Vulnerabilities (CVE)

Filtered by CWE-77
Total 1527 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-22903 1 Vinchin 1 Vinchin Backup And Recovery 2024-02-07 N/A 8.8 HIGH
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.
CVE-2024-22900 1 Vinchin 1 Vinchin Backup And Recovery 2024-02-07 N/A 8.8 HIGH
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.
CVE-2023-41281 1 Qnap 3 Qts, Quts Hero, Qutscloud 2024-02-06 N/A 7.2 HIGH
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later QuTScloud c5.1.5.2651 and later
CVE-2023-41282 1 Qnap 3 Qts, Quts Hero, Qutscloud 2024-02-06 N/A 7.2 HIGH
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later QuTScloud c5.1.5.2651 and later
CVE-2023-41283 1 Qnap 3 Qts, Quts Hero, Qutscloud 2024-02-06 N/A 7.2 HIGH
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later QuTScloud c5.1.5.2651 and later
CVE-2023-51887 1 Ctan 1 Mathtex 2024-02-05 N/A 9.8 CRITICAL
Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.
CVE-2024-20287 1 Cisco 2 Wap371, Wap371 Firmware 2024-02-02 N/A 7.2 HIGH
A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point Setup could allow an authenticated, remote attacker to perform command injection attacks against an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the device. To exploit this vulnerability, the attacker must have valid administrative credentials for the device.
CVE-2024-23628 1 Motorola 2 Mr2600, Mr2600 Firmware 2024-02-01 7.7 HIGH 8.8 HIGH
A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.
CVE-2024-23627 1 Motorola 2 Mr2600, Mr2600 Firmware 2024-02-01 7.7 HIGH 8.8 HIGH
A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.
CVE-2024-23626 1 Motorola 2 Mr2600, Mr2600 Firmware 2024-02-01 7.7 HIGH 8.8 HIGH
A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.
CVE-2024-22729 1 Netis-systems 2 Mw5360, Mw5360 Firmware 2024-02-01 N/A 9.8 CRITICAL
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.
CVE-2023-51833 1 Trendnet 2 Tew-411brpplus, Tew-411brpplus Firmware 2024-01-31 N/A 8.1 HIGH
A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the debug.cgi page.
CVE-2024-23625 1 Dlink 2 Dap-1650, Dap-1650 Firmware 2024-01-31 8.3 HIGH 9.8 CRITICAL
A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.
CVE-2024-23624 1 Dlink 2 Dap-1650, Dap-1650 Firmware 2024-01-31 8.3 HIGH 9.8 CRITICAL
A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.
CVE-2023-7227 1 Systemk-corp 6 Nvr 504, Nvr 504 Firmware, Nvr 508 and 3 more 2024-01-31 N/A 9.8 CRITICAL
SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow an attacker to execute arbitrary commands with root privileges.
CVE-2024-22529 1 Totolink 2 X2000r, X2000r Firmware 2024-01-31 N/A 9.8 CRITICAL
TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.
CVE-2023-37679 1 Nextgen 1 Mirth Connect 2024-01-31 N/A 9.8 CRITICAL
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
CVE-2023-52038 1 Totolink 2 X6000r, X6000r Firmware 2024-01-30 N/A 9.8 CRITICAL
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.
CVE-2023-52039 1 Totolink 2 X6000r, X6000r Firmware 2024-01-30 N/A 9.8 CRITICAL
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.
CVE-2023-52040 1 Totolink 2 X6000r, X6000r Firmware 2024-01-30 N/A 9.8 CRITICAL
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.