All vulnerabilities
35 / 35
Sort
10.0
CVE-2024-3400CVE KEV
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect f…
2024-01-01KEV
EPSS100.0%
pct 100
9.1
CVE-2024-21887CVE KEV
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Iv…
2024-01-01KEV
EPSS100.0%
pct 100
9.8
CVE-2023-1671CVE KEV
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance …
2023-01-01KEV
EPSS100.0%
pct 100
8.8
CVE-2023-1389CVE KEV
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command …
2023-01-01KEV
EPSS100.0%
pct 100
9.8
CVE-2012-1823DEB KEV
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI scrip…
2012-01-01KEV
EPSS100.0%
pct 99
9.8
CVE-2024-3273CVE KEV
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in…
2024-01-01KEV
EPSS100.0%
pct 99
9.8
CVE-2025-10035CVE KEV
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an act…
2025-01-01KEV
EPSS99.6%
pct 99
9.8
CVE-2016-1555CVE KEV
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) b…
2016-01-01KEV
EPSS98.3%
pct 99
6.9
CVE-2024-12987CVE KEV
A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B…
2024-01-01KEV
EPSS98.1%
pct 99
9.8
CVE-2023-20887CVE KEV
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with…
2023-01-01KEV
EPSS98.1%
pct 99
9.8
CVE-2007-3010CVE KEV
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7…
2007-01-01KEV
EPSS97.4%
pct 99
8.8
CVE-2015-2051CVE KEV
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remot…
2015-01-01KEV
EPSS97.1%
pct 99
7.3
CVE-2017-8291DEB KEV
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .…
2017-01-01KEV
EPSS97.0%
pct 99
8.7
CVE-2025-4008CVE KEV
The Meteobridge web interface let meteobridge administrator manage their weather station data c…
2025-01-01KEV
EPSS93.9%
pct 99
9.8
CVE-2024-55956CVE KEV
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unau…
2024-01-01KEV
EPSS93.8%
pct 99
8.8
CVE-2022-33891DEB KEV
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.ac…
2022-01-01KEV
EPSS93.0%
pct 99
9.8
CVE-2024-12356CVE KEV
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Suppo…
2024-01-01KEV
EPSS88.0%
pct 99
9.8
CVE-2005-2773CVE KEV
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary …
2005-01-01KEV
EPSS74.1%
pct 99
7.2
CVE-2024-9380CVE KEV
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0…
2024-01-01KEV
EPSS63.0%
pct 99
9.8
CVE-2016-20017CVE KEV
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the log…
2016-01-01KEV
EPSS60.4%
pct 99
7.2
CVE-2023-20118CVE KEV
A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV…
2023-01-01KEV
EPSS53.8%
pct 98
8.8
CVE-2019-0541MSR KEV
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly valid…
2019-01-01MicrosoftKEV
EPSS53.2%
pct 98
8.8
CVE-2020-25079CVE KEV
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 de…
2020-01-01KEV
EPSS52.7%
pct 98
8.8
CVE-2023-33538CVE KEV
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a comm…
2023-01-01KEV
EPSS42.6%
pct 98
8.8
CVE-2017-6327CVE KEV
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code executio…
2017-01-01KEV
EPSS35.3%
pct 98
7.2
CVE-2025-29635CVE KEV
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized att…
2025-01-01KEV
EPSS35.1%
pct 98
9.8
CVE-2020-2509CVE KEV
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, …
2020-01-01KEV
EPSS34.2%
pct 98
9.8
CVE-2010-5330CVE KEV
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Sho…
2010-01-01KEV
EPSS34.0%
pct 98
7.8
CVE-2016-6367CVE KEV
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, an…
2016-01-01KEV
EPSS22.6%
pct 97
8.8
CVE-2021-22899CVE KEV
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remot…
2021-01-01KEV
EPSS22.3%
pct 97
8.8
CVE-2024-40891CVE KEV
**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the mana…
2024-01-01KEV
EPSS20.5%
pct 97
7.8
CVE-2010-4345DEB KEV
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the ex…
2010-01-01KEV
EPSS17.8%
pct 96
8.1
CVE-2026-22719CVE KEV
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated …
2026-01-01KEV
EPSS17.4%
pct 96
6.8
CVE-2022-40765CVE KEV
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100…
2022-01-01KEV
EPSS10.5%
pct 95
6.1
CVE-2025-59689CVE KEV
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail a…
2025-01-01KEV
EPSS1.9%
pct 77
Select a vulnerability on the left to open the preview.