Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2023-34233 The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard op… Snowflake Connector 3.0.2+ Fix from $1,9502023-06-08 HIGH 8.8 CVE-2023-34231 gosnowflake is th Snowflake Golang driver. Prior to version 1.6.19, a command injection vulnerability exists in the Snowflake Golang driver via singl… Gosnowflake 1.6.19+ Fix from $1,9502023-06-08 CRITICAL 9.8 CVE-2023-33556 TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg. A7100ru Firmware No fix yet Fix from $2,3002023-06-07 CRITICAL 9.8 CVE-2023-20887 KEVEPSS 98% Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks… Aria Operations For Networks after 6.10.0 Fix from $2,3002023-06-07 HIGH 7.5 CVE-2023-20889EPSS 79% Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Ne… Vrealize Network Insight after 6.10.0 Fix from $1,9502023-06-07 HIGH 8.8 CVE-2023-33538 KEVEPSS 42% TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm… Tl Wr940n Firmware Mitigation only Fix from $1,9502023-06-07 CRITICAL 9.8 CVE-2023-30400 An issue was discovered in Anyka Microelectronics AK3918EV300 MCU v18. A command injection vulnerability in the network configuration script within t… Ak3918ev300 Firmware No fix yet Fix from $2,3002023-06-07 HIGH 8.8 CVE-2023-33782EPSS 37% D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function. Dir 842v2 Firmware Mitigation only Fix from $1,9502023-06-07 HIGH 7.8 CVE-2022-25834 In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected command sh… Xtrabackup after 8.0.27-19 Fix from $1,9502023-06-07 CRITICAL 9.8 CVE-2023-34111 The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerability which allows for arbitrary… Grafana after 2023-05-22 Fix from $2,3002023-06-06 CRITICAL 9.8 CVE-2023-31569 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function. X5000r Firmware Mitigation only Fix from $2,3002023-06-06 CRITICAL 9.8 CVE-2023-33532EPSS 16% There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges… R6250 Firmware Mitigation only Fix from $2,3002023-06-06 HIGH 8.8 CVE-2023-33533 Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Ver… D6220 Firmware No fix yet Fix from $1,9502023-06-06 HIGH 8.8 CVE-2023-33530 There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web managemen… G103 Firmware Mitigation only Fix from $1,9502023-06-06 CRITICAL 9.8 CVE-2023-0636 Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S302… Aspect Ent 2 Firmware 3.07.01+ Fix from $2,3002023-06-05 CRITICAL 9.8 CVE-2023-23952 Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability. Advanced Secure Gateway 3.1.6.0 / 7.3.13.1+ Fix from $2,3002023-06-01 HIGH 8.8 CVE-2023-33722 EDIMAX BR-6288ACL v1.12 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the pppUserName parameter. Br 6288acl Firmware No fix yet Fix from $1,9502023-05-31 CRITICAL 9.8 CVE-2023-33486 TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allow… X5000r Firmware No fix yet Fix from $2,3002023-05-31 CRITICAL 9.8 CVE-2023-33487 TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability al… X5000r Firmware No fix yet Fix from $2,3002023-05-31 HIGH 7.8 CVE-2023-34153 A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format opt… Fedora 7.1.1-11+ Fix from $1,9502023-05-30 MEDIUM 5.5 CVE-2022-47028 An issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of service via arbitary data injection to function inse… Action Launcher No fix yet Fix from $1,6002023-05-30 MEDIUM 6.8 CVE-2022-46361 An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system com… Onewireless Network Wireless Device Manager Firmware Mitigation only Fix from $1,6002023-05-30 HIGH 8.8 CVE-2023-26130 Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type … Cpp Httplib 0.12.4+ Fix from $1,9502023-05-30 HIGH 7.2 CVE-2022-24630EPSS 24% An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_comm… Device Manager Express after 7.8.20002.47752 Fix from $1,9502023-05-29 MEDIUM 5.9 CVE-2020-29547 An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP … Webcit after 926 Fix from $1,6002023-05-29 CRITICAL 9.8 CVE-2015-20108 xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used. Ruby Saml 1.0.0+ Fix from $2,3002023-05-27 HIGH 7.8 CVE-2023-26127 All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function. **Note:** … N158 Mitigation only Fix from $1,9502023-05-27 HIGH 7.8 CVE-2023-26128 All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes be… Keep Module Latest No fix yet Fix from $1,9502023-05-27 HIGH 7.8 CVE-2023-26129 All versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check' function in the bwm-ng.js fi… Bwm Ng No fix yet Fix from $1,9502023-05-27 HIGH 7.2 CVE-2023-31460 A vulnerability in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier could allow an authenticated attacker w… Mivoice Connect after 9.6.2208.101 Fix from $1,9502023-05-24