Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Qts HIGH 8.8
CVE-2024-21898

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $1,950 2024-09-06
Qts HIGH 7.2
CVE-2023-39300

An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allow authenticated administrator…

Mitigation only
Fix from $1,950 2024-09-06
Video Station HIGH 8.8
CVE-2023-47563

An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to e…

Fix: 5.8.2+
Fix from $1,950 2024-09-06
Qts HIGH 8.8
CVE-2023-34974

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $1,950 2024-09-06
Qts HIGH 7.2
CVE-2023-34979

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $1,950 2024-09-06
Spip CRITICAL 9.8
CVE-2024-8517EPSS 95%

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary opera…

Fix: 4.1.18+
Fix from $2,300 2024-09-06
Loadmaster HIGH 7.2
CVE-2024-7591EPSS 44%

Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * E…

Fix: 7.1.35.11+
Fix from $1,950 2024-09-05
Identity Services Engine MEDIUM 6.7
CVE-2024-20469

A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command inje…

Mitigation only
Fix from $1,600 2024-09-04
Rust HIGH 8.8
CVE-2024-43402

Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments when invoking batch files on …

Fix: 1.81.0+
Fix from $1,950 2024-09-04
Nuclei HIGH 7.8
CVE-2024-43405

Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's …

Fix: 3.3.2+
Fix from $1,950 2024-09-04
Nwa110ax Firmware CRITICAL 9.8
CVE-2024-7261EPSS 11%

The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and ear…

Fix: 6.28 / 6.70+
Fix from $2,300 2024-09-03
Zld HIGH 7.2
CVE-2024-7203

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware ver…

Fix: 5.39+
Fix from $1,950 2024-09-03
Zld HIGH 8.1
CVE-2024-42057

A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware v…

Fix: 5.39+
Fix from $1,950 2024-09-03
Zld HIGH 7.2
CVE-2024-42059

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versio…

Fix: 5.39+
Fix from $1,950 2024-09-03
Zld HIGH 7.2
CVE-2024-42060

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versio…

Fix: 5.39+
Fix from $1,950 2024-09-03
Nwaw1100 N Firmware CRITICAL 9.8
CVE-2024-8234

** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NW…

No fix yet
Fix from $2,300 2024-08-30
Roxy Wi HIGH 8.8
CVE-2024-43804

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated…

No fix yet
Fix from $1,950 2024-08-29
Dns 315l Firmware CRITICAL 9.8
CVE-2024-8213EPSS 7%

A vulnerability classified as critical has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323…

No fix yet
Fix from $2,300 2024-08-27
Dns 315l Firmware CRITICAL 9.8
CVE-2024-8214EPSS 5%

A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS…

No fix yet
Fix from $2,300 2024-08-27
Dns 315l Firmware CRITICAL 9.8
CVE-2024-8210EPSS 7%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-27
Dns 315l Firmware CRITICAL 9.8
CVE-2024-8211EPSS 5%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-27
Dir 846w Firmware CRITICAL 9.8
CVE-2024-41622

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HN…

Mitigation only
Fix from $2,300 2024-08-27
Dir 846w Firmware HIGH 8.8
CVE-2024-44340

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_n…

Mitigation only
Fix from $1,950 2024-08-27
Dir 846w Firmware CRITICAL 9.8
CVE-2024-44341

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This …

Mitigation only
Fix from $2,300 2024-08-27
Dir 846w Firmware CRITICAL 9.8
CVE-2024-44342

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerabi…

Mitigation only
Fix from $2,300 2024-08-27
Ax9000 Firmware HIGH 8.8
CVE-2023-26315EPSS 19%

The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allo…

Fix: 1.0.174+
Fix from $1,950 2024-08-26
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8134EPSS 8%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-24
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8133EPSS 8%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-24
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8131EPSS 8%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-24
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8132EPSS 23%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $2,300 2024-08-24