Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2024-21898 An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… Qts Mitigation only Fix from $1,9502024-09-06 HIGH 7.2 CVE-2023-39300 An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allow authenticated administrator… Qts Mitigation only Fix from $1,9502024-09-06 HIGH 8.8 CVE-2023-47563 An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to e… Video Station 5.8.2+ Fix from $1,9502024-09-06 HIGH 8.8 CVE-2023-34974 An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… Qts Mitigation only Fix from $1,9502024-09-06 HIGH 7.2 CVE-2023-34979 An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… Qts Mitigation only Fix from $1,9502024-09-06 CRITICAL 9.8 CVE-2024-8517EPSS 95% SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary opera… Spip 4.1.18+ Fix from $2,3002024-09-06 HIGH 7.2 CVE-2024-7591EPSS 44% Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * E… Loadmaster 7.1.35.11+ Fix from $1,9502024-09-05 MEDIUM 6.7 CVE-2024-20469 A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command inje… Identity Services Engine Mitigation only Fix from $1,6002024-09-04 HIGH 8.8 CVE-2024-43402 Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments when invoking batch files on … Rust 1.81.0+ Fix from $1,9502024-09-04 HIGH 7.8 CVE-2024-43405 Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's … Nuclei 3.3.2+ Fix from $1,9502024-09-04 CRITICAL 9.8 CVE-2024-7261EPSS 11% The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and ear… Nwa110ax Firmware 6.28 / 6.70+ Fix from $2,3002024-09-03 HIGH 7.2 CVE-2024-7203 A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware ver… Zld 5.39+ Fix from $1,9502024-09-03 HIGH 8.1 CVE-2024-42057 A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware v… Zld 5.39+ Fix from $1,9502024-09-03 HIGH 7.2 CVE-2024-42059 A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versio… Zld 5.39+ Fix from $1,9502024-09-03 HIGH 7.2 CVE-2024-42060 A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versio… Zld 5.39+ Fix from $1,9502024-09-03 CRITICAL 9.8 CVE-2024-8234 ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NW… Nwaw1100 N Firmware No fix yet Fix from $2,3002024-08-30 HIGH 8.8 CVE-2024-43804 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated… Roxy Wi No fix yet Fix from $1,9502024-08-29 CRITICAL 9.8 CVE-2024-8213EPSS 7% A vulnerability classified as critical has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323… Dns 315l Firmware No fix yet Fix from $2,3002024-08-27 CRITICAL 9.8 CVE-2024-8214EPSS 5% A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS… Dns 315l Firmware No fix yet Fix from $2,3002024-08-27 CRITICAL 9.8 CVE-2024-8210EPSS 7% A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L… Dns 315l Firmware No fix yet Fix from $2,3002024-08-27 CRITICAL 9.8 CVE-2024-8211EPSS 5% A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L… Dns 315l Firmware No fix yet Fix from $2,3002024-08-27 CRITICAL 9.8 CVE-2024-41622 D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HN… Dir 846w Firmware Mitigation only Fix from $2,3002024-08-27 HIGH 8.8 CVE-2024-44340 D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_n… Dir 846w Firmware Mitigation only Fix from $1,9502024-08-27 CRITICAL 9.8 CVE-2024-44341 D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This … Dir 846w Firmware Mitigation only Fix from $2,3002024-08-27 CRITICAL 9.8 CVE-2024-44342 D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerabi… Dir 846w Firmware Mitigation only Fix from $2,3002024-08-27 HIGH 8.8 CVE-2023-26315EPSS 19% The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allo… Ax9000 Firmware 1.0.174+ Fix from $1,9502024-08-26 CRITICAL 9.8 CVE-2024-8134EPSS 8% A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L… Dns 1550 04 Firmware No fix yet Fix from $2,3002024-08-24 CRITICAL 9.8 CVE-2024-8133EPSS 8% A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L… Dns 1550 04 Firmware No fix yet Fix from $2,3002024-08-24 CRITICAL 9.8 CVE-2024-8131EPSS 8% A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L… Dns 1550 04 Firmware No fix yet Fix from $2,3002024-08-24 CRITICAL 9.8 CVE-2024-8132EPSS 23% A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L… Dns 1550 04 Firmware No fix yet Fix from $2,3002024-08-24