Filtered by CWE-77
Total 2862 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-34206 1 Totolink 2 Cp450, Cp450 Firmware 2025-04-09 6.5 Medium
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter.
CVE-2024-35340 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-09 8.6 High
Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip/goform/formexeCommand.
CVE-2022-45094 1 Siemens 1 Sinec Ins 2025-04-09 8.4 High
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially inject commands into the dhcpd configuration of the affected product. An attacker might leverage this to trigger remote code execution on the affected component.
CVE-2008-3880 1 Zoneminder 1 Zoneminder 2025-04-09 N/A
SQL injection vulnerability in zm_html_view_event.php in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary SQL commands via the filter array parameter.
CVE-2024-22544 1 Linksys 2 E1700, E1700 Firmware 2025-04-08 8.0 High
An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function.
CVE-2023-22671 1 Nsa 1 Ghidra 2025-04-07 9.8 Critical
Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.
CVE-2025-25791 1 Yzncms 1 Yzncms 2025-04-07 4.4 Medium
An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.
CVE-2023-0315 1 Froxlor 1 Froxlor 2025-04-07 8.8 High
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
CVE-2024-51772 1 Arubanetworks 1 Clearpass Policy Manager 2025-04-07 6.4 Medium
An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
CVE-2024-53672 1 Arubanetworks 1 Clearpass Policy Manager 2025-04-07 4.7 Medium
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the underlying operating system.
CVE-2024-51771 1 Arubanetworks 1 Clearpass Policy Manager 2025-04-07 7.2 High
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the underlying operating system.
CVE-2024-10697 1 Tenda 2 Ac6, Ac6 Firmware 2025-04-05 6.3 Medium
A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac of the component API Endpoint. The manipulation of the argument mac leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-36783 1 Totolink 2 Lr350, Lr350 Firmware 2025-04-04 9.8 Critical
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.
CVE-2024-30572 1 Netgear 2 R6850, R6850 Firmware 2025-04-04 8 High
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.
CVE-2025-25604 1 Totolink 2 X5000r, X5000r Firmware 2025-04-04 6.5 Medium
Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.
CVE-2025-25605 1 Totolink 2 X5000r, X5000r Firmware 2025-04-04 6.5 Medium
Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.
CVE-2025-25768 1 Mrcms 1 Mrcms 2025-04-04 5.4 Medium
MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
CVE-2022-21191 1 Global-modules-path Project 1 Global-modules-path 2025-04-04 7.4 High
Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.
CVE-2024-34218 1 Totolink 2 Cp450, Cp450 Firmware 2025-04-04 3.8 Low
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter.
CVE-2024-53333 1 Totolink 2 Ex200, Ex200 Firmware 2025-04-04 6.3 Medium
TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via the "ussd" parameter.