Vulnerabilities (CVE)

Filtered by CWE-78
Total 4525 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-20016 1 Mvpower 4 Tv-7104he, Tv-7104he Firmware, Tv7108he and 1 more 2025-05-09 N/A 9.8 CRITICAL
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenticated attacker can execute arbitrary operating system commands as root. This vulnerability has also been referred to as the "JAWS webserver RCE" because of the easily identifying HTTP response server field. Other firmware versions, at least from 2014 through 2019, can be affected. This was exploited in the wild in 2017 through 2022.
CVE-2024-6047 1 Geovision 37 Gv-dsp Lpr, Gv-dsp Lpr Firmware, Gv-vs14 Vs14 and 34 more 2025-05-09 N/A 9.8 CRITICAL
Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.
CVE-2024-11120 1 Geovision 8 Gv-dsp Lpr, Gv-dsp Lpr Firmware, Gv-vs11 and 5 more 2025-05-09 N/A 9.8 CRITICAL
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.
CVE-2022-43184 1 Dlink 2 Dir-878, Dir-878 Firmware 2025-05-08 N/A 9.8 CRITICAL
D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.
CVE-2025-20213 2025-05-08 N/A 5.5 MEDIUM
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. To exploit this vulnerability, the attacker must have valid read-only credentials with CLI access on the affected system. This vulnerability is due to improper access controls on files that are on the local file system. An attacker could exploit this vulnerability by running a series of crafted commands on the local file system of an affected device. A successful exploit could allow the attacker to overwrite arbitrary files on the affected device and gain privileges of the root user. To exploit this vulnerability, an attacker would need to have CLI access as a low-privilege user.
CVE-2020-17384 1 Cellopoint 1 Cellos 2025-05-08 9.0 HIGH 7.2 HIGH
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With the cookie of the system administrator, attackers can inject and remotely execute arbitrary command to manipulate the system.
CVE-2022-35132 1 Webmin 1 Usermin 2025-05-07 N/A 8.8 HIGH
Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module.
CVE-2022-31898 1 Gl-inet 4 Gl-ax1800, Gl-ax1800 Firmware, Gl-mt300n-v2 and 1 more 2025-05-07 N/A 6.8 MEDIUM
gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr and trace_addr function parameters.
CVE-2024-30247 1 Nextcloud 1 Nextcloudpi 2025-05-07 N/A 10.0 CRITICAL
NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command injection vulnerability in NextCloudPi allows command execution as the root user via the NextCloudPi web-panel. Due to a security misconfiguration this can be used by anyone with access to NextCloudPi web-panel, no authentication is required. It is recommended that the NextCloudPi is upgraded to 1.53.1.
CVE-2025-45042 1 Tenda 2 Ac9, Ac9 Firmware 2025-05-07 N/A 9.8 CRITICAL
Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.
CVE-2024-48629 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the IPAddress parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48630 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48632 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAddress, TCPPorts, and UDPPorts parameters in the SetPortForwardingSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48631 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48633 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48634 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48635 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48637 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:1/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48636 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:0/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48638 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SubnetMask parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.