Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 7.8
CVE-2024-45242EPSS 35%

EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping or Speed T…

Mitigation only
Fix from $1,950 2024-10-24
Snyk Cli CRITICAL 9.8
CVE-2024-48963

The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Sn…

Fix: 1.1294.0+
Fix from $2,300 2024-10-23
Snyk Cli HIGH 8.8
CVE-2024-48964

The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if…

Fix: 1.1294.0+
Fix from $1,950 2024-10-23
Secure Firewall Management Center CRITICAL 9.9
CVE-2024-20424

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center…

Mitigation only
Fix from $2,300 2024-10-23
Secure Firewall Management Center MEDIUM 6.1
CVE-2024-20275

A vulnerability in the cluster backup feature of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Softwar…

Mitigation only
Fix from $1,600 2024-10-23
Intermesh 7177 Hybrid 2.0 Subscriber CRITICAL 9.8
CVE-2024-47901

A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < …

Fix: 7.2.12 / 8.2.12+
Fix from $2,300 2024-10-23
Administrative Management System HIGH 8.8
CVE-2024-10202

Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inje…

Mitigation only
Fix from $1,950 2024-10-21
Wrtm326 Firmware CRITICAL 9.8
CVE-2024-10119

The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary sy…

Fix: after 2.3.20
Fix from $2,300 2024-10-18
Unclassified CRITICAL 9.8
CVE-2024-10118

SECOM WRTR-304GN-304TW-UPSC does not properly filter user input in the specific functionality. Unauthenticated remote attackers can exploit this vuln…

Mitigation only
Fix from $2,300 2024-10-18
Click To Chat MEDIUM 5.4
CVE-2024-49281

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ninja Team Click to Chat – WP Support All…

Fix: 2.3.4+
Fix from $1,600 2024-10-17
Dir 882 Firmware HIGH 8.0
CVE-2024-48629

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the IPAddress parameter in the …

Mitigation only
Fix from $1,950 2024-10-17
Dir 882 Firmware HIGH 8.0
CVE-2024-48630

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the…

Mitigation only
Fix from $1,950 2024-10-17
Dir 882 Firmware HIGH 8.0
CVE-2024-48631

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWL…

Mitigation only
Fix from $1,950 2024-10-17
Dir 882 Firmware HIGH 8.0
CVE-2024-48632

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAddress, TC…

Mitigation only
Fix from $1,950 2024-10-17
Dir 882 Firmware HIGH 8.0
CVE-2024-48633

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, Inte…

Mitigation only
Fix from $1,950 2024-10-17
Dir 882 Firmware HIGH 8.0
CVE-2024-48634EPSS 17%

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLa…

Mitigation only
Fix from $1,950 2024-10-17
Dir 882 Firmware HIGH 8.0
CVE-2024-48635

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in t…

Mitigation only
Fix from $1,950 2024-10-17
Dir 882 Firmware HIGH 8.0
CVE-2024-48636

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:0/VID parameter in t…

Mitigation only
Fix from $1,950 2024-10-17
Dir 882 Firmware HIGH 8.0
CVE-2024-48637

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:1/VID parameter in t…

Mitigation only
Fix from $1,950 2024-10-17
Dir 882 Firmware HIGH 8.0
CVE-2024-48638

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SubnetMask parameter in the…

Mitigation only
Fix from $1,950 2024-10-17
Unclassified HIGH 7.2
CVE-2024-6333

Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.

No fix yet
Fix from $1,950 2024-10-17
Xcomic CRITICAL 9.8
CVE-2005-10003

A vulnerability classified as critical has been found in mikexstudios Xcomic up to 0.8.2. This affects an unknown part. The manipulation of the argum…

Fix: 0.8.3+
Fix from $2,300 2024-10-17
Ata 191 Firmware MEDIUM 6.0
CVE-2024-20461

A vulnerability in the CLI&nbsp;of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, local attacker with high priv…

Fix: 11.2.5 / 12.0.2+
Fix from $1,600 2024-10-16
Ata 191 Firmware HIGH 8.2
CVE-2024-20458

A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remot…

Fix: 11.2.5 / 12.0.2+
Fix from $1,950 2024-10-16
Ata 191 Firmware HIGH 7.2
CVE-2024-20459

A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog Telephone Adapter firmware could allow an authenti…

Fix: 11.2.5 / 12.0.2+
Fix from $1,950 2024-10-16
Unclassified MEDIUM 6.3
CVE-2024-22033

The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide a configuration to the servi…

Mitigation only
Fix from $1,600 2024-10-16
Ex3700 Firmware MEDIUM 6.8
CVE-2024-35519

Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap…

Fix: after 1.0.2.28
Fix from $1,600 2024-10-14
Unclassified HIGH 7.2
CVE-2024-9139

The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers to execute arbitrary code.

Mitigation only
Fix from $1,950 2024-10-14
Usualtoolcms CRITICAL 9.8
CVE-2024-9916EPSS 73%

A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the f…

No fix yet
Fix from $2,300 2024-10-13
Loadmaster CRITICAL 9.8
CVE-2024-8755

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects:  Product …

Fix: 7.2.61.0+
Fix from $2,300 2024-10-11