Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.9 CVE-2023-27407 A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate… Scalance Lpe9403 Firmware 2.1+ Fix from $2,3002023-05-09 HIGH 8.8 CVE-2023-22788 Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation … Arubaos 8.6.0.0+ Fix from $1,9502023-05-08 HIGH 8.8 CVE-2023-22789 Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation … Arubaos 8.6.0.0+ Fix from $1,9502023-05-08 HIGH 8.8 CVE-2023-22790 Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation … Arubaos 8.6.0.0+ Fix from $1,9502023-05-08 HIGH 8.8 CVE-2023-2573 Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which c… Eki 1521 Firmware after 1.21 Fix from $1,9502023-05-08 HIGH 8.8 CVE-2023-2574 Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which … Eki 1521 Firmware after 1.21 Fix from $1,9502023-05-08 CRITICAL 9.8 CVE-2023-30135 Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload functi… Ac18 Firmware Patch available Fix from $2,3002023-05-05 CRITICAL 9.8 CVE-2023-2520 A vulnerability was found in Caton Prime 2.1.2.51.e8d7225049(202303031001) and classified as critical. This issue affects some unknown processing of … Caton Prime Mitigation only Fix from $2,3002023-05-04 HIGH 7.3 CVE-2023-26125 Versions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially … Gin 1.9.0+ Fix from $1,9502023-05-04 HIGH 8.8 CVE-2023-32007EPSS 76% ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an aut… Spark after 3.2.1 Fix from $1,9502023-05-02 HIGH 7.2 CVE-2023-2377EPSS 8% A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The impacted element is an unknown function of the component Web Manageme… Er X Firmware 2.0.9+ Fix from $1,9502023-04-28 HIGH 7.2 CVE-2023-2378EPSS 8% A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown function of the component Web Management Interface. This… Er X Firmware 2.0.9+ Fix from $1,9502023-04-28 HIGH 7.2 CVE-2023-2376EPSS 8% A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The affected element is an unknown function of the componen… Er X Firmware 2.0.9+ Fix from $1,9502023-04-28 HIGH 7.2 CVE-2023-2374EPSS 7% A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This issue affects some unknown processing of the component Web Ma… Er X Firmware 2.0.9+ Fix from $1,9502023-04-28 HIGH 7.2 CVE-2023-2375EPSS 9% A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. Impacted is an unknown function of the component Web Management Interfa… Er X Firmware 2.0.9+ Fix from $1,9502023-04-28 HIGH 7.2 CVE-2023-2373EPSS 8% A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This vulnerability affects unknown code of the component Web Management… Edgemax Edgerouter Firmware 2.0.9+ Fix from $1,9502023-04-28 HIGH 7.2 CVE-2022-36769 IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed wit… Cloud Pak For Data Mitigation only Fix from $1,9502023-04-26 HIGH 8.8 CVE-2023-30623 `embano1/wip` is a GitHub Action written in Bash. Prior to version 2, the `embano1/wip` action uses the `github.event.pull_request.title` parameter … Wip 2.0.0+ Fix from $1,9502023-04-24 CRITICAL 9.8 CVE-2023-27848 broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. Broccoli Compass No fix yet Fix from $2,3002023-04-24 CRITICAL 9.8 CVE-2023-27849 rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. Rails Routes To Json No fix yet Fix from $2,3002023-04-24 CRITICAL 9.8 CVE-2023-29566 huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the ch… Dawnsparks Node Tesseract Patch available Fix from $2,3002023-04-24 HIGH 8.1 CVE-2023-22913 A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 throu… Usg Flex 100 Firmware after 5.35 Fix from $1,9502023-04-24 HIGH 7.2 CVE-2023-20865 VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operation… Aria Operations For Logs 8.12.0+ Fix from $1,9502023-04-20 HIGH 7.2 CVE-2023-29855 WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php. Wbce Cms No fix yet Fix from $1,9502023-04-18 CRITICAL 9.8 CVE-2022-46640 Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request. Nanoleaf Desktop 1.3.1+ Fix from $2,3002023-04-18 MEDIUM 6.7 CVE-2022-37704 Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/… Amanda Patch available Fix from $1,6002023-04-16 MEDIUM 6.5 CVE-2019-14944 An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection … GitLab 11.11.8 / 12.0.6+ Fix from $1,6002023-04-16 HIGH 8.8 CVE-2023-30535 Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake … Snowflake Jdbc 3.13.29+ Fix from $1,9502023-04-14 CRITICAL 9.8 CVE-2023-29800 TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile… X18 Firmware No fix yet Fix from $2,3002023-04-14 CRITICAL 9.8 CVE-2023-29801 TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parame… X18 Firmware No fix yet Fix from $2,3002023-04-14