Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2024-9200 A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions thro… Emg6726 B10a Firmware 5.13 / 5.15+ Fix from $1,9502024-12-03 HIGH 8.0 CVE-2024-53375EPSS 41% An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exists in the "tmp_get_sites" fu… Mitigation only Fix from $1,9502024-12-02 HIGH 8.8 CVE-2024-53939 An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq… Mitigation only Fix from $1,9502024-12-02 HIGH 8.8 CVE-2024-53940 An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /cgi-bin/luci/admin endpoints … Mitigation only Fix from $1,9502024-12-02 HIGH 8.8 CVE-2024-53992 unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malicious commands that are execut… Patch available Fix from $1,9502024-12-02 HIGH 8.8 CVE-2024-49803 IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitrary commands on the system by… Security Verify Access after 10.0.8 Fix from $1,9502024-11-29 CRITICAL 9.8 CVE-2024-11482 A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command inject… Enterprise Security Manager No fix yet Fix from $2,3002024-11-29 HIGH 7.2 CVE-2024-11983 Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to… Mitigation only Fix from $1,9502024-11-29 MEDIUM 5.4 CVE-2024-10896 The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and Slider settings, which could allow high privilege us… Logo Slider 4.5.0+ Fix from $1,6002024-11-28 MEDIUM 6.8 CVE-2024-51228 An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and T… Mitigation only Fix from $1,6002024-11-27 HIGH 8.0 CVE-2024-31976 EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity parameter. Ews356 Fir Firmware after 1.1.30 Fix from $1,9502024-11-27 HIGH 7.2 CVE-2024-9461 The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all vers… Total Upkeep 1.16.7+ Fix from $1,9502024-11-26 MEDIUM 5.2 CVE-2024-50376 A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufa… Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $1,6002024-11-26 MEDIUM 6.5 CVE-2024-50377 A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-633… Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $1,6002024-11-26 CRITICAL 9.8 CVE-2024-50374 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $2,3002024-11-26 CRITICAL 9.8 CVE-2024-50375 A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $2,3002024-11-26 CRITICAL 9.8 CVE-2024-50371 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $2,3002024-11-26 CRITICAL 9.8 CVE-2024-50372 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $2,3002024-11-26 CRITICAL 9.8 CVE-2024-50373 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $2,3002024-11-26 HIGH 7.2 CVE-2024-50369 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $1,9502024-11-26 CRITICAL 9.8 CVE-2024-50370 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $2,3002024-11-26 HIGH 7.2 CVE-2024-50367 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $1,9502024-11-26 HIGH 7.2 CVE-2024-50368 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $1,9502024-11-26 HIGH 7.2 CVE-2024-50365 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $1,9502024-11-26 HIGH 7.2 CVE-2024-50366 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $1,9502024-11-26 HIGH 7.2 CVE-2024-50362 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $1,9502024-11-26 HIGH 7.2 CVE-2024-50363 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $1,9502024-11-26 HIGH 7.2 CVE-2024-50364 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $1,9502024-11-26 HIGH 7.2 CVE-2024-50360 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $1,9502024-11-26 HIGH 7.2 CVE-2024-50361 A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $1,9502024-11-26