Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 7.2
CVE-2024-38512

A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform command inj…

Mitigation only
Fix from $1,950 2024-07-26
Unclassified HIGH 7.2
CVE-2024-38508

A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC that could allow an authentica…

Mitigation only
Fix from $1,950 2024-07-26
Msg2300 Firmware CRITICAL 9.8
CVE-2024-7120EPSS 93%

A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of…

No fix yet
Fix from $2,300 2024-07-26
Fh1201 Firmware CRITICAL 9.8
CVE-2024-41468

Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand

Mitigation only
Fix from $2,300 2024-07-25
Fh1201 Firmware CRITICAL 9.8
CVE-2024-41473EPSS 7%

Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac

No fix yet
Fix from $2,300 2024-07-25
Webuzo HIGH 8.8
CVE-2024-24622

Softaculous Webuzo contains a command injection in the password reset functionality. A remote, authenticated attacker can exploit this vulnerability …

Fix: 4.2.9+
Fix from $1,950 2024-07-25
Webuzo HIGH 8.8
CVE-2024-24623

Softaculous Webuzo contains a command injection vulnerability in the FTP management functionality. A remote, authenticated attacker can exploit this …

Fix: 4.2.9+
Fix from $1,950 2024-07-25
Edgeconnect Sd Wan Orchestrator HIGH 8.8
CVE-2024-41136

An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful ex…

Fix: after 9.2.9
Fix from $1,950 2024-07-24
Sdg Smartos HIGH 7.2
CVE-2024-39345

AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented, hard-coded support account w…

Fix: 12.1.3.1+
Fix from $1,950 2024-07-24
Sdg Smartos HIGH 8.8
CVE-2024-31977

Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via shell metacharacters to the Pi…

Fix: 12.5.5.1+
Fix from $1,950 2024-07-24
Datacube3 Firmware CRITICAL 9.8
CVE-2024-7066

A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of t…

No fix yet
Fix from $2,300 2024-07-24
Bert Vits2 CRITICAL 9.8
CVE-2024-39685

Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with sub…

Fix: after 2.3
Fix from $2,300 2024-07-22
Bert Vits2 CRITICAL 9.8
CVE-2024-39686

Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with sub…

Fix: after 2.3
Fix from $2,300 2024-07-22
A6000r Firmware MEDIUM 6.8
CVE-2024-41314

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.

No fix yet
Fix from $1,600 2024-07-22
A6000r Firmware MEDIUM 6.8
CVE-2024-41315

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wp…

No fix yet
Fix from $1,600 2024-07-22
A6000r Firmware HIGH 8.0
CVE-2024-41317

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wp…

No fix yet
Fix from $1,950 2024-07-22
Protonvpn HIGH 7.8
CVE-2024-37391

ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in…

Fix: 3.2.10+
Fix from $1,950 2024-07-22
Cam V4 Firmware HIGH 8.8
CVE-2024-37066

A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands ov…

Fix: after 4.52.4.9887
Fix from $1,950 2024-07-19
Unclassified HIGH 7.8
CVE-2024-34013

Local privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True Image (macOS) before build 41…

Mitigation only
Fix from $1,950 2024-07-18
Unclassified HIGH 7.4
CVE-2024-40641

Nuclei is a fast and customizable vulnerability scanner based on simple YAML based DSL. In affected versions it a way to execute code template witho…

Mitigation only
Fix from $1,950 2024-07-17
Futurenet Nxr 1300 Firmware HIGH 8.8
CVE-2024-36475

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows…

Fix: 6.23.11 / 7.4.10+
Fix from $1,950 2024-07-17
Futurenet Nxr 1300 Firmware CRITICAL 9.8
CVE-2024-36491

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command…

Fix: 6.23.11 / 7.4.10+
Fix from $2,300 2024-07-17
Eg 2000se Firmware CRITICAL 9.8
CVE-2019-16639

An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attacker (who…

No fix yet
Fix from $2,300 2024-07-16
Junos Os Evolved HIGH 7.8
CVE-2024-39521

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker wit…

Fix: 21.2+
Fix from $1,950 2024-07-11
Junos Os Evolved HIGH 7.8
CVE-2024-39522

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker wit…

Mitigation only
Fix from $1,950 2024-07-11
Junos Os Evolved HIGH 7.8
CVE-2024-39523

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker wit…

Fix: 20.4+
Fix from $1,950 2024-07-11
Junos Os Evolved HIGH 7.8
CVE-2024-39524

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker wit…

Fix: 20.4+
Fix from $1,950 2024-07-11
Junos Os Evolved HIGH 7.8
CVE-2024-39520

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker wit…

Fix: 20.4+
Fix from $1,950 2024-07-11
Unclassified HIGH 8.7
CVE-2024-3799EPSS 15%

Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source project Phoniebox allows an attacke…

Mitigation only
Fix from $1,950 2024-07-10
Unclassified HIGH 8.7
CVE-2024-3798

Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker…

Mitigation only
Fix from $1,950 2024-07-10