Vulnerabilities (CVE)

Filtered by CWE-77
Total 2455 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-54006 2025-01-07 N/A 7.2 HIGH
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system.
CVE-2024-43613 1 Microsoft 1 Azure Database For Postgresql Flexible Server 2025-01-07 N/A 7.2 HIGH
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
CVE-2024-49042 1 Microsoft 1 Azure Database For Postgresql Flexible Server 2025-01-07 N/A 7.2 HIGH
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
CVE-2023-20889 1 Vmware 1 Vrealize Network Insight 2025-01-07 N/A 7.5 HIGH
Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure.
CVE-2023-33556 1 Totolink 2 A7100ru, A7100ru Firmware 2025-01-07 N/A 9.8 CRITICAL
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.
CVE-2023-33782 1 Dlink 2 Dir-842v2, Dir-842v2 Firmware 2025-01-06 N/A 8.8 HIGH
D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.
CVE-2023-26294 1 Hp 1 Hp Device Manager 2025-01-06 N/A 7.8 HIGH
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
CVE-2024-13062 2025-01-02 N/A 7.2 HIGH
An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. Refer to the ' 01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
CVE-2024-12912 2025-01-02 N/A 7.2 HIGH
An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. Refer to the '01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
CVE-2023-35390 1 Microsoft 2 .net, Visual Studio 2022 2025-01-01 N/A 7.8 HIGH
.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2024-12985 2024-12-27 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical was found in Overtek OT-E801G OTE801G65.1.1.0. This vulnerability affects unknown code of the file /diag_ping.cmd?action=test&interface=ppp0.1&ipaddr=8.8.8.8%26%26cat%20/etc/passwd&ipversion=4&sessionKey=test. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2020-13712 2024-12-26 N/A 7.8 HIGH
A command injection is possible through the user interface, allowing arbitrary command execution as the root user. oMG2000 running MGOS 3.15.1 or earlier is affected.  MG90 running MGOS 4.2.1 or earlier is affected.
CVE-2024-25255 2024-12-24 N/A 9.8 CRITICAL
Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties report that this is intended behavior.
CVE-2024-42427 1 Dell 1 Wyse Thinos 2024-12-20 N/A 7.6 HIGH
Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVE-2024-12111 2024-12-19 N/A 8.0 HIGH
In a specific scenario a LDAP user can abuse the authentication process in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5)
CVE-2023-23356 2024-12-19 N/A 5.5 MEDIUM
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QuFirewall 2.3.3 ( 2023/03/27 ) and later and later
CVE-2024-39703 2024-12-18 N/A 8.8 HIGH
In ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary commands by sending a crafted request to an API endpoint.
CVE-2024-10966 1 Totolink 2 X18, X18 Firmware 2024-12-16 6.5 MEDIUM 6.3 MEDIUM
A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-36604 1 Tenda 2 O3, O3 Firmware 2024-12-13 N/A 9.8 CRITICAL
Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.
CVE-2024-29404 2024-12-13 N/A 7.8 HIGH
An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter of the Chroma Effects function in the Profiles component.