Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Openbi CRITICAL 9.8
CVE-2024-1115

A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function dlfile of the file /application/websocket…

Fix: after 1.0.8
Fix from $2,300 2024-01-31
A3300r Firmware CRITICAL 9.8
CVE-2024-24325

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules …

No fix yet
Fix from $2,300 2024-01-30
A3300r Firmware CRITICAL 9.8
CVE-2024-24326

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpR…

No fix yet
Fix from $2,300 2024-01-30
A3300r Firmware CRITICAL 9.8
CVE-2024-24327

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg fun…

No fix yet
Fix from $2,300 2024-01-30
A3300r Firmware CRITICAL 9.8
CVE-2024-24328EPSS 6%

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules…

No fix yet
Fix from $2,300 2024-01-30
A3300r Firmware CRITICAL 9.8
CVE-2024-24329EPSS 6%

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRul…

No fix yet
Fix from $2,300 2024-01-30
A3300r Firmware CRITICAL 9.8
CVE-2024-24330

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemote…

No fix yet
Fix from $2,300 2024-01-30
A3300r Firmware CRITICAL 9.8
CVE-2024-24331

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCf…

No fix yet
Fix from $2,300 2024-01-30
A3300r Firmware CRITICAL 9.8
CVE-2024-24332

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules fu…

No fix yet
Fix from $2,300 2024-01-30
A3300r Firmware CRITICAL 9.8
CVE-2024-24333

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules fun…

No fix yet
Fix from $2,300 2024-01-30
Nas326 Firmware HIGH 7.2
CVE-2023-5372EPSS 28%

The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and NAS542 firmware versions throu…

Fix: 5.21+
Fix from $1,950 2024-01-30
Ls210d Firmware HIGH 7.2
CVE-2023-49038

Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as…

No fix yet
Fix from $1,950 2024-01-29
Pbx CRITICAL 9.8
CVE-2024-0986EPSS 58%

A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php?menu…

No fix yet
Fix from $2,300 2024-01-29
Dir 816 A2 Firmware CRITICAL 9.8
CVE-2024-0921EPSS 38%

A vulnerability has been found in D-Link DIR-816 A2 1.10CNB04 and classified as critical. Affected by this vulnerability is an unknown functionality …

No fix yet
Fix from $2,300 2024-01-26
Tew 800mb Firmware HIGH 7.2
CVE-2024-0918EPSS 25%

A vulnerability was found in TRENDnet TEW-800MB 1.0.1.0 and classified as critical. Affected by this issue is some unknown functionality of the compo…

No fix yet
Fix from $1,950 2024-01-26
Opennds CRITICAL 9.8
CVE-2023-38319

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attackers that have dire…

Fix: 10.1.3+
Fix from $2,300 2024-01-26
Opennds CRITICAL 9.8
CVE-2023-38323

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers tha…

Fix: 10.1.3+
Fix from $2,300 2024-01-26
Opennds CRITICAL 9.8
CVE-2023-38317

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers…

Fix: 10.1.3+
Fix from $2,300 2024-01-26
Opennds CRITICAL 9.8
CVE-2023-38318

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have…

Fix: 10.1.3+
Fix from $2,300 2024-01-26
Wrc X1800gs B Firmware MEDIUM 6.8
CVE-2024-22372

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbi…

Fix: 1.14 / 1.18+
Fix from $1,600 2024-01-24
Wlx222 Firmware MEDIUM 6.8
CVE-2024-22366

Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device…

Fix: 16.00.19 / 18.00.13+
Fix from $1,600 2024-01-24
Bluefield Bmc HIGH 7.2
CVE-2023-31037

NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. A succ…

Mitigation only
Fix from $1,950 2024-01-24
Am 300 Firmware HIGH 7.8
CVE-2023-6926

There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH sessi…

Mitigation only
Fix from $1,950 2024-01-23
Isc 2500 S Firmware CRITICAL 9.8
CVE-2024-0778EPSS 32%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S up to 20210930. Affected by t…

Fix: after 20210930
Fix from $2,300 2024-01-22
Match HIGH 7.2
CVE-2023-49329

Anomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating system commands. This arises fro…

Fix: 4.4.5 / 4.5.4+
Fix from $1,950 2024-01-19
Phoniebox CRITICAL 9.8
CVE-2024-0714

A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.5.0. It has been rated as critical. Affected by this issue is some unknown functionali…

Fix: after 2.5.0
Fix from $2,300 2024-01-19
Tws 200 Firmware HIGH 8.8
CVE-2023-51217

An issue discovered in TenghuTOS TWS-200 firmware version:V4.0-201809201424 allows a remote attacker to execute arbitrary code via crafted command on…

No fix yet
Fix from $1,950 2024-01-18
Thousandeyes Enterprise Agent HIGH 8.0
CVE-2024-20277

A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an aut…

Fix: 0.233.2+
Fix from $1,950 2024-01-17
Atril HIGH 8.8
CVE-2023-51698

Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacke…

Fix: after 1.26.3
Fix from $1,950 2024-01-12
H8951 4g Esp Firmware HIGH 8.8
CVE-2023-49254

Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destination" field of the network test…

Fix: 2310271149+
Fix from $1,950 2024-01-12