Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2024-38512 A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform command inj… Mitigation only Fix from $1,9502024-07-26 HIGH 7.2 CVE-2024-38508 A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC that could allow an authentica… Mitigation only Fix from $1,9502024-07-26 CRITICAL 9.8 CVE-2024-7120EPSS 93% A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of… Msg2300 Firmware No fix yet Fix from $2,3002024-07-26 CRITICAL 9.8 CVE-2024-41468 Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand Fh1201 Firmware Mitigation only Fix from $2,3002024-07-25 CRITICAL 9.8 CVE-2024-41473EPSS 7% Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac Fh1201 Firmware No fix yet Fix from $2,3002024-07-25 HIGH 8.8 CVE-2024-24622 Softaculous Webuzo contains a command injection in the password reset functionality. A remote, authenticated attacker can exploit this vulnerability … Webuzo 4.2.9+ Fix from $1,9502024-07-25 HIGH 8.8 CVE-2024-24623 Softaculous Webuzo contains a command injection vulnerability in the FTP management functionality. A remote, authenticated attacker can exploit this … Webuzo 4.2.9+ Fix from $1,9502024-07-25 HIGH 8.8 CVE-2024-41136 An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful ex… Edgeconnect Sd Wan Orchestrator after 9.2.9 Fix from $1,9502024-07-24 HIGH 7.2 CVE-2024-39345 AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented, hard-coded support account w… Sdg Smartos 12.1.3.1+ Fix from $1,9502024-07-24 HIGH 8.8 CVE-2024-31977 Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via shell metacharacters to the Pi… Sdg Smartos 12.5.5.1+ Fix from $1,9502024-07-24 CRITICAL 9.8 CVE-2024-7066 A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of t… Datacube3 Firmware No fix yet Fix from $2,3002024-07-24 CRITICAL 9.8 CVE-2024-39685 Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with sub… Bert Vits2 after 2.3 Fix from $2,3002024-07-22 CRITICAL 9.8 CVE-2024-39686 Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with sub… Bert Vits2 after 2.3 Fix from $2,3002024-07-22 MEDIUM 6.8 CVE-2024-41314 TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function. A6000r Firmware No fix yet Fix from $1,6002024-07-22 MEDIUM 6.8 CVE-2024-41315 TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wp… A6000r Firmware No fix yet Fix from $1,6002024-07-22 HIGH 8.0 CVE-2024-41317 TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wp… A6000r Firmware No fix yet Fix from $1,9502024-07-22 HIGH 7.8 CVE-2024-37391 ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in… Protonvpn 3.2.10+ Fix from $1,9502024-07-22 HIGH 8.8 CVE-2024-37066 A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands ov… Cam V4 Firmware after 4.52.4.9887 Fix from $1,9502024-07-19 HIGH 7.8 CVE-2024-34013 Local privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True Image (macOS) before build 41… Mitigation only Fix from $1,9502024-07-18 HIGH 7.4 CVE-2024-40641 Nuclei is a fast and customizable vulnerability scanner based on simple YAML based DSL. In affected versions it a way to execute code template witho… Mitigation only Fix from $1,9502024-07-17 HIGH 8.8 CVE-2024-36475 FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows… Futurenet Nxr 1300 Firmware 6.23.11 / 7.4.10+ Fix from $1,9502024-07-17 CRITICAL 9.8 CVE-2024-36491 FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command… Futurenet Nxr 1300 Firmware 6.23.11 / 7.4.10+ Fix from $2,3002024-07-17 CRITICAL 9.8 CVE-2019-16639 An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attacker (who… Eg 2000se Firmware No fix yet Fix from $2,3002024-07-16 HIGH 7.8 CVE-2024-39521 An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker wit… Junos Os Evolved 21.2+ Fix from $1,9502024-07-11 HIGH 7.8 CVE-2024-39522 An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker wit… Junos Os Evolved Mitigation only Fix from $1,9502024-07-11 HIGH 7.8 CVE-2024-39523 An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker wit… Junos Os Evolved 20.4+ Fix from $1,9502024-07-11 HIGH 7.8 CVE-2024-39524 An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker wit… Junos Os Evolved 20.4+ Fix from $1,9502024-07-11 HIGH 7.8 CVE-2024-39520 An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker wit… Junos Os Evolved 20.4+ Fix from $1,9502024-07-11 HIGH 8.7 CVE-2024-3799EPSS 15% Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source project Phoniebox allows an attacke… Mitigation only Fix from $1,9502024-07-10 HIGH 8.7 CVE-2024-3798 Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker… Mitigation only Fix from $1,9502024-07-10