Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.1 CVE-2023-51833 A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the … Tew 411brpplus Firmware No fix yet Fix from $1,9502024-01-25 CRITICAL 9.8 CVE-2023-7227 SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DD… Nvr 504 Firmware Mitigation only Fix from $2,3002024-01-25 CRITICAL 9.8 CVE-2024-22529 TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa. X2000r Firmware No fix yet Fix from $2,3002024-01-25 CRITICAL 9.8 CVE-2024-22729EPSS 71% NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page. Mw5360 Firmware No fix yet Fix from $2,3002024-01-25 CRITICAL 9.8 CVE-2023-52038 An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function. X6000r Firmware No fix yet Fix from $2,3002024-01-24 CRITICAL 9.8 CVE-2023-52039 An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function. X6000r Firmware No fix yet Fix from $2,3002024-01-24 CRITICAL 9.8 CVE-2023-52040 An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function. X6000r Firmware No fix yet Fix from $2,3002024-01-24 CRITICAL 9.8 CVE-2023-51887 Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL. Mathtex after 1.05 Fix from $2,3002024-01-24 CRITICAL 9.8 CVE-2024-22651EPSS 20% There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04. Dir 815 Firmware after 1.04 Fix from $2,3002024-01-24 HIGH 7.8 CVE-2023-50274 HPE OneView may allow command injection with local privilege escalation. Oneview 8.70+ Fix from $1,9502024-01-23 CRITICAL 9.8 CVE-2024-22663 TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg A3700r Firmware No fix yet Fix from $2,3002024-01-23 HIGH 7.8 CVE-2023-24135 Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the function formWriteFacMac. This … Eagle 1200ac Firmware No fix yet Fix from $1,9502024-01-22 HIGH 7.2 CVE-2024-20287 A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point Setup could al… Wap371 Firmware Mitigation only Fix from $1,9502024-01-17 CRITICAL 9.8 CVE-2023-52042 An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parame… X6000r Firmware No fix yet Fix from $2,3002024-01-16 HIGH 8.8 CVE-2024-0507EPSS 66% An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability… Enterprise Server 3.8.13 / 3.9.8+ Fix from $1,9502024-01-16 CRITICAL 9.8 CVE-2024-0579 A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDe… X2000r Firmware Mitigation only Fix from $2,3002024-01-16 HIGH 7.2 CVE-2023-4797 The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell com… Newsletters 4.9.3+ Fix from $1,9502024-01-16 HIGH 7.8 CVE-2023-42136 PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system … Paydroid after 8.1.0_sagittarius_11.1.50_20230614 Fix from $1,9502024-01-15 CRITICAL 9.1 CVE-2024-21887 KEVEPSS 100% A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticate… Connect Secure Mitigation only Fix from $2,3002024-01-12 HIGH 8.8 CVE-2024-22198 Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. Th… Nginx Ui 2.0.0+ Fix from $1,9502024-01-11 HIGH 8.8 CVE-2024-22197 Nginx-ui is online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Prefere… Nginx Ui 2.0.0+ Fix from $1,9502024-01-11 CRITICAL 9.8 CVE-2023-6634EPSS 9% The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. Th… Learnpress after 4.2.5.7 Fix from $2,3002024-01-11 CRITICAL 9.8 CVE-2023-52027 TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function. A3700r Firmware No fix yet Fix from $2,3002024-01-11 CRITICAL 9.8 CVE-2023-51126EPSS 31% Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOT… Flir Ax8 Firmware after 1.46.16 Fix from $2,3002024-01-10 CRITICAL 9.8 CVE-2023-51972 Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp. Ax1803 Firmware No fix yet Fix from $2,3002024-01-10 CRITICAL 9.8 CVE-2023-31446EPSS 61% In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads… Xc1000 Firmware No fix yet Fix from $2,3002024-01-10 HIGH 8.0 CVE-2024-20676 Azure Storage Mover Remote Code Execution Vulnerability Azure Storage Mover 3.0.430+ Fix from $1,9502024-01-09 CRITICAL 9.8 CVE-2023-49237EPSS 19% An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to u… Tv Ip1314pi Firmware No fix yet Fix from $2,3002024-01-09 HIGH 8.8 CVE-2024-21663 Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is… Discord Recon 0.0.8+ Fix from $1,9502024-01-09 HIGH 8.8 CVE-2024-0291 A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function UploadFirmwareFi… Lr1200gb Firmware No fix yet Fix from $1,9502024-01-08