Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.0 CVE-2024-45889 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45890 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cg… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45891 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45893 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45882 DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45884 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-51246 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP func… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-51249 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot func… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-51251 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup func… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-51253 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP func… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 CRITICAL 9.8 CVE-2024-10035 Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Impro… Coslat after 3.1069 Fix from $2,3002024-11-04 HIGH 7.2 CVE-2024-51661 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant med… Media Library Assistant 3.20+ Fix from $1,9502024-11-04 CRITICAL 9.8 CVE-2024-51252 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore fun… Vigor3900 Firmware No fix yet Fix from $2,3002024-11-01 HIGH 8.8 CVE-2024-51244 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec fun… Vigor3900 Firmware No fix yet Fix from $1,9502024-11-01 HIGH 8.8 CVE-2024-51245 In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_tabl… Vigor3900 Firmware No fix yet Fix from $1,9502024-11-01 HIGH 8.8 CVE-2024-51247 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo func… Vigor3900 Firmware No fix yet Fix from $1,9502024-11-01 HIGH 8.8 CVE-2024-51248 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow f… Vigor3900 Firmware No fix yet Fix from $1,9502024-11-01 HIGH 7.2 CVE-2024-10653 IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attacke… Mitigation only Fix from $1,9502024-11-01 MEDIUM 6.5 CVE-2024-8934 A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manag… Mitigation only Fix from $1,6002024-10-31 HIGH 8.8 CVE-2024-36060 EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test parameters. Mitigation only Fix from $1,9502024-10-30 CRITICAL 9.8 CVE-2024-51378 KEVEPSS 95% getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and e… Cyberpanel 2.3.8+ Fix from $2,3002024-10-29 CRITICAL 9.8 CVE-2024-51568EPSS 45% CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filem… Cyberpanel 2.3.5+ Fix from $2,3002024-10-29 HIGH 7.2 CVE-2024-41153 Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If … Tro610 Firmware 9.2.0.5+ Fix from $1,9502024-10-29 HIGH 8.8 CVE-2024-22065 There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authent… Mf258k Pro Firmware Mitigation only Fix from $1,9502024-10-29 HIGH 8.8 CVE-2024-48825 Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code. Ac7 Firmware No fix yet Fix from $1,9502024-10-28 HIGH 8.8 CVE-2024-48826 Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code. Ac7 Firmware No fix yet Fix from $1,9502024-10-28 HIGH 8.0 CVE-2024-48074 An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table … Vigor2960 Firmware No fix yet Fix from $1,9502024-10-28 HIGH 7.2 CVE-2024-37845 MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature. Mango 5.2.0+ Fix from $1,9502024-10-25 HIGH 7.3 CVE-2024-48459EPSS 8% A command execution vulnerability exists in the AX2 Pro home router produced by Shenzhen Tenda Technology Co., Ltd. (Jixiang Tenda) v.DI_7003G-19.12.… Mitigation only Fix from $1,9502024-10-25 HIGH 7.5 CVE-2024-49380 Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an … Plenti 0.7.2+ Fix from $1,9502024-10-25