Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2024-8130EPSS 8% A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS… Dns 1550 04 Firmware No fix yet Fix from $2,3002024-08-24 CRITICAL 9.8 CVE-2024-8129EPSS 23% A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, … Dns 1550 04 Firmware No fix yet Fix from $2,3002024-08-24 CRITICAL 9.8 CVE-2024-8128EPSS 8% A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-3… Dns 1550 04 Firmware No fix yet Fix from $2,3002024-08-24 CRITICAL 9.8 CVE-2024-8127EPSS 7% A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS… Dns 1550 04 Firmware No fix yet Fix from $2,3002024-08-24 CRITICAL 9.8 CVE-2024-8077 A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been classified as critical. This affects the function setTracerouteCfg… T8 Firmware No fix yet Fix from $2,3002024-08-22 CRITICAL 9.8 CVE-2024-8075 A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this vulnerability is the function… T8 Firmware Mitigation only Fix from $2,3002024-08-22 HIGH 8.0 CVE-2024-7448 Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitra… Axiom Mitigation only Fix from $1,9502024-08-21 HIGH 7.8 CVE-2020-11847 SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged … Netiq Privileged Access Manager 3.7+ Fix from $1,9502024-08-21 HIGH 8.8 CVE-2024-42633 A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authentica… E1500 Firmware No fix yet Fix from $1,9502024-08-19 CRITICAL 9.8 CVE-2024-42757 Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page. Mitigation only Fix from $2,3002024-08-15 CRITICAL 9.8 CVE-2024-42978 An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP req… Fh1206 Firmware No fix yet Fix from $2,3002024-08-15 HIGH 8.4 CVE-2024-39401 Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an … Commerce after 2.4.3 Fix from $1,9502024-08-14 HIGH 8.4 CVE-2024-39402 Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an … Commerce after 2.4.3 Fix from $1,9502024-08-14 HIGH 7.2 CVE-2024-7728 The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to injec… Mitigation only Fix from $1,9502024-08-14 HIGH 7.8 CVE-2022-27486 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2… Fortiddos 5.6.2 / 6.4.2+ Fix from $1,9502024-08-13 MEDIUM 6.8 CVE-2024-42740 In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated … X5000r Firmware No fix yet Fix from $1,6002024-08-13 HIGH 7.8 CVE-2024-42736 In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticat… X5000r Firmware No fix yet Fix from $1,9502024-08-13 HIGH 8.8 CVE-2024-42737 In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticat… X5000r Firmware No fix yet Fix from $1,9502024-08-13 HIGH 8.8 CVE-2024-42738 In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. Authenticated … X5000r Firmware No fix yet Fix from $1,9502024-08-13 HIGH 8.8 CVE-2024-42739 In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authe… X5000r Firmware No fix yet Fix from $1,9502024-08-13 HIGH 8.8 CVE-2024-42743 In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . Authentica… X5000r Firmware No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42744 In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setModifyVpnUser. Authent… X5000r Firmware No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42745 In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated… X5000r Firmware No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42747 In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticate… X5000r Firmware No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42748 In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. Authentica… X5000r Firmware No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42741 In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfg. Authent… X5000r Firmware No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42742 In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUrlFilterRules. Authen… X5000r Firmware No fix yet Fix from $1,9502024-08-12 MEDIUM 6.8 CVE-2024-40893 Multiple authenticated operating system (OS) command injection vulnerabilities exist in Firewalla Box Software versions before 1.979. A physically c… Mitigation only Fix from $1,6002024-08-12 HIGH 8.8 CVE-2024-39091 An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the sam… Crater 2 Firmware Mitigation only Fix from $1,9502024-08-12 CRITICAL 9.8 CVE-2024-6917 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Veribilim Software Veribase Order Managem… Order Management 4.010.2+ Fix from $2,3002024-08-12