Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-77 Clear
ID Title
CVE-2024-48419 Command Injection in edimax (CVE-2024-48419)
command injection in edimax (CVE-2024-48419). Successful exploitation can lead to full system takeover.
CVE-2025-22912 Command Injection in edimax (CVE-2025-22912)
command injection in edimax (CVE-2025-22912). Successful exploitation can lead to full system takeover.
CVE-2024-12356 KEV [KEV] Command Injection in Beyondtrust privileged-remote-access-pra-and-remote-support-rs (CVE-2024-12356)
command injection in Beyondtrust privileged-remote-access-pra-and-remote-support-rs (CVE-2024-12356). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-55956 KEV [KEV] Command Injection in Cleo multiple-products (CVE-2024-55956)
command injection in Cleo multiple-products (CVE-2024-55956). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2024-9474 KEV [KEV] OS Command Injection in Palo alto networks palo-alto-networks (CVE-2024-9474)
OS command injection in Palo alto networks palo-alto-networks (CVE-2024-9474). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2024-10035 Command Injection in privilege-escalation (CVE-2024-10035)
command injection in privilege-escalation (CVE-2024-10035). Successful exploitation can lead to full system takeover.
CVE-2024-40089 Command Injection in viloliving (CVE-2024-40089)
command injection in viloliving (CVE-2024-40089). Successful exploitation can lead to full system takeover.
CVE-2024-9380 KEV [KEV] Command Injection in Ivanti cloud-services-appliance-csa (CVE-2024-9380)
command injection in Ivanti cloud-services-appliance-csa (CVE-2024-9380). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-46084 Command Injection in scriptcase (CVE-2024-46084)
command injection in scriptcase (CVE-2024-46084). Successful exploitation can lead to full system takeover.
CVE-2024-44570 Command Injection in relyum (CVE-2024-44570)
command injection in relyum (CVE-2024-44570). Successful exploitation can lead to full system takeover.
CVE-2024-44572 Command Injection in relyum (CVE-2024-44572)
command injection in relyum (CVE-2024-44572). Successful exploitation can lead to full system takeover.
CVE-2024-44574 Command Injection in relyum (CVE-2024-44574)
command injection in relyum (CVE-2024-44574). Successful exploitation can lead to full system takeover.
CVE-2024-44577 Command Injection in relyum (CVE-2024-44577)
command injection in relyum (CVE-2024-44577). Successful exploitation can lead to full system takeover.
CVE-2024-44916 Command Injection in seacms (CVE-2024-44916)
command injection in seacms (CVE-2024-44916). Successful exploitation can lead to full system takeover.
CVE-2024-4944 Command Injection in privilege-escalation (CVE-2024-4944)
command injection in privilege-escalation (CVE-2024-4944). Successful exploitation can lead to full system takeover.
CVE-2024-35401 Command Injection in totolink (CVE-2024-35401)
command injection in totolink (CVE-2024-35401). Risk of unauthorized operations or information disclosure.
CVE-2024-35397 Command Injection in totolink (CVE-2024-35397)
command injection in totolink (CVE-2024-35397). Successful exploitation can lead to full system takeover.
CVE-2024-28328 Command Injection in CVE-2024-28328 (CVE-2024-28328)
command injection in CVE-2024-28328 (CVE-2024-28328). Risk of unauthorized operations or information disclosure.
CVE-2024-3154 Command Injection in CVE-2024-3154 (CVE-2024-3154)
command injection in CVE-2024-3154 (CVE-2024-3154). Successful exploitation can lead to full system takeover.
CVE-2024-3400 KEV [KEV] Vulnerability in Palo alto networks palo-alto-networks (CVE-2024-3400)
vulnerability in Palo alto networks palo-alto-networks (CVE-2024-3400). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-3273 KEV [KEV] Command Injection in D-link multiple-nas-devices (CVE-2024-3273)
command injection in D-link multiple-nas-devices (CVE-2024-3273). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-3566 Command Injection in node (CVE-2024-3566)
command injection in node (CVE-2024-3566). Successful exploitation can lead to full system takeover. Exploitable via ``cmd.exe``. Mitigation: upgrade to `18.19.0` or later.
CVE-2024-20667 Azure DevOps Server Remote Code Execution Vulnerability
Azure DevOps Server Remote Code Execution Vulnerability
CVE-2024-24321 Command Injection in dlink (CVE-2024-24321)
command injection in dlink (CVE-2024-24321). Successful exploitation can lead to full system takeover.
CVE-2024-22900 Command Injection in vinchin (CVE-2024-22900)
command injection in vinchin (CVE-2024-22900). Successful exploitation can lead to full system takeover.
CVE-2024-22903 Command Injection in vinchin (CVE-2024-22903)
command injection in vinchin (CVE-2024-22903). Successful exploitation can lead to full system takeover.
CVE-2024-21488 Command Injection in forkhq (CVE-2024-21488)
command injection in forkhq (CVE-2024-21488). Risk of unauthorized operations or information disclosure.
CVE-2023-24135 Command Injection in jensenofscandinavia (CVE-2023-24135)
command injection in jensenofscandinavia (CVE-2023-24135). Successful exploitation can lead to full system takeover.
CVE-2024-21887 KEV [KEV] Command Injection in Ivanti connect-secure-and-policy-secure (CVE-2024-21887)
command injection in Ivanti connect-secure-and-policy-secure (CVE-2024-21887). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2016-20017 KEV [KEV] Command Injection in D-link dsl-2750b-devices (CVE-2016-20017)
command injection in D-link dsl-2750b-devices (CVE-2016-20017). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2023-50989 Command Injection in tenda (CVE-2023-50989)
command injection in tenda (CVE-2023-50989). Successful exploitation can lead to full system takeover.
CVE-2023-50983 Command Injection in tenda (CVE-2023-50983)
command injection in tenda (CVE-2023-50983). Successful exploitation can lead to full system takeover.
CVE-2023-1671 KEV [KEV] Command Injection in Sophos web-appliance (CVE-2023-1671)
command injection in Sophos web-appliance (CVE-2023-1671). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2023-39637 Command Injection in dlink (CVE-2023-39637)
command injection in dlink (CVE-2023-39637). Successful exploitation can lead to full system takeover.
CVE-2023-39809 Command Injection in nvki (CVE-2023-39809)
command injection in nvki (CVE-2023-39809). Successful exploitation can lead to full system takeover.
CVE-2023-35390 .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2023-37679 Command Injection in nextgen (CVE-2023-37679)
command injection in nextgen (CVE-2023-37679). Successful exploitation can lead to full system takeover.
CVE-2023-34960 Command Injection in chamilo (CVE-2023-34960)
command injection in chamilo (CVE-2023-34960). Successful exploitation can lead to full system takeover.
CVE-2023-20887 KEV [KEV] Command Injection in Vmware aria-operations-for-networks (CVE-2023-20887)
command injection in Vmware aria-operations-for-networks (CVE-2023-20887). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2023-33782 Command Injection in dlink (CVE-2023-33782)
command injection in dlink (CVE-2023-33782). Successful exploitation can lead to full system takeover.
CVE-2023-31569 Command Injection in totolink (CVE-2023-31569)
command injection in totolink (CVE-2023-31569). Successful exploitation can lead to full system takeover.
CVE-2023-33532 Command Injection in netgear (CVE-2023-33532)
command injection in netgear (CVE-2023-33532). Successful exploitation can lead to full system takeover.
CVE-2023-33530 Command Injection in tenda (CVE-2023-33530)
command injection in tenda (CVE-2023-33530). Successful exploitation can lead to full system takeover.
CVE-2023-31740 Command Injection in linksys (CVE-2023-31740)
command injection in linksys (CVE-2023-31740). Successful exploitation can lead to full system takeover.
CVE-2023-31741 Command Injection in linksys (CVE-2023-31741)
command injection in linksys (CVE-2023-31741). Successful exploitation can lead to full system takeover.
CVE-2023-31742 Command Injection in linksys (CVE-2023-31742)
command injection in linksys (CVE-2023-31742). Successful exploitation can lead to full system takeover.
CVE-2023-31729 TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
CVE-2023-1389 KEV [KEV] Command Injection in Tp-link archer-ax21 (CVE-2023-1389)
command injection in Tp-link archer-ax21 (CVE-2023-1389). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2023-2376 Vulnerability in ui (CVE-2023-2376)
vulnerability in ui (CVE-2023-2376). Successful exploitation can lead to full system takeover.
CVE-2023-2378 Vulnerability in ui (CVE-2023-2378)
vulnerability in ui (CVE-2023-2378). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →