Перейти к содержимому
Noroxi

CWE-77 · 3 230 записей

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CVE этого класса

3 228 записей

  • CVE-2023-1671
    99Срочно

    A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    sophos · web appliance4 апр. 2023 г.

  • CVE-2012-1823
    99Срочно

    sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    php · php11 мая 2012 г.

  • CVE-2024-3273
    99Срочно

    D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    dlink · dns-320l firmware3 апр. 2024 г.

  • CVE-2025-10035
    99Срочно

    Deserialization Vulnerability in GoAnywhere MFT's License Servlet

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    fortra · goanywhere managed file transfer18 сент. 2025 г.

  • CVE-2016-1555
    98Срочно

    (1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %

    netgear · wnap320 firmware21 апр. 2017 г.

  • CVE-2023-20887
    98Срочно

    Aria Operations for Networks contains a command injection vulnerability.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %

    vmware · aria operations for networks7 июн. 2023 г.

  • CVE-2007-3010
    98Срочно

    masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to exe

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    al-enterprise · omnipcx enterprise communication server18 сент. 2007 г.

  • CVE-2024-55956
    97Срочно

    In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbit

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %

    cleo · harmony13 дек. 2024 г.

  • CVE-2024-21887
    96Срочно

    A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an aut

    КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 100 %

    ivanti · connect secure12 янв. 2024 г.

  • CVE-2023-1389
    95Срочно

    TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form o

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %

    tp-link · archer ax21 firmware15 мар. 2023 г.

  • CVE-2024-12356
    95Срочно

    Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %

    beyondtrust · privileged remote access17 дек. 2024 г.

  • CVE-2015-2051
    94Срочно

    The D-Link DIR-645 Wired/Wireless Router Rev.

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 97 %

    dlink · dir-645 firmware23 февр. 2015 г.

  • CVE-2025-4008
    92Срочно

    Arbitrary Command Injection in Smartbedded MeteoBridge

    ВысокаяCVSS 8,7KEVГотовый эксплойтEPSS 94 %

    smartbedded · meteobridge vm21 мая 2025 г.

  • CVE-2026-8037
    92Срочно

    OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 77 %

    progress · connection manager for objectscale4 июн. 2026 г.

  • CVE-2005-2773
    91Срочно

    HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1)

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 75 %

    hp · openview network node manager2 сент. 2005 г.

  • CVE-2016-20017
    88Срочно

    D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wil

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 64 %

    dlink · dsl-2750b firmware19 окт. 2022 г.

  • CVE-2024-12987
    86Срочно

    DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection

    СредняяCVSS 6,9KEVГотовый эксплойтEPSS 98 %

    draytek · vigor300b firmware27 дек. 2024 г.

  • CVE-2025-29635
    84Срочно

    A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 88 %

    dlink · dir-823x firmware25 мар. 2025 г.

  • CVE-2020-25079
    81Срочно

    An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 54 %

    dlink · dcs-4703e firmware2 сент. 2020 г.

  • CVE-2019-0541
    81Срочно

    A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Ex

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 53 %

    microsoft · internet explorer8 янв. 2019 г.

  • CVE-2010-5330
    81Срочно

    On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 39 %

    ui · airos11 июн. 2019 г.

  • CVE-2020-2509
    79На этой неделе

    Command Injection Vulnerability in QTS and QuTS hero

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 34 %

    qnap · qts17 апр. 2021 г.

  • CVE-2023-33538
    77На этой неделе

    TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 42 %

    tp-link · tl-wr940n firmware7 июн. 2023 г.

  • CVE-2024-9380
    76На этой неделе

    An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker wit

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 60 %

    ivanti · endpoint manager cloud services appliance8 окт. 2024 г.

  • CVE-2017-6327
    76На этой неделе

    The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an ind

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 36 %

    symantec · message gateway11 авг. 2017 г.

Все классы уязвимостей