-21 CRITICAL 9.8 CVE-2023-24331 Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlA… Dir 816 Firmware No fix yet Fix from $2,3002024-02-21 HIGH 7.8 CVE-2024-23346 Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesF… Pymatgen 2024.2.20+ Fix from $1,9502024-02-21 CRITICAL 9.8 CVE-2024-24377 An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script. Idocview after 14.1.3_20231228 Fix from $2,3002024-02-16 HIGH 8.8 CVE-2024-24301 Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid crede… Eap 767 Firmware No fix yet Fix from $1,9502024-02-14 HIGH 8.7 CVE-2024-22093 When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-blad… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,9502024-02-14 CRITICAL 9.1 CVE-2024-1369 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $2,3002024-02-13 CRITICAL 9.1 CVE-2024-1372 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $2,3002024-02-13 CRITICAL 9.1 CVE-2024-1374 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $2,3002024-02-13 CRITICAL 9.1 CVE-2024-1378 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $2,3002024-02-13 HIGH 8.0 CVE-2024-1354 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $1,9502024-02-13