Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2023-23080 Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<… It7 Lcs Firmware after 20220906024_2025 Fix from $2,3002023-02-27 CRITICAL 9.8 CVE-2023-26602EPSS 17% ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snm… Asmb8 Ikvm Firmware after 1.14.51 Fix from $2,3002023-02-26 HIGH 8.8 CVE-2023-23294 Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter t… Jetwave 2212g Firmware 1.5 / 1.6+ Fix from $1,9502023-02-23 HIGH 8.8 CVE-2023-23295 Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the… Jetwave 2212g Firmware 1.5 / 1.6+ Fix from $1,9502023-02-23 HIGH 8.8 CVE-2023-23917 A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can c… Rocket.chat 5.2.0+ Fix from $1,9502023-02-23 HIGH 8.8 CVE-2022-45600 Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in … Wmb250ac Firmware No fix yet Fix from $1,9502023-02-22 CRITICAL 9.8 CVE-2023-24184 TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability. A7100ru Firmware Mitigation only Fix from $2,3002023-02-21 HIGH 7.3 CVE-2022-48338 An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. … Emacs after 28.2 Fix from $1,9502023-02-20 CRITICAL 9.8 CVE-2023-25805 versionn, software for changing version information across multiple files, has a command injection vulnerability in all versions prior to version 1.1… Versionn 1.1.0+ Fix from $2,3002023-02-20 CRITICAL 9.8 CVE-2022-40021 QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vulnerability. Amino A140 Firmware 1.0.0-283+ Fix from $2,3002023-02-17 HIGH 8.8 CVE-2022-45701EPSS 42% Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature. Arris Tg2482a Firmware after 9.1.103 Fix from $1,9502023-02-17 CRITICAL 9.8 CVE-2023-24238 TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRu… A7100ru Firmware No fix yet Fix from $2,3002023-02-16 CRITICAL 9.8 CVE-2023-24236 TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDh… A7100ru Firmware No fix yet Fix from $2,3002023-02-16 HIGH 8.8 CVE-2023-0861EPSS 29% NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authe… Netmodule Router Software 4.3.0.119 / 4.4.0.118+ Fix from $1,9502023-02-16 CRITICAL 9.8 CVE-2023-0849 A vulnerability has been found in Netgear WNDR3700v2 1.0.1.14 and classified as critical. This vulnerability affects unknown code of the component We… Wndr3700 Firmware Mitigation only Fix from $2,3002023-02-15 HIGH 8.0 CVE-2023-21778 Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability Dynamics 365 4.2.0.51+ Fix from $1,9502023-02-14 HIGH 7.8 CVE-2023-21805 Windows MSHTML Platform Remote Code Execution Vulnerability Windows 10 10.0.10240.19747 / 10.0.14393.5717+ Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-22935 In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass S… Splunk 8.1.13 / 8.2.10+ Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-0830EPSS 21% A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation lead… Easynas No fix yet Fix from $1,9502023-02-14 CRITICAL 9.8 CVE-2023-24159 TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function. Ca300 Poe Firmware No fix yet Fix from $2,3002023-02-14 CRITICAL 9.8 CVE-2023-24160 TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function. Ca300 Poe Firmware No fix yet Fix from $2,3002023-02-14 CRITICAL 9.8 CVE-2023-24161 TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function. Ca300 Poe Firmware No fix yet Fix from $2,3002023-02-14 CRITICAL 9.8 CVE-2022-40022EPSS 92% Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability. Syncserver S650 Firmware No fix yet Fix from $2,3002023-02-13 CRITICAL 9.8 CVE-2023-0789 Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11. Phpmyfaq 3.1.11+ Fix from $2,3002023-02-12 HIGH 7.8 CVE-2023-0127 A command injection vulnerability in the firmware_update command, in the device's restricted telnet interface, allows an authenticated attacker to ex… Dwl 2600ap Firmware No fix yet Fix from $1,9502023-02-11 CRITICAL 10.0 CVE-2023-0776 Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell co… Neutrino 430 Firmware Patch available Fix from $2,3002023-02-11 HIGH 8.8 CVE-2022-45104 Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low priv… Evasa Provider Virtual Appliance 9.2.3.6 / 9.2.4.15+ Fix from $1,9502023-02-11 CRITICAL 9.8 CVE-2022-43550 A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which cou… Jitsi 2022-09-14+ Fix from $2,3002023-02-09 CRITICAL 9.8 CVE-2021-31573 In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a p… En7580 Firmware Mitigation only Fix from $2,3002023-02-06 CRITICAL 9.8 CVE-2021-31574 In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a p… En7580 Firmware Mitigation only Fix from $2,3002023-02-06