Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Dsl6740c Firmware HIGH 7.2
CVE-2024-11063

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute ar…

Mitigation only
Fix from $1,950 2024-11-11
Dsl6740c Firmware HIGH 7.2
CVE-2024-11064

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute ar…

Mitigation only
Fix from $1,950 2024-11-11
Dsl6740c Firmware HIGH 7.2
CVE-2024-11062

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute ar…

Mitigation only
Fix from $1,950 2024-11-11
Unclassified HIGH 8.8
CVE-2024-41992

Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is us…

Mitigation only
Fix from $1,950 2024-11-11
Di 8003 Firmware CRITICAL 9.8
CVE-2024-11046

A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been classified as critical. Affected is the function upgrade_filter_asp of the file /…

No fix yet
Fix from $2,300 2024-11-10
Unclassified HIGH 8.8
CVE-2024-50809

The theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commands

Mitigation only
Fix from $1,950 2024-11-08
Enterprise Sonic Distribution HIGH 7.2
CVE-2024-45763

Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec…

Fix: 4.1.6 / 4.2.2+
Fix from $1,950 2024-11-08
Enterprise Sonic Distribution HIGH 7.2
CVE-2024-45765

Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec…

Fix: 4.1.6 / 4.2.2+
Fix from $1,950 2024-11-08
Unclassified CRITICAL 9.8
CVE-2020-8007

The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection via three field…

Mitigation only
Fix from $2,300 2024-11-08
X18 Firmware HIGH 8.8
CVE-2024-10966

A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown func…

No fix yet
Fix from $1,950 2024-11-07
Siem MEDIUM 6.4
CVE-2024-48954

An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code…

Fix: 7.5.0+
Fix from $1,600 2024-11-07
Super Jacoco CRITICAL 9.8
CVE-2024-10919EPSS 5%

A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the…

No fix yet
Fix from $2,300 2024-11-06
Dns 320 Firmware CRITICAL 9.8
CVE-2024-10914EPSS 96%

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulne…

No fix yet
Fix from $2,300 2024-11-06
Dns 320 Firmware CRITICAL 9.8
CVE-2024-10915EPSS 79%

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is…

No fix yet
Fix from $2,300 2024-11-06
Waybox Pro Firmware HIGH 8.8
CVE-2023-29120

Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.

Fix: 2.1.1.0_jb3vu096a+
Fix from $1,950 2024-11-05
Dir 823g Firmware HIGH 8.0
CVE-2024-51024

D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the HostName parameter in the SetWanSettings function. This …

Mitigation only
Fix from $1,950 2024-11-05
Xr300 Firmware HIGH 8.0
CVE-2024-52018

Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnerability…

Mitigation only
Fix from $1,950 2024-11-05
R8500 Firmware HIGH 8.0
CVE-2024-52019

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at genie_fix2.cgi. This vulnerabili…

Mitigation only
Fix from $1,950 2024-11-05
R8500 Firmware HIGH 8.0
CVE-2024-52020

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at wiz_fix2.cgi. This vulnerability…

Mitigation only
Fix from $1,950 2024-11-05
R8500 Firmware HIGH 8.0
CVE-2024-52021

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at bsw_fix.cgi. This vulnerability …

Mitigation only
Fix from $1,950 2024-11-05
Xr300 Firmware HIGH 8.0
CVE-2024-51021

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a command injection vulnerability via the wan_gateway pa…

Mitigation only
Fix from $1,950 2024-11-05
Dir 823g Firmware HIGH 8.8
CVE-2024-51023

D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySettings fu…

Mitigation only
Fix from $1,950 2024-11-05
R8500 Firmware HIGH 8.0
CVE-2024-51005

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the share_name parameter at usb_remote_smb_conf.cgi. This vul…

Mitigation only
Fix from $1,950 2024-11-05
Xr300 Firmware HIGH 8.0
CVE-2024-51008

Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at wiz_dyn.cgi. This vulnerability a…

Mitigation only
Fix from $1,950 2024-11-05
R8500 Firmware HIGH 8.0
CVE-2024-51009

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at ether.cgi. This vulnerability al…

Mitigation only
Fix from $1,950 2024-11-05
R8500 Firmware HIGH 8.0
CVE-2024-51010

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in …

Mitigation only
Fix from $1,950 2024-11-05
R8500 Firmware HIGH 8.0
CVE-2024-50993

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at admin_account.cgi. This vulnera…

Mitigation only
Fix from $1,950 2024-11-05
Vigor3900 Firmware HIGH 8.0
CVE-2024-45885

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45887

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45888

DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.…

Mitigation only
Fix from $1,950 2024-11-04