Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2023-46412 TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_41D998 function. X6000r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46413 TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_4155DC function. X6000r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46414 TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function. X6000r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46415 TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function. X6000r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46416 TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function. X6000r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46417 TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function. X6000r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46418 TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_412688 function. X6000r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46419 TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415730 function. X6000r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46420 TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41590C function. X6000r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46421 TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411D00 function. X6000r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46422 TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411994 function. X6000r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46423 TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_417094 function. X6000r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46424 TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_422BD4 function. X6000r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46574EPSS 65% An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwar… A3700r Firmware No fix yet Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-46370EPSS 18% Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function. W18e Firmware No fix yet Fix from $2,3002023-10-25 MEDIUM 6.3 CVE-2023-43510 A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the und… Clearpass Policy Manager 6.9.13 / 6.10.8+ Fix from $1,6002023-10-25 HIGH 8.8 CVE-2023-38193 An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line. Superwebmailer No fix yet Fix from $1,9502023-10-21 HIGH 7.2 CVE-2023-21413 GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis … Axis Os 10.12.199 / 11.6.94+ Fix from $1,9502023-10-16 CRITICAL 9.8 CVE-2023-36953 TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection. Cp300\+ Firmware No fix yet Fix from $2,3002023-10-16 CRITICAL 9.8 CVE-2023-36954 TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection. Cp300\+ Firmware No fix yet Fix from $2,3002023-10-16 CRITICAL 9.8 CVE-2023-26155 All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt() fails to sanitize its param… Node Qpdf No fix yet Fix from $2,3002023-10-14 CRITICAL 9.8 CVE-2023-45852EPSS 14% In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell m… Vitogate 300 Firmware after 2.1.3.0 Fix from $2,3002023-10-14 CRITICAL 9.8 CVE-2023-45465 Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settings. N3m Firmware No fix yet Fix from $2,3002023-10-13 CRITICAL 9.8 CVE-2023-45466 Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS Settings. N3mv2 Firmware No fix yet Fix from $2,3002023-10-13 CRITICAL 9.8 CVE-2023-32632 A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network r… Yf325 Firmware Mitigation only Fix from $2,3002023-10-11 HIGH 7.2 CVE-2023-26319 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. Xiaomi Router Ax3200 Firmware 2023.2+ Fix from $1,9502023-10-11 HIGH 8.1 CVE-2023-26320 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. Xiaomi Router Ax3200 Firmware 2023.2+ Fix from $1,9502023-10-11 HIGH 8.8 CVE-2023-36414 Azure Identity SDK Remote Code Execution Vulnerability Azure Identity Sdk 1.10.2+ Fix from $1,9502023-10-10 HIGH 8.8 CVE-2023-36415 Azure Identity SDK Remote Code Execution Vulnerability Azure Identity Sdk 1.10.2 / 1.14.1+ Fix from $1,9502023-10-10 HIGH 8.8 CVE-2023-45208 A command injection in the parsing_xml_stasurvey function inside libcgifunc.so of the D-Link DAP-X1860 repeater 1.00 through 1.01b05-01 allows attack… Dap 1860 Firmware No fix yet Fix from $1,9502023-10-10