Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2023-47560 An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute… Qumagie Mitigation only Fix from $1,9502024-01-05 CRITICAL 9.8 CVE-2023-51812 Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList. Ax3 Firmware No fix yet Fix from $2,3002024-01-04 HIGH 8.8 CVE-2023-52137 The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames,… Verify Changed Files 17.0.0+ Fix from $1,9502023-12-29 HIGH 7.8 CVE-2023-50445EPSS 9% Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N… Gl Mt1300 Firmware No fix yet Fix from $1,9502023-12-28 CRITICAL 9.8 CVE-2023-51664 tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows fo… Changed Files 41.0.0+ Fix from $2,3002023-12-27 HIGH 7.2 CVE-2023-49226 An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users w… Balance Two Firmware 8.4.0+ Fix from $1,9502023-12-25 CRITICAL 9.8 CVE-2023-51014 TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig in… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51016 TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51025 TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCf… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51707 MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffe… Arrayos Ag 9.4.0.505+ Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-50989 Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function. I29 Firmware Mitigation only Fix from $2,3002023-12-20 CRITICAL 9.8 CVE-2023-50983 Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function. I29 Firmware Mitigation only Fix from $2,3002023-12-20 HIGH 8.8 CVE-2023-6940 with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system. Mlflow 2.9.2+ Fix from $1,9502023-12-19 HIGH 7.2 CVE-2023-39509 A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands o… Cpp13 Firmware after 8.90 Fix from $1,9502023-12-18 CRITICAL 9.8 CVE-2023-6848 A vulnerability was found in kalcaddle kodbox up to 1.48. It has been declared as critical. Affected by this vulnerability is the function check of t… Kodbox 1.48.04+ Fix from $2,3002023-12-16 CRITICAL 9.8 CVE-2023-50089 A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs dur… Wnr2000 Firmware No fix yet Fix from $2,3002023-12-15 CRITICAL 9.8 CVE-2023-50917EPSS 38% MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majo… Majordomo 2023-11-15+ Fix from $2,3002023-12-15 HIGH 7.2 CVE-2023-49898 In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of … Streampark 2.1.2+ Fix from $1,9502023-12-15 HIGH 8.1 CVE-2023-6572 Command Injection in GitHub repository gradio-app/gradio prior to main. Gradio 4.14.0+ Fix from $1,9502023-12-14 HIGH 8.8 CVE-2023-25643 There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters,… Mc801a Firmware Mitigation only Fix from $1,9502023-12-14 HIGH 7.2 CVE-2023-48702 Jellyfin is a system for managing and streaming media. Prior to version 10.8.13, the `/System/MediaEncoder/Path` endpoint executes an arbitrary file … Jellyfin 10.8.13+ Fix from $1,9502023-12-13 HIGH 8.8 CVE-2023-48791 An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7… Fortiportal after 7.0.6 Fix from $1,9502023-12-13 HIGH 8.8 CVE-2023-47576 An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web interface. Rely Pcie Firmware Mitigation only Fix from $1,9502023-12-13 CRITICAL 9.8 CVE-2013-2513 The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file. Flash Tool after 0.6.0 Fix from $2,3002023-12-12 MEDIUM 6.4 CVE-2023-49587 SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of sam… Solution Manager Mitigation only Fix from $1,6002023-12-12 CRITICAL 9.8 CVE-2023-40301 NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability. Ngeniuspulse Mitigation only Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-49431 Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName. Ax9 Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-49435 Tenda AX9 V22.03.01.46 is vulnerable to command injection. Ax9 Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-49436 Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList. Ax9 Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-49428 Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName. Ax12 Firmware No fix yet Fix from $2,3002023-12-07