Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 8.3
CVE-2024-42370

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulner…

Patch available
Fix from $1,950 2024-08-12
Keyrock HIGH 7.2
CVE-2024-42166

The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Comma…

Fix: after 8.4
Fix from $1,950 2024-08-12
Keyrock HIGH 7.2
CVE-2024-42167

The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Co…

Fix: after 8.4
Fix from $1,950 2024-08-12
Iq Gateway Firmware CRITICAL 9.8
CVE-2024-21878

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) all…

Fix: 8.2.4225+
Fix from $2,300 2024-08-12
Iq Gateway Firmware HIGH 8.8
CVE-2024-21879

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoin…

Fix: 8.2.4225+
Fix from $1,950 2024-08-12
Iq Gateway Firmware HIGH 7.2
CVE-2024-21880

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint i…

Fix: after 7.3.120
Fix from $1,950 2024-08-12
Ar2140 Firmware HIGH 7.2
CVE-2024-3659

Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one…

Fix: 4.2.16+
Fix from $1,950 2024-08-08
Alr F800 Firmware CRITICAL 9.8
CVE-2024-7580EPSS 9%

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been rated as critical. Affected by this issue is some unknown funct…

Fix: after 19.10.24.00
Fix from $2,300 2024-08-07
Alr F800 Firmware HIGH 8.8
CVE-2024-7579EPSS 8%

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by this vulnerability is the fun…

Fix: after 19.10.24
Fix from $1,950 2024-08-07
Mt6000 Firmware CRITICAL 9.8
CVE-2024-39228

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4…

No fix yet
Fix from $2,300 2024-08-06
Client Connector CRITICAL 9.8
CVE-2024-23483

An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connec…

Fix: 4.2+
Fix from $2,300 2024-08-06
Msg2300 Firmware CRITICAL 9.8
CVE-2024-7469EPSS 25%

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been declared as critical. This vulnerability affects the f…

No fix yet
Fix from $2,300 2024-08-05
Msg2300 Firmware CRITICAL 9.8
CVE-2024-7470EPSS 25%

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been rated as critical. This issue affects the function ssl…

No fix yet
Fix from $2,300 2024-08-05
Msg2300 Firmware CRITICAL 9.8
CVE-2024-7467EPSS 23%

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 and classified as critical. Affected by this issue is the function …

No fix yet
Fix from $2,300 2024-08-05
Msg2300 Firmware CRITICAL 9.8
CVE-2024-7468EPSS 25%

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been classified as critical. This affects the function sslv…

No fix yet
Fix from $2,300 2024-08-05
Caterease CRITICAL 9.8
CVE-2024-38887

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand …

Fix: after 24.0.1.2405
Fix from $2,300 2024-08-02
Caterease CRITICAL 9.8
CVE-2024-38889

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform…

Fix: after 24.0.1.2405
Fix from $2,300 2024-08-02
Ewon Cosy\+ Firmware HIGH 7.2
CVE-2024-33896

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blackl…

Fix: after 22.1s3
Fix from $1,950 2024-08-02
Caterease CRITICAL 9.8
CVE-2024-38882

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform…

Fix: after 24.0.1.2405
Fix from $2,300 2024-08-02
Unclassified HIGH 8.1
CVE-2024-41956

Soft Serve is a self-hostable Git server for the command line. Prior to 0.7.5, it is possible for a user who can commit files to a repository hosted …

Patch available
Fix from $1,950 2024-08-01
Dir 600 Firmware CRITICAL 9.8
CVE-2024-7357EPSS 6%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-600 up to 2.18. It has been rated as critical. This issue affects the functio…

Fix: after 2.18
Fix from $2,300 2024-08-01
Unclassified MEDIUM 6.8
CVE-2024-39607

OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product by a logged…

Mitigation only
Fix from $1,600 2024-08-01
Unclassified MEDIUM 6.4
CVE-2024-40895

FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticated attacker…

Mitigation only
Fix from $1,600 2024-07-30
Sn Os CRITICAL 9.8
CVE-2024-5670

The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remo…

Mitigation only
Fix from $2,300 2024-07-29
A3600r Firmware HIGH 8.8
CVE-2024-7175

A vulnerability has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. This vulnerability affects the function setDiagn…

No fix yet
Fix from $1,950 2024-07-29
A3600r Firmware HIGH 8.8
CVE-2024-7171

A vulnerability classified as critical has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected is the function NTPSyncWithHost of the file…

No fix yet
Fix from $1,950 2024-07-28
Unclassified MEDIUM 6.3
CVE-2024-42029

xdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e.g., because single quotes ar…

Patch available
Fix from $1,600 2024-07-27
Starship HIGH 7.0
CVE-2024-41815

Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quotin…

Fix: 1.20.0+
Fix from $1,950 2024-07-26
Unclassified HIGH 7.2
CVE-2024-38510

A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user with elevat…

Mitigation only
Fix from $1,950 2024-07-26
Unclassified HIGH 7.2
CVE-2024-38511

A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with elev…

Mitigation only
Fix from $1,950 2024-07-26