Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2024-1115 A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function dlfile of the file /application/websocket… Openbi after 1.0.8 Fix from $2,3002024-01-31 CRITICAL 9.8 CVE-2024-24325 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules … A3300r Firmware No fix yet Fix from $2,3002024-01-30 CRITICAL 9.8 CVE-2024-24326 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpR… A3300r Firmware No fix yet Fix from $2,3002024-01-30 CRITICAL 9.8 CVE-2024-24327 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg fun… A3300r Firmware No fix yet Fix from $2,3002024-01-30 CRITICAL 9.8 CVE-2024-24328EPSS 6% TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules… A3300r Firmware No fix yet Fix from $2,3002024-01-30 CRITICAL 9.8 CVE-2024-24329EPSS 6% TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRul… A3300r Firmware No fix yet Fix from $2,3002024-01-30 CRITICAL 9.8 CVE-2024-24330 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemote… A3300r Firmware No fix yet Fix from $2,3002024-01-30 CRITICAL 9.8 CVE-2024-24331 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCf… A3300r Firmware No fix yet Fix from $2,3002024-01-30 CRITICAL 9.8 CVE-2024-24332 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules fu… A3300r Firmware No fix yet Fix from $2,3002024-01-30 CRITICAL 9.8 CVE-2024-24333 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules fun… A3300r Firmware No fix yet Fix from $2,3002024-01-30 HIGH 7.2 CVE-2023-5372EPSS 28% The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and NAS542 firmware versions throu… Nas326 Firmware 5.21+ Fix from $1,9502024-01-30 HIGH 7.2 CVE-2023-49038 Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as… Ls210d Firmware No fix yet Fix from $1,9502024-01-29 CRITICAL 9.8 CVE-2024-0986EPSS 58% A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php?menu… Pbx No fix yet Fix from $2,3002024-01-29 CRITICAL 9.8 CVE-2024-0921EPSS 38% A vulnerability has been found in D-Link DIR-816 A2 1.10CNB04 and classified as critical. Affected by this vulnerability is an unknown functionality … Dir 816 A2 Firmware No fix yet Fix from $2,3002024-01-26 HIGH 7.2 CVE-2024-0918EPSS 25% A vulnerability was found in TRENDnet TEW-800MB 1.0.1.0 and classified as critical. Affected by this issue is some unknown functionality of the compo… Tew 800mb Firmware No fix yet Fix from $1,9502024-01-26 CRITICAL 9.8 CVE-2023-38319 An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attackers that have dire… Opennds 10.1.3+ Fix from $2,3002024-01-26 CRITICAL 9.8 CVE-2023-38323 An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers tha… Opennds 10.1.3+ Fix from $2,3002024-01-26 CRITICAL 9.8 CVE-2023-38317 An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers… Opennds 10.1.3+ Fix from $2,3002024-01-26 CRITICAL 9.8 CVE-2023-38318 An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have… Opennds 10.1.3+ Fix from $2,3002024-01-26 MEDIUM 6.8 CVE-2024-22372 OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbi… Wrc X1800gs B Firmware 1.14 / 1.18+ Fix from $1,6002024-01-24 MEDIUM 6.8 CVE-2024-22366 Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device… Wlx222 Firmware 16.00.19 / 18.00.13+ Fix from $1,6002024-01-24 HIGH 7.2 CVE-2023-31037 NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. A succ… Bluefield Bmc Mitigation only Fix from $1,9502024-01-24 HIGH 7.8 CVE-2023-6926 There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH sessi… Am 300 Firmware Mitigation only Fix from $1,9502024-01-23 CRITICAL 9.8 CVE-2024-0778EPSS 32% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S up to 20210930. Affected by t… Isc 2500 S Firmware after 20210930 Fix from $2,3002024-01-22 HIGH 7.2 CVE-2023-49329 Anomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating system commands. This arises fro… Match 4.4.5 / 4.5.4+ Fix from $1,9502024-01-19 CRITICAL 9.8 CVE-2024-0714 A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.5.0. It has been rated as critical. Affected by this issue is some unknown functionali… Phoniebox after 2.5.0 Fix from $2,3002024-01-19 HIGH 8.8 CVE-2023-51217 An issue discovered in TenghuTOS TWS-200 firmware version:V4.0-201809201424 allows a remote attacker to execute arbitrary code via crafted command on… Tws 200 Firmware No fix yet Fix from $1,9502024-01-18 HIGH 8.0 CVE-2024-20277 A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an aut… Thousandeyes Enterprise Agent 0.233.2+ Fix from $1,9502024-01-17 HIGH 8.8 CVE-2023-51698 Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacke… Atril after 1.26.3 Fix from $1,9502024-01-12 HIGH 8.8 CVE-2023-49254 Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destination" field of the network test… H8951 4g Esp Firmware 2310271149+ Fix from $1,9502024-01-12