Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2023-51833
A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the …
Tew 411brpplus Firmware
No fix yet
CRITICAL 9.8
CVE-2023-7227
SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DD…
Nvr 504 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-22529
TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.
X2000r Firmware
No fix yet
CRITICAL 9.8
CVE-2024-22729EPSS 71%
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.
Mw5360 Firmware
No fix yet
CRITICAL 9.8
CVE-2023-52038
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.
X6000r Firmware
No fix yet
CRITICAL 9.8
CVE-2023-52039
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.
X6000r Firmware
No fix yet
CRITICAL 9.8
CVE-2023-52040
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.
X6000r Firmware
No fix yet
CRITICAL 9.8
CVE-2023-51887
Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.
Mathtex
after 1.05
CRITICAL 9.8
CVE-2024-22651EPSS 20%
There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.
Dir 815 Firmware
after 1.04
HIGH 7.8
CVE-2023-50274
HPE OneView may allow command injection with local privilege escalation.
Oneview
8.70+
CRITICAL 9.8
CVE-2024-22663
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg
A3700r Firmware
No fix yet
HIGH 7.8
CVE-2023-24135
Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the function formWriteFacMac. This …
Eagle 1200ac Firmware
No fix yet
HIGH 7.2
CVE-2024-20287
A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point Setup could al…
Wap371 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-52042
An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parame…
X6000r Firmware
No fix yet
HIGH 8.8
CVE-2024-0507EPSS 66%
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability…
Enterprise Server
3.8.13 / 3.9.8+
CRITICAL 9.8
CVE-2024-0579
A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDe…
X2000r Firmware
Mitigation only
HIGH 7.2
CVE-2023-4797
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell com…
Newsletters
4.9.3+
HIGH 7.8
CVE-2023-42136
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system …
Paydroid
after 8.1.0_sagittarius_11.1.50_20230614
CRITICAL 9.1
CVE-2024-21887 KEVEPSS 100%
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticate…
Connect Secure
Mitigation only
HIGH 8.8
CVE-2024-22198
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. Th…
Nginx Ui
2.0.0+
HIGH 8.8
CVE-2024-22197
Nginx-ui is online statistics for Server Indicators Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Prefere…
Nginx Ui
2.0.0+
CRITICAL 9.8
CVE-2023-6634EPSS 9%
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. Th…
Learnpress
after 4.2.5.7
CRITICAL 9.8
CVE-2023-52027
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.
A3700r Firmware
No fix yet
CRITICAL 9.8
CVE-2023-51126EPSS 31%
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOT…
Flir Ax8 Firmware
after 1.46.16
CRITICAL 9.8
CVE-2023-51972
Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.
Ax1803 Firmware
No fix yet
CRITICAL 9.8
CVE-2023-31446EPSS 61%
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads…
Xc1000 Firmware
No fix yet
HIGH 8.0
CVE-2024-20676
Azure Storage Mover Remote Code Execution Vulnerability
Azure Storage Mover
3.0.430+
CRITICAL 9.8
CVE-2023-49237EPSS 19%
An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to u…
Tv Ip1314pi Firmware
No fix yet
HIGH 8.8
CVE-2024-21663
Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is…
Discord Recon
0.0.8+
HIGH 8.8
CVE-2024-0291
A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function UploadFirmwareFi…
Lr1200gb Firmware
No fix yet