Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8130EPSS 8%

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS…

No fix yet
Fix from $2,300 2024-08-24
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8129EPSS 23%

A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, …

No fix yet
Fix from $2,300 2024-08-24
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8128EPSS 8%

A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-3…

No fix yet
Fix from $2,300 2024-08-24
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2024-8127EPSS 7%

A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS…

No fix yet
Fix from $2,300 2024-08-24
T8 Firmware CRITICAL 9.8
CVE-2024-8077

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been classified as critical. This affects the function setTracerouteCfg…

No fix yet
Fix from $2,300 2024-08-22
T8 Firmware CRITICAL 9.8
CVE-2024-8075

A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this vulnerability is the function…

Mitigation only
Fix from $2,300 2024-08-22
Axiom HIGH 8.0
CVE-2024-7448

Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitra…

Mitigation only
Fix from $1,950 2024-08-21
Netiq Privileged Access Manager HIGH 7.8
CVE-2020-11847

SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged …

Fix: 3.7+
Fix from $1,950 2024-08-21
E1500 Firmware HIGH 8.8
CVE-2024-42633

A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authentica…

No fix yet
Fix from $1,950 2024-08-19
Unclassified CRITICAL 9.8
CVE-2024-42757

Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page.

Mitigation only
Fix from $2,300 2024-08-15
Fh1206 Firmware CRITICAL 9.8
CVE-2024-42978

An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP req…

No fix yet
Fix from $2,300 2024-08-15
Commerce HIGH 8.4
CVE-2024-39401

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an …

Fix: after 2.4.3
Fix from $1,950 2024-08-14
Commerce HIGH 8.4
CVE-2024-39402

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an …

Fix: after 2.4.3
Fix from $1,950 2024-08-14
Unclassified HIGH 7.2
CVE-2024-7728

The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to injec…

Mitigation only
Fix from $1,950 2024-08-14
Fortiddos HIGH 7.8
CVE-2022-27486

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2…

Fix: 5.6.2 / 6.4.2+
Fix from $1,950 2024-08-13
X5000r Firmware MEDIUM 6.8
CVE-2024-42740

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated …

No fix yet
Fix from $1,600 2024-08-13
X5000r Firmware HIGH 7.8
CVE-2024-42736

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticat…

No fix yet
Fix from $1,950 2024-08-13
X5000r Firmware HIGH 8.8
CVE-2024-42737

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticat…

No fix yet
Fix from $1,950 2024-08-13
X5000r Firmware HIGH 8.8
CVE-2024-42738

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. Authenticated …

No fix yet
Fix from $1,950 2024-08-13
X5000r Firmware HIGH 8.8
CVE-2024-42739

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authe…

No fix yet
Fix from $1,950 2024-08-13
X5000r Firmware HIGH 8.8
CVE-2024-42743

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . Authentica…

No fix yet
Fix from $1,950 2024-08-12
X5000r Firmware HIGH 8.8
CVE-2024-42744

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setModifyVpnUser. Authent…

No fix yet
Fix from $1,950 2024-08-12
X5000r Firmware HIGH 8.8
CVE-2024-42745

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated…

No fix yet
Fix from $1,950 2024-08-12
X5000r Firmware HIGH 8.8
CVE-2024-42747

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticate…

No fix yet
Fix from $1,950 2024-08-12
X5000r Firmware HIGH 8.8
CVE-2024-42748

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. Authentica…

No fix yet
Fix from $1,950 2024-08-12
X5000r Firmware HIGH 8.8
CVE-2024-42741

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfg. Authent…

No fix yet
Fix from $1,950 2024-08-12
X5000r Firmware HIGH 8.8
CVE-2024-42742

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUrlFilterRules. Authen…

No fix yet
Fix from $1,950 2024-08-12
Unclassified MEDIUM 6.8
CVE-2024-40893

Multiple authenticated operating system (OS) command injection vulnerabilities exist in Firewalla Box Software versions before 1.979. A physically c…

Mitigation only
Fix from $1,600 2024-08-12
Crater 2 Firmware HIGH 8.8
CVE-2024-39091

An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the sam…

Mitigation only
Fix from $1,950 2024-08-12
Order Management CRITICAL 9.8
CVE-2024-6917

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Veribilim Software Veribase Order Managem…

Fix: 4.010.2+
Fix from $2,300 2024-08-12