Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.3 CVE-2024-42370 Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulner… Patch available Fix from $1,9502024-08-12 HIGH 7.2 CVE-2024-42166 The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Comma… Keyrock after 8.4 Fix from $1,9502024-08-12 HIGH 7.2 CVE-2024-42167 The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Co… Keyrock after 8.4 Fix from $1,9502024-08-12 CRITICAL 9.8 CVE-2024-21878 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) all… Iq Gateway Firmware 8.2.4225+ Fix from $2,3002024-08-12 HIGH 8.8 CVE-2024-21879 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoin… Iq Gateway Firmware 8.2.4225+ Fix from $1,9502024-08-12 HIGH 7.2 CVE-2024-21880 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint i… Iq Gateway Firmware after 7.3.120 Fix from $1,9502024-08-12 HIGH 7.2 CVE-2024-3659 Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one… Ar2140 Firmware 4.2.16+ Fix from $1,9502024-08-08 CRITICAL 9.8 CVE-2024-7580EPSS 9% A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been rated as critical. Affected by this issue is some unknown funct… Alr F800 Firmware after 19.10.24.00 Fix from $2,3002024-08-07 HIGH 8.8 CVE-2024-7579EPSS 8% A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by this vulnerability is the fun… Alr F800 Firmware after 19.10.24 Fix from $1,9502024-08-07 CRITICAL 9.8 CVE-2024-39228 GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4… Mt6000 Firmware No fix yet Fix from $2,3002024-08-06 CRITICAL 9.8 CVE-2024-23483 An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connec… Client Connector 4.2+ Fix from $2,3002024-08-06 CRITICAL 9.8 CVE-2024-7469EPSS 25% A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been declared as critical. This vulnerability affects the f… Msg2300 Firmware No fix yet Fix from $2,3002024-08-05 CRITICAL 9.8 CVE-2024-7470EPSS 25% A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been rated as critical. This issue affects the function ssl… Msg2300 Firmware No fix yet Fix from $2,3002024-08-05 CRITICAL 9.8 CVE-2024-7467EPSS 23% A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 and classified as critical. Affected by this issue is the function … Msg2300 Firmware No fix yet Fix from $2,3002024-08-05 CRITICAL 9.8 CVE-2024-7468EPSS 25% A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been classified as critical. This affects the function sslv… Msg2300 Firmware No fix yet Fix from $2,3002024-08-05 CRITICAL 9.8 CVE-2024-38887 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand … Caterease after 24.0.1.2405 Fix from $2,3002024-08-02 CRITICAL 9.8 CVE-2024-38889 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform… Caterease after 24.0.1.2405 Fix from $2,3002024-08-02 HIGH 7.2 CVE-2024-33896 Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blackl… Ewon Cosy\+ Firmware after 22.1s3 Fix from $1,9502024-08-02 CRITICAL 9.8 CVE-2024-38882 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform… Caterease after 24.0.1.2405 Fix from $2,3002024-08-02 HIGH 8.1 CVE-2024-41956 Soft Serve is a self-hostable Git server for the command line. Prior to 0.7.5, it is possible for a user who can commit files to a repository hosted … Patch available Fix from $1,9502024-08-01 CRITICAL 9.8 CVE-2024-7357EPSS 6% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-600 up to 2.18. It has been rated as critical. This issue affects the functio… Dir 600 Firmware after 2.18 Fix from $2,3002024-08-01 MEDIUM 6.8 CVE-2024-39607 OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product by a logged… Mitigation only Fix from $1,6002024-08-01 MEDIUM 6.4 CVE-2024-40895 FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticated attacker… Mitigation only Fix from $1,6002024-07-30 CRITICAL 9.8 CVE-2024-5670 The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remo… Sn Os Mitigation only Fix from $2,3002024-07-29 HIGH 8.8 CVE-2024-7175 A vulnerability has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. This vulnerability affects the function setDiagn… A3600r Firmware No fix yet Fix from $1,9502024-07-29 HIGH 8.8 CVE-2024-7171 A vulnerability classified as critical has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected is the function NTPSyncWithHost of the file… A3600r Firmware No fix yet Fix from $1,9502024-07-28 MEDIUM 6.3 CVE-2024-42029 xdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e.g., because single quotes ar… Patch available Fix from $1,6002024-07-27 HIGH 7.0 CVE-2024-41815 Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quotin… Starship 1.20.0+ Fix from $1,9502024-07-26 HIGH 7.2 CVE-2024-38510 A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user with elevat… Mitigation only Fix from $1,9502024-07-26 HIGH 7.2 CVE-2024-38511 A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with elev… Mitigation only Fix from $1,9502024-07-26