Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Vigor3900 Firmware HIGH 8.0
CVE-2024-45889

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45890

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cg…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45891

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45893

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45882

DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45884

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-51246

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP func…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-51249

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot func…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-51251

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup func…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-51253

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP func…

Mitigation only
Fix from $1,950 2024-11-04
Coslat CRITICAL 9.8
CVE-2024-10035

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Impro…

Fix: after 3.1069
Fix from $2,300 2024-11-04
Media Library Assistant HIGH 7.2
CVE-2024-51661

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant med…

Fix: 3.20+
Fix from $1,950 2024-11-04
Vigor3900 Firmware CRITICAL 9.8
CVE-2024-51252

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore fun…

No fix yet
Fix from $2,300 2024-11-01
Vigor3900 Firmware HIGH 8.8
CVE-2024-51244

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec fun…

No fix yet
Fix from $1,950 2024-11-01
Vigor3900 Firmware HIGH 8.8
CVE-2024-51245

In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_tabl…

No fix yet
Fix from $1,950 2024-11-01
Vigor3900 Firmware HIGH 8.8
CVE-2024-51247

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo func…

No fix yet
Fix from $1,950 2024-11-01
Vigor3900 Firmware HIGH 8.8
CVE-2024-51248

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow f…

No fix yet
Fix from $1,950 2024-11-01
Unclassified HIGH 7.2
CVE-2024-10653

IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attacke…

Mitigation only
Fix from $1,950 2024-11-01
Unclassified MEDIUM 6.5
CVE-2024-8934

A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manag…

Mitigation only
Fix from $1,600 2024-10-31
Unclassified HIGH 8.8
CVE-2024-36060

EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test parameters.

Mitigation only
Fix from $1,950 2024-10-30
Cyberpanel CRITICAL 9.8
CVE-2024-51378 KEVEPSS 95%

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and e…

Fix: 2.3.8+
Fix from $2,300 2024-10-29
Cyberpanel CRITICAL 9.8
CVE-2024-51568EPSS 45%

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filem…

Fix: 2.3.5+
Fix from $2,300 2024-10-29
Tro610 Firmware HIGH 7.2
CVE-2024-41153

Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If …

Fix: 9.2.0.5+
Fix from $1,950 2024-10-29
Mf258k Pro Firmware HIGH 8.8
CVE-2024-22065

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authent…

Mitigation only
Fix from $1,950 2024-10-29
Ac7 Firmware HIGH 8.8
CVE-2024-48825

Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.

No fix yet
Fix from $1,950 2024-10-28
Ac7 Firmware HIGH 8.8
CVE-2024-48826

Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.

No fix yet
Fix from $1,950 2024-10-28
Vigor2960 Firmware HIGH 8.0
CVE-2024-48074

An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table …

No fix yet
Fix from $1,950 2024-10-28
Mango HIGH 7.2
CVE-2024-37845

MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.

Fix: 5.2.0+
Fix from $1,950 2024-10-25
Unclassified HIGH 7.3
CVE-2024-48459EPSS 8%

A command execution vulnerability exists in the AX2 Pro home router produced by Shenzhen Tenda Technology Co., Ltd. (Jixiang Tenda) v.DI_7003G-19.12.…

Mitigation only
Fix from $1,950 2024-10-25
Plenti HIGH 7.5
CVE-2024-49380

Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an …

Fix: 0.7.2+
Fix from $1,950 2024-10-25