Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2023-2868 KEVEPSS 87% A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3… Email Security Gateway 300 Firmware after 9.2.0.006 Fix from $2,3002023-05-24 HIGH 7.2 CVE-2023-31740 There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, … E2000 Firmware No fix yet Fix from $1,9502023-05-23 HIGH 7.2 CVE-2023-31741 There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, … E2000 Firmware No fix yet Fix from $1,9502023-05-23 HIGH 8.8 CVE-2023-31996 Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Command Injection due to improper sanitization of special characters for the NAS storage test fu… Ane L6012r Firmware 1.41.03+ Fix from $1,9502023-05-23 HIGH 7.2 CVE-2023-31742EPSS 9% There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privi… Wrt54gl Firmware No fix yet Fix from $1,9502023-05-22 CRITICAL 9.8 CVE-2023-33294 An issue was discovered in KaiOS 3.0 before 3.1. The /system/bin/tctweb_server binary exposes a local web server that responds to GET and POST reques… Kaios No fix yet Fix from $2,3002023-05-22 HIGH 8.8 CVE-2023-33235 MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH CLI program, which can be ex… Mxsecurity Patch available Fix from $1,9502023-05-22 HIGH 7.8 CVE-2023-32700 LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because lu… Luatex 1.16.2 / 23.5+ Fix from $1,9502023-05-20 CRITICAL 9.8 CVE-2023-31729 TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi. A3300r Firmware Mitigation only Fix from $2,3002023-05-18 HIGH 7.8 CVE-2023-2491 A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el ca… Enterprise Linux Mitigation only Fix from $1,9502023-05-17 HIGH 8.8 CVE-2023-31700 TP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceAdd. Tl Wpa4530 Kit Firmware No fix yet Fix from $1,9502023-05-17 HIGH 8.8 CVE-2023-31701 TP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceRemove. Tl Wpa4530 Kit Firmware No fix yet Fix from $1,9502023-05-17 HIGH 8.8 CVE-2023-31208 Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary live… Checkmk 2.0.0+ Fix from $1,9502023-05-17 CRITICAL 9.8 CVE-2023-31856 A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers … Cp300\+ Firmware No fix yet Fix from $2,3002023-05-16 CRITICAL 9.8 CVE-2023-31986EPSS 8% A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN funct… Br 6428ns Firmware No fix yet Fix from $2,3002023-05-15 CRITICAL 9.8 CVE-2023-31983EPSS 25% A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function … Br 6428ns Firmware No fix yet Fix from $2,3002023-05-12 HIGH 8.8 CVE-2023-32073EPSS 6% WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.j… Avideo after 12.4 Fix from $1,9502023-05-12 MEDIUM 6.3 CVE-2023-2682 A vulnerability was found in Caton Live up to 2023-04-26 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/… Caton Live after 2023-04-26 Fix from $1,6002023-05-12 CRITICAL 9.8 CVE-2023-31985EPSS 8% A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept f… Br 6428ns Firmware No fix yet Fix from $2,3002023-05-12 HIGH 8.8 CVE-2023-31528 Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the staticroute_list parameter. Cx2l Firmware No fix yet Fix from $1,9502023-05-11 HIGH 8.8 CVE-2023-31529 Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the system_time_timezone parameter. Cx2l Firmware No fix yet Fix from $1,9502023-05-11 HIGH 8.8 CVE-2023-31530 Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter. Cx2l Firmware No fix yet Fix from $1,9502023-05-11 HIGH 8.8 CVE-2023-31531 Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter. Cx2l Firmware No fix yet Fix from $1,9502023-05-11 CRITICAL 9.8 CVE-2023-24540 Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character s… Go 1.19.9 / 1.20.4+ Fix from $2,3002023-05-11 HIGH 8.8 CVE-2023-2647EPSS 7% A vulnerability was found in Weaver E-Office 9.5 and classified as critical. Affected by this issue is some unknown functionality of the file /webroo… E Office No fix yet Fix from $1,9502023-05-11 HIGH 8.8 CVE-2023-2649EPSS 10% A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unknown code of the file /bin/at… Ac23 Firmware No fix yet Fix from $1,9502023-05-11 CRITICAL 9.8 CVE-2022-29842 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the… My Cloud Os 5.26.119+ Fix from $2,3002023-05-10 CRITICAL 9.8 CVE-2023-30353 Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document. Cp3 Firmware Mitigation only Fix from $2,3002023-05-10 HIGH 7.5 CVE-2023-31476 An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almo… Gl Mv1000w Firmware after 3.215 Fix from $1,9502023-05-09 HIGH 7.2 CVE-2023-28832 A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2… 6gk1411 1ac00 Firmware Patch available Fix from $1,9502023-05-09