Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Ac1206 Firmware CRITICAL 9.8
CVE-2024-9793EPSS 23%

A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconf…

No fix yet
Fix from $2,300 2024-10-10
Expedition MEDIUM 6.5
CVE-2024-9464EPSS 82%

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Exped…

Fix: 1.2.96+
Fix from $1,600 2024-10-09
Expedition HIGH 7.5
CVE-2024-9463 KEVEPSS 98%

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Exp…

Fix: 1.2.96+
Fix from $1,950 2024-10-09
Vigor3900 Firmware HIGH 8.0
CVE-2024-46316

DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This …

Mitigation only
Fix from $1,950 2024-10-09
Subversion HIGH 7.8
CVE-2024-45720

On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead…

Fix: 1.14.4+
Fix from $1,950 2024-10-09
Endpoint Manager Cloud Services Appliance HIGH 7.2
CVE-2024-9380 KEVEPSS 63%

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin p…

Fix: 5.0.2+
Fix from $1,950 2024-10-08
Unclassified HIGH 8.0
CVE-2024-45880

A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. T…

Mitigation only
Fix from $1,950 2024-10-08
Unclassified HIGH 7.3
CVE-2024-21532

All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to …

Mitigation only
Fix from $1,950 2024-10-08
PHP HIGH 8.8
CVE-2024-8926

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages,…

Fix: 8.1.30 / 8.2.24+
Fix from $1,950 2024-10-08
Unclassified CRITICAL 9.8
CVE-2024-45252

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Mitigation only
Fix from $2,300 2024-10-06
Unclassified CRITICAL 9.8
CVE-2024-45251

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Mitigation only
Fix from $2,300 2024-10-06
Timeprovider 4100 Firmware HIGH 8.8
CVE-2024-9054EPSS 16%

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Acto…

Fix: 2.4.7+
Fix from $1,950 2024-10-04
Tl Wdr5620 Firmware HIGH 8.0
CVE-2024-46486

TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.

No fix yet
Fix from $1,950 2024-10-04
Unclassified HIGH 8.0
CVE-2024-46658EPSS 24%

Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.

Mitigation only
Fix from $1,950 2024-10-03
Vigor3910 Firmware MEDIUM 6.8
CVE-2024-41585

DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binar…

Fix: after 4.3.2.6
Fix from $1,600 2024-10-03
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2024-45519 KEVEPSS 100%

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 somet…

Fix: 8.8.15 / 10.0.9+
Fix from $2,300 2024-10-02
Unclassified CRITICAL 9.8
CVE-2024-9441EPSS 53%

The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can…

Mitigation only
Fix from $2,300 2024-10-02
Logicytics CRITICAL 9.8
CVE-2024-47608

Logicytics is designed to harvest and collect data for forensic analysis. Logicytics has a basic vuln affecting compromised devices from shell inject…

Fix: after 2.3.1
Fix from $2,300 2024-10-01
Unclassified MEDIUM 5.3
CVE-2024-21531

All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the process vari…

Mitigation only
Fix from $1,600 2024-10-01
Ilx F509 Firmware MEDIUM 6.8
CVE-2024-23961

Alpine Halo9 UPDM_wemCmdUpdFSpeDecomp Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers t…

Mitigation only
Fix from $1,600 2024-09-28
Ilx F509 Firmware MEDIUM 6.8
CVE-2024-23924

Alpine Halo9 UPDM_wemCmdCreatSHA256Hash Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers…

Mitigation only
Fix from $1,600 2024-09-28
Rpshare HIGH 8.8
CVE-2024-33368

An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method in DonwloadPromptScreen

Mitigation only
Fix from $1,950 2024-09-27
G3 Firmware CRITICAL 9.8
CVE-2024-46628EPSS 12%

Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the…

No fix yet
Fix from $2,300 2024-09-26
Unclassified CRITICAL 9.3
CVE-2024-9166

The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the '…

Mitigation only
Fix from $2,300 2024-09-26
Vap11g 300 Firmware HIGH 8.0
CVE-2024-46329

VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object.

Mitigation only
Fix from $1,950 2024-09-26
Vap11g 300 Firmware HIGH 7.4
CVE-2024-46330

VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun object.

Mitigation only
Fix from $1,950 2024-09-26
Unclassified HIGH 8.0
CVE-2024-44678

Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commands on th…

Mitigation only
Fix from $1,950 2024-09-25
Dedecms HIGH 8.8
CVE-2024-9076EPSS 21%

A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/artic…

Fix: after 5.7.115
Fix from $1,950 2024-09-22
Dar 7000 Firmware CRITICAL 9.8
CVE-2024-9004EPSS 17%

A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. Affected is an unknown function of the file /view/DBManage/B…

Fix: after 2024-09-12
Fix from $2,300 2024-09-19
T10 Firmware HIGH 8.8
CVE-2024-9001

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of…

No fix yet
Fix from $1,950 2024-09-19