Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2024-11063 The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute ar… Dsl6740c Firmware Mitigation only Fix from $1,9502024-11-11 HIGH 7.2 CVE-2024-11064 The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute ar… Dsl6740c Firmware Mitigation only Fix from $1,9502024-11-11 HIGH 7.2 CVE-2024-11062 The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute ar… Dsl6740c Firmware Mitigation only Fix from $1,9502024-11-11 HIGH 8.8 CVE-2024-41992 Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is us… Mitigation only Fix from $1,9502024-11-11 CRITICAL 9.8 CVE-2024-11046 A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been classified as critical. Affected is the function upgrade_filter_asp of the file /… Di 8003 Firmware No fix yet Fix from $2,3002024-11-10 HIGH 8.8 CVE-2024-50809 The theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commands Mitigation only Fix from $1,9502024-11-08 HIGH 7.2 CVE-2024-45763 Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec… Enterprise Sonic Distribution 4.1.6 / 4.2.2+ Fix from $1,9502024-11-08 HIGH 7.2 CVE-2024-45765 Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec… Enterprise Sonic Distribution 4.1.6 / 4.2.2+ Fix from $1,9502024-11-08 CRITICAL 9.8 CVE-2020-8007 The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection via three field… Mitigation only Fix from $2,3002024-11-08 HIGH 8.8 CVE-2024-10966 A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown func… X18 Firmware No fix yet Fix from $1,9502024-11-07 MEDIUM 6.4 CVE-2024-48954 An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code… Siem 7.5.0+ Fix from $1,6002024-11-07 CRITICAL 9.8 CVE-2024-10919EPSS 5% A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the… Super Jacoco No fix yet Fix from $2,3002024-11-06 CRITICAL 9.8 CVE-2024-10914EPSS 96% A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulne… Dns 320 Firmware No fix yet Fix from $2,3002024-11-06 CRITICAL 9.8 CVE-2024-10915EPSS 79% A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is… Dns 320 Firmware No fix yet Fix from $2,3002024-11-06 HIGH 8.8 CVE-2023-29120 Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system. Waybox Pro Firmware 2.1.1.0_jb3vu096a+ Fix from $1,9502024-11-05 HIGH 8.0 CVE-2024-51024 D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the HostName parameter in the SetWanSettings function. This … Dir 823g Firmware Mitigation only Fix from $1,9502024-11-05 HIGH 8.0 CVE-2024-52018 Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnerability… Xr300 Firmware Mitigation only Fix from $1,9502024-11-05 HIGH 8.0 CVE-2024-52019 Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at genie_fix2.cgi. This vulnerabili… R8500 Firmware Mitigation only Fix from $1,9502024-11-05 HIGH 8.0 CVE-2024-52020 Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at wiz_fix2.cgi. This vulnerability… R8500 Firmware Mitigation only Fix from $1,9502024-11-05 HIGH 8.0 CVE-2024-52021 Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at bsw_fix.cgi. This vulnerability … R8500 Firmware Mitigation only Fix from $1,9502024-11-05 HIGH 8.0 CVE-2024-51021 Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a command injection vulnerability via the wan_gateway pa… Xr300 Firmware Mitigation only Fix from $1,9502024-11-05 HIGH 8.8 CVE-2024-51023 D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySettings fu… Dir 823g Firmware Mitigation only Fix from $1,9502024-11-05 HIGH 8.0 CVE-2024-51005 Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the share_name parameter at usb_remote_smb_conf.cgi. This vul… R8500 Firmware Mitigation only Fix from $1,9502024-11-05 HIGH 8.0 CVE-2024-51008 Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at wiz_dyn.cgi. This vulnerability a… Xr300 Firmware Mitigation only Fix from $1,9502024-11-05 HIGH 8.0 CVE-2024-51009 Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at ether.cgi. This vulnerability al… R8500 Firmware Mitigation only Fix from $1,9502024-11-05 HIGH 8.0 CVE-2024-51010 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in … R8500 Firmware Mitigation only Fix from $1,9502024-11-05 HIGH 8.0 CVE-2024-50993 Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at admin_account.cgi. This vulnera… R8500 Firmware Mitigation only Fix from $1,9502024-11-05 HIGH 8.0 CVE-2024-45885 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45887 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45888 DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04