Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.0
CVE-2024-45889
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-45890
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cg…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-45891
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-45893
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-45882
DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-45884
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-51246
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP func…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-51249
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot func…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-51251
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup func…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-51253
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP func…
Vigor3900 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-10035
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Impro…
Coslat
after 3.1069
HIGH 7.2
CVE-2024-51661
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant med…
Media Library Assistant
3.20+
CRITICAL 9.8
CVE-2024-51252
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore fun…
Vigor3900 Firmware
No fix yet
HIGH 8.8
CVE-2024-51244
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec fun…
Vigor3900 Firmware
No fix yet
HIGH 8.8
CVE-2024-51245
In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_tabl…
Vigor3900 Firmware
No fix yet
HIGH 8.8
CVE-2024-51247
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo func…
Vigor3900 Firmware
No fix yet
HIGH 8.8
CVE-2024-51248
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow f…
Vigor3900 Firmware
No fix yet
HIGH 7.2
CVE-2024-10653
IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attacke…
Mitigation only
MEDIUM 6.5
CVE-2024-8934
A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manag…
Mitigation only
HIGH 8.8
CVE-2024-36060
EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test parameters.
Mitigation only
CRITICAL 9.8
CVE-2024-51378 KEVEPSS 95%
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and e…
Cyberpanel
2.3.8+
CRITICAL 9.8
CVE-2024-51568EPSS 45%
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filem…
Cyberpanel
2.3.5+
HIGH 7.2
CVE-2024-41153
Command injection vulnerability in the Edge Computing UI for the
TRO600 series radios that allows for the execution of arbitrary system commands. If …
Tro610 Firmware
9.2.0.5+
HIGH 8.8
CVE-2024-22065
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authent…
Mf258k Pro Firmware
Mitigation only
HIGH 8.8
CVE-2024-48825
Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
Ac7 Firmware
No fix yet
HIGH 8.8
CVE-2024-48826
Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
Ac7 Firmware
No fix yet
HIGH 8.0
CVE-2024-48074
An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table …
Vigor2960 Firmware
No fix yet
HIGH 7.2
CVE-2024-37845
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.
Mango
5.2.0+
HIGH 7.3
CVE-2024-48459EPSS 8%
A command execution vulnerability exists in the AX2 Pro home router produced by Shenzhen Tenda Technology Co., Ltd. (Jixiang Tenda) v.DI_7003G-19.12.…
Mitigation only
HIGH 7.5
CVE-2024-49380
Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an …
Plenti
0.7.2+