Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2023-27232 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /setting/setWanIe… A7100ru Firmware No fix yet Fix from $2,3002023-03-28 CRITICAL 9.8 CVE-2023-27229 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at /setting/setWanIeCfg. A7100ru Firmware No fix yet Fix from $2,3002023-03-28 CRITICAL 9.8 CVE-2023-27231 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg. A7100ru Firmware No fix yet Fix from $2,3002023-03-28 CRITICAL 9.8 CVE-2023-28712 Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system access with www-data permissi… Osprey Pump Controller Firmware Mitigation only Fix from $2,3002023-03-28 HIGH 8.1 CVE-2023-28430 OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is triggered on issues (types: [clo… React Native Onesignal 4.5.1+ Fix from $1,9502023-03-27 HIGH 8.8 CVE-2023-26493 Cocos Engine is an open-source framework for building 2D & 3D real-time rendering and interactive content. In the github repo for Cocos Engine the `w… Cocos Engine 2023-02-20+ Fix from $1,9502023-03-27 HIGH 8.8 CVE-2023-1141 Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an attacker to inject a… Infrasuite Device Master 1.0.5+ Fix from $1,9502023-03-27 CRITICAL 9.8 CVE-2023-26801EPSS 70% LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command inje… Bl Lte300 Firmware No fix yet Fix from $2,3002023-03-26 HIGH 8.8 CVE-2023-27796 RG-EW1200G PRO Wireless Routers EW_3.0(1)B11P204, RG-EW1800GX PRO Wireless Routers EW_3.0(1)B11P204, and RG-EW3200GX PRO Wireless Routers EW_3.0(1)B1… Rg Ew1800gx Pro Firmware No fix yet Fix from $1,9502023-03-26 CRITICAL 9.8 CVE-2023-26800 Ruijie Networks RG-EW1200 Wireless Routers EW_3.0(1)B11P204 was discovered to contain a command injetion vulnerability via the params.path parameter … Rg Ew1200r Firmware No fix yet Fix from $2,3002023-03-26 CRITICAL 9.8 CVE-2023-1458 A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical. Affected by this vulnerability is an unknown funct… Edgerouter X Firmware No fix yet Fix from $2,3002023-03-25 CRITICAL 9.8 CVE-2023-1456 A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6. This issue affects some unknown processing… Edgerouter X Firmware Mitigation only Fix from $2,3002023-03-25 CRITICAL 9.8 CVE-2023-1457 A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6. Affected is an unknown function of the componen… Edgerouter X Firmware Mitigation only Fix from $2,3002023-03-25 CRITICAL 9.8 CVE-2023-23149 DEK-1705 <=Firmware:34.23.1 device was discovered to have a command execution vulnerability. Dek 1705 Firmware Mitigation only Fix from $2,3002023-03-24 MEDIUM 6.7 CVE-2023-20097 A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with … Wireless Lan Controller Software 8.10.183.0 / 16.12.8+ Fix from $1,6002023-03-23 CRITICAL 9.8 CVE-2022-28496 TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminus… Cp900 Firmware Mitigation only Fix from $2,3002023-03-23 CRITICAL 9.8 CVE-2022-28497 TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via th… Cp900 Firmware Mitigation only Fix from $2,3002023-03-23 CRITICAL 9.8 CVE-2023-27078 A command injection issue was found in TP-Link MR3020 v.1_150921 that allows a remote attacker to execute arbitrary commands via a crafted request to… Tl Mr3020 Firmware No fix yet Fix from $2,3002023-03-23 CRITICAL 9.8 CVE-2023-27135 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at /setting/setWanIeCfg. A7100ru Firmware No fix yet Fix from $2,3002023-03-23 HIGH 7.5 CVE-2023-27079 Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package G103 Firmware No fix yet Fix from $1,9502023-03-23 CRITICAL 9.8 CVE-2023-27224 An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file. Nginx Proxy Manager No fix yet Fix from $2,3002023-03-22 HIGH 8.8 CVE-2023-1168 An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerabi… Arubaos Cx 10.06.0240 / 10.10.1030+ Fix from $1,9502023-03-22 MEDIUM 5.5 CVE-2023-28425EPSS 55% Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX c… Redis 7.0.10+ Fix from $1,6002023-03-20 HIGH 8.1 CVE-2015-10096 A vulnerability, which was classified as critical, was found in Zarthus IRC Twitter Announcer Bot up to 1.1.0. This affects the function get_tweets o… Irc Twitter Announcer Bot Patch available Fix from $1,9502023-03-20 CRITICAL 9.9 CVE-2023-28110 Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP serv… Koko 2.28.8+ Fix from $2,3002023-03-16 HIGH 8.8 CVE-2022-4009 In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation Octopus Server 2022.2.8552 / 2022.3.10750+ Fix from $1,9502023-03-16 HIGH 7.2 CVE-2023-28460 A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted packet after logging into the a… Array Os after 10.4.2.58 Fix from $1,9502023-03-15 HIGH 8.8 CVE-2023-1389 KEVEPSS 100% TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cg… Archer Ax21 Firmware 1.1.4+ Fix from $1,9502023-03-15 HIGH 7.8 CVE-2023-24229EPSS 7% DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands v… Vigor2960 Firmware No fix yet Fix from $1,9502023-03-15 CRITICAL 9.8 CVE-2023-27240 Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip. Ax3 Firmware No fix yet Fix from $2,3002023-03-15