Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-48419 |
|
Command Injection in edimax (CVE-2024-48419)
command injection in edimax (CVE-2024-48419). Successful exploitation can lead to full system takeover.
|
| CVE-2025-22912 |
|
Command Injection in edimax (CVE-2025-22912)
command injection in edimax (CVE-2025-22912). Successful exploitation can lead to full system takeover.
|
| CVE-2024-12356 KEV |
|
[KEV] Command Injection in Beyondtrust privileged-remote-access-pra-and-remote-support-rs (CVE-2024-12356)
command injection in Beyondtrust privileged-remote-access-pra-and-remote-support-rs (CVE-2024-12356). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-55956 KEV |
|
[KEV] Command Injection in Cleo multiple-products (CVE-2024-55956)
command injection in Cleo multiple-products (CVE-2024-55956). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-9474 KEV |
|
[KEV] OS Command Injection in Palo alto networks palo-alto-networks (CVE-2024-9474)
OS command injection in Palo alto networks palo-alto-networks (CVE-2024-9474). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-10035 |
|
Command Injection in privilege-escalation (CVE-2024-10035)
command injection in privilege-escalation (CVE-2024-10035). Successful exploitation can lead to full system takeover.
|
| CVE-2024-40089 |
|
Command Injection in viloliving (CVE-2024-40089)
command injection in viloliving (CVE-2024-40089). Successful exploitation can lead to full system takeover.
|
| CVE-2024-9380 KEV |
|
[KEV] Command Injection in Ivanti cloud-services-appliance-csa (CVE-2024-9380)
command injection in Ivanti cloud-services-appliance-csa (CVE-2024-9380). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-46084 |
|
Command Injection in scriptcase (CVE-2024-46084)
command injection in scriptcase (CVE-2024-46084). Successful exploitation can lead to full system takeover.
|
| CVE-2024-44570 |
|
Command Injection in relyum (CVE-2024-44570)
command injection in relyum (CVE-2024-44570). Successful exploitation can lead to full system takeover.
|
| CVE-2024-44572 |
|
Command Injection in relyum (CVE-2024-44572)
command injection in relyum (CVE-2024-44572). Successful exploitation can lead to full system takeover.
|
| CVE-2024-44574 |
|
Command Injection in relyum (CVE-2024-44574)
command injection in relyum (CVE-2024-44574). Successful exploitation can lead to full system takeover.
|
| CVE-2024-44577 |
|
Command Injection in relyum (CVE-2024-44577)
command injection in relyum (CVE-2024-44577). Successful exploitation can lead to full system takeover.
|
| CVE-2024-44916 |
|
Command Injection in seacms (CVE-2024-44916)
command injection in seacms (CVE-2024-44916). Successful exploitation can lead to full system takeover.
|
| CVE-2024-4944 |
|
Command Injection in privilege-escalation (CVE-2024-4944)
command injection in privilege-escalation (CVE-2024-4944). Successful exploitation can lead to full system takeover.
|
| CVE-2024-35401 |
|
Command Injection in totolink (CVE-2024-35401)
command injection in totolink (CVE-2024-35401). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-35397 |
|
Command Injection in totolink (CVE-2024-35397)
command injection in totolink (CVE-2024-35397). Successful exploitation can lead to full system takeover.
|
| CVE-2024-28328 |
|
Command Injection in CVE-2024-28328 (CVE-2024-28328)
command injection in CVE-2024-28328 (CVE-2024-28328). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-3154 |
|
Command Injection in CVE-2024-3154 (CVE-2024-3154)
command injection in CVE-2024-3154 (CVE-2024-3154). Successful exploitation can lead to full system takeover.
|
| CVE-2024-3400 KEV |
|
[KEV] Vulnerability in Palo alto networks palo-alto-networks (CVE-2024-3400)
vulnerability in Palo alto networks palo-alto-networks (CVE-2024-3400). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-3273 KEV |
|
[KEV] Command Injection in D-link multiple-nas-devices (CVE-2024-3273)
command injection in D-link multiple-nas-devices (CVE-2024-3273). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-3566 |
|
Command Injection in node (CVE-2024-3566)
command injection in node (CVE-2024-3566). Successful exploitation can lead to full system takeover. Exploitable via ``cmd.exe``. Mitigation: upgrade to `18.19.0` or later.
|
| CVE-2024-20667 |
|
Azure DevOps Server Remote Code Execution Vulnerability
Azure DevOps Server Remote Code Execution Vulnerability
|
| CVE-2024-24321 |
|
Command Injection in dlink (CVE-2024-24321)
command injection in dlink (CVE-2024-24321). Successful exploitation can lead to full system takeover.
|
| CVE-2024-22900 |
|
Command Injection in vinchin (CVE-2024-22900)
command injection in vinchin (CVE-2024-22900). Successful exploitation can lead to full system takeover.
|
| CVE-2024-22903 |
|
Command Injection in vinchin (CVE-2024-22903)
command injection in vinchin (CVE-2024-22903). Successful exploitation can lead to full system takeover.
|
| CVE-2024-21488 |
|
Command Injection in forkhq (CVE-2024-21488)
command injection in forkhq (CVE-2024-21488). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-24135 |
|
Command Injection in jensenofscandinavia (CVE-2023-24135)
command injection in jensenofscandinavia (CVE-2023-24135). Successful exploitation can lead to full system takeover.
|
| CVE-2024-21887 KEV |
|
[KEV] Command Injection in Ivanti connect-secure-and-policy-secure (CVE-2024-21887)
command injection in Ivanti connect-secure-and-policy-secure (CVE-2024-21887). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2016-20017 KEV |
|
[KEV] Command Injection in D-link dsl-2750b-devices (CVE-2016-20017)
command injection in D-link dsl-2750b-devices (CVE-2016-20017). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-50989 |
|
Command Injection in tenda (CVE-2023-50989)
command injection in tenda (CVE-2023-50989). Successful exploitation can lead to full system takeover.
|
| CVE-2023-50983 |
|
Command Injection in tenda (CVE-2023-50983)
command injection in tenda (CVE-2023-50983). Successful exploitation can lead to full system takeover.
|
| CVE-2023-1671 KEV |
|
[KEV] Command Injection in Sophos web-appliance (CVE-2023-1671)
command injection in Sophos web-appliance (CVE-2023-1671). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-39637 |
|
Command Injection in dlink (CVE-2023-39637)
command injection in dlink (CVE-2023-39637). Successful exploitation can lead to full system takeover.
|
| CVE-2023-39809 |
|
Command Injection in nvki (CVE-2023-39809)
command injection in nvki (CVE-2023-39809). Successful exploitation can lead to full system takeover.
|
| CVE-2023-35390 |
|
.NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
|
| CVE-2023-37679 |
|
Command Injection in nextgen (CVE-2023-37679)
command injection in nextgen (CVE-2023-37679). Successful exploitation can lead to full system takeover.
|
| CVE-2023-34960 |
|
Command Injection in chamilo (CVE-2023-34960)
command injection in chamilo (CVE-2023-34960). Successful exploitation can lead to full system takeover.
|
| CVE-2023-20887 KEV |
|
[KEV] Command Injection in Vmware aria-operations-for-networks (CVE-2023-20887)
command injection in Vmware aria-operations-for-networks (CVE-2023-20887). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-33782 |
|
Command Injection in dlink (CVE-2023-33782)
command injection in dlink (CVE-2023-33782). Successful exploitation can lead to full system takeover.
|
| CVE-2023-31569 |
|
Command Injection in totolink (CVE-2023-31569)
command injection in totolink (CVE-2023-31569). Successful exploitation can lead to full system takeover.
|
| CVE-2023-33532 |
|
Command Injection in netgear (CVE-2023-33532)
command injection in netgear (CVE-2023-33532). Successful exploitation can lead to full system takeover.
|
| CVE-2023-33530 |
|
Command Injection in tenda (CVE-2023-33530)
command injection in tenda (CVE-2023-33530). Successful exploitation can lead to full system takeover.
|
| CVE-2023-31740 |
|
Command Injection in linksys (CVE-2023-31740)
command injection in linksys (CVE-2023-31740). Successful exploitation can lead to full system takeover.
|
| CVE-2023-31741 |
|
Command Injection in linksys (CVE-2023-31741)
command injection in linksys (CVE-2023-31741). Successful exploitation can lead to full system takeover.
|
| CVE-2023-31742 |
|
Command Injection in linksys (CVE-2023-31742)
command injection in linksys (CVE-2023-31742). Successful exploitation can lead to full system takeover.
|
| CVE-2023-31729 |
|
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
|
| CVE-2023-1389 KEV |
|
[KEV] Command Injection in Tp-link archer-ax21 (CVE-2023-1389)
command injection in Tp-link archer-ax21 (CVE-2023-1389). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-2376 |
|
Vulnerability in ui (CVE-2023-2376)
vulnerability in ui (CVE-2023-2376). Successful exploitation can lead to full system takeover.
|
| CVE-2023-2378 |
|
Vulnerability in ui (CVE-2023-2378)
vulnerability in ui (CVE-2023-2378). Successful exploitation can lead to full system takeover.
|