Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.1 CVE-2024-1355 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $2,3002024-02-13 CRITICAL 9.1 CVE-2024-1359 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $2,3002024-02-13 HIGH 7.5 CVE-2024-20667 Azure DevOps Server Remote Code Execution Vulnerability Azure Devops Server Patch available Fix from $1,9502024-02-13 HIGH 8.3 CVE-2023-47218EPSS 90% An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… Qts 5.1.5.2645+ Fix from $1,9502024-02-13 HIGH 7.8 CVE-2024-23749 KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and v… Kitty after 0.76.1.13 Fix from $1,9502024-02-09 CRITICAL 9.8 CVE-2023-49716 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote co… Gc370xa Firmware Mitigation only Fix from $2,3002024-02-09 CRITICAL 9.8 CVE-2023-46687 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root co… Gc370xa Firmware Mitigation only Fix from $2,3002024-02-09 HIGH 8.8 CVE-2023-40263 An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp. Openscape Voice Trace Manager Mitigation only Fix from $1,9502024-02-08 CRITICAL 9.8 CVE-2024-24321 An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 fun… Dir 816 Firmware Mitigation only Fix from $2,3002024-02-08 CRITICAL 9.8 CVE-2024-24216 Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/rep… Zentao after 18.10 Fix from $2,3002024-02-08 CRITICAL 9.8 CVE-2024-23049 An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component. Symphony after 3.6.3 Fix from $2,3002024-02-05 HIGH 7.2 CVE-2024-22107 An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React… Gtb Central Console No fix yet Fix from $1,9502024-02-02 HIGH 8.8 CVE-2023-47562 An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to e… Photo Station 6.4.2+ Fix from $1,9502024-02-02 HIGH 7.2 CVE-2023-41281 An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… Qts Mitigation only Fix from $1,9502024-02-02 HIGH 7.2 CVE-2023-41282 An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… Qts Mitigation only Fix from $1,9502024-02-02 HIGH 7.2 CVE-2023-41283 An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… Qts Mitigation only Fix from $1,9502024-02-02 CRITICAL 9.8 CVE-2023-45025 An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… Qts Mitigation only Fix from $2,3002024-02-02 HIGH 8.8 CVE-2024-22900 Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo functi… Vinchin Backup And Recovery after 7.2 Fix from $1,9502024-02-02 HIGH 8.8 CVE-2024-22903 Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function. Vinchin Backup And Recovery after 7.2 Fix from $1,9502024-02-02 HIGH 7.8 CVE-2024-0325 In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.   Helix Sync 2024.1+ Fix from $1,9502024-02-01 CRITICAL 9.8 CVE-2024-23745 In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary commands. Addit… Web Clipper No fix yet Fix from $2,3002024-01-31 CRITICAL 9.8 CVE-2024-21488 Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without inpu… Network 0.7.0+ Fix from $2,3002024-01-30 HIGH 7.2 CVE-2024-0919EPSS 23% A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical. This affects the function do_setNTP of the component PO… Tew 815dap Firmware No fix yet Fix from $1,9502024-01-26 HIGH 7.2 CVE-2024-0920EPSS 9% A vulnerability was found in TRENDnet TEW-822DRE 1.03B02. It has been declared as critical. This vulnerability affects unknown code of the file /admi… Tew 822dre Firmware No fix yet Fix from $1,9502024-01-26 HIGH 7.8 CVE-2024-22545 An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntp.server … Tew 824dru Firmware No fix yet Fix from $1,9502024-01-26 HIGH 8.8 CVE-2024-23627 A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vuln… Mr2600 Firmware Mitigation only Fix from $1,9502024-01-26 HIGH 8.8 CVE-2024-23628 A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vu… Mr2600 Firmware Mitigation only Fix from $1,9502024-01-26 CRITICAL 9.8 CVE-2024-23624EPSS 26% A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerabilit… Dap 1650 Firmware Mitigation only Fix from $2,3002024-01-26 CRITICAL 9.8 CVE-2024-23625EPSS 23% A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit th… Dap 1650 Firmware Mitigation only Fix from $2,3002024-01-26 HIGH 8.8 CVE-2024-23626 A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerabili… Mr2600 Firmware Mitigation only Fix from $1,9502024-01-26