Vulnerabilities (CVE)

Filtered by CWE-78
Total 6045 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-52021 1 Netgear 2 R8500, R8500 Firmware 2026-06-17 N/A 8.0 HIGH
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at bsw_fix.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
CVE-2024-52020 1 Netgear 2 R8500, R8500 Firmware 2026-06-17 N/A 8.0 HIGH
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at wiz_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
CVE-2024-52019 1 Netgear 2 R8500, R8500 Firmware 2026-06-17 N/A 8.0 HIGH
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at genie_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
CVE-2024-52018 1 Netgear 2 Xr300, Xr300 Firmware 2026-06-17 N/A 8.0 HIGH
Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
CVE-2024-52010 2026-06-17 N/A N/A
Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. A command injection vulnerability in the Web SSH feature allows an authenticated attacker to execute arbitrary commands as root on the host. Zoraxy has a Web SSH terminal feature that allows authenticated users to connect to SSH servers from their browsers. In HandleCreateProxySession the request to create an SSH session is handled. An attacker can exploit the username variable to escape from the bash command and inject arbitrary commands into sshCommand. This is possible, because, unlike hostname and port, the username is not validated or sanitized.
CVE-2024-51661 1 Davidlingren 1 Media Library Assistant 2026-06-17 N/A 9.1 CRITICAL
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This issue affects Media LIbrary Assistant: from n/a through <= 3.19.
CVE-2024-51568 1 Cyberpanel 1 Cyberpanel 2026-06-17 N/A 10.0 CRITICAL
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.
CVE-2024-51503 1 Trendmicro 1 Deep Security Agent 2026-06-17 N/A 8.0 HIGH
A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands to other machines in the same domain. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability locally and must have domain user privileges to affect other machines.
CVE-2024-51465 2 Ibm, Redhat 2 App Connect Enterprise Certified Container, Openshift 2026-06-17 N/A 8.8 HIGH
IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
CVE-2024-51450 1 Ibm 1 Security Verify Directory 2026-06-17 N/A 9.1 CRITICAL
IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
CVE-2024-51378 1 Cyberpanel 1 Cyberpanel 2026-06-17 N/A 10.0 CRITICAL
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected.
CVE-2024-51253 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.0 HIGH
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function.
CVE-2024-51252 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 9.8 CRITICAL
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.
CVE-2024-51251 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.0 HIGH
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.
CVE-2024-51249 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.0 HIGH
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.
CVE-2024-51248 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.8 HIGH
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.
CVE-2024-51247 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.8 HIGH
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.
CVE-2024-51246 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.0 HIGH
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.
CVE-2024-51245 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.8 HIGH
In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.
CVE-2024-51244 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.8 HIGH
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.