Vulnerabilities (CVE)

Filtered by CWE-78
Total 6045 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-47918 2026-06-17 N/A 6.1 MEDIUM
Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2024-47908 1 Ivanti 1 Cloud Services Appliance 2026-06-17 N/A 9.1 CRITICAL
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-47901 1 Siemens 3 Intermesh 7177 Hybrid 2.0 Subscriber, Intermesh 7707 Fire Subscriber, Intermesh 7707 Fire Subscriber Firmware 2026-06-17 N/A 10.0 CRITICAL
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not sanitize the input parameters in specific GET requests that allow for code execution on operating system level. In combination with other vulnerabilities (CVE-2024-47902, CVE-2024-47903, CVE-2024-47904) this could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
CVE-2024-47821 1 Pyload 1 Pyload 2026-06-17 N/A 9.1 CRITICAL
pyLoad is a free and open-source Download Manager. The folder `/.pyload/scripts` has scripts which are run when certain actions are completed, for e.g. a download is finished. By downloading a executable file to a folder in /scripts and performing the respective action, remote code execution can be achieved in versions prior to 0.5.0b3.dev87. A file can be downloaded to such a folder by changing the download folder to a folder in `/scripts` path and using the `/flashgot` API to download the file. This vulnerability allows an attacker with access to change the settings on a pyload server to execute arbitrary code and completely compromise the system. Version 0.5.0b3.dev87 fixes this issue.
CVE-2024-47608 1 Definetlynotai 1 Logicytics 2026-06-17 N/A 9.8 CRITICAL
Logicytics is designed to harvest and collect data for forensic analysis. Logicytics has a basic vuln affecting compromised devices from shell injections. This vulnerability is fixed in 2.3.2.
CVE-2024-47407 2026-06-17 N/A 10.0 CRITICAL
A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.
CVE-2024-47133 2026-06-17 N/A 7.2 HIGH
UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administrative account to execute arbitrary OS commands.
CVE-2024-47115 1 Ibm 2 Aix, Vios 2026-06-17 N/A 7.8 HIGH
IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.
CVE-2024-46890 1 Siemens 1 Sinec Ins 2026-06-17 N/A 9.1 CRITICAL
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent to specific endpoints of its web API. This could allow an authenticated remote attacker with high privileges on the application to execute arbitrary code on the underlying OS.
CVE-2024-46658 2026-06-17 N/A 8.0 HIGH
Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.
CVE-2024-46628 1 Tendacn 2 G3, G3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.
CVE-2024-46486 1 Tp-link 2 Tl-wdr5620, Tl-wdr5620 Firmware 2026-06-17 N/A 8.0 HIGH
TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.
CVE-2024-46330 1 Vonets 2 Vap11g-300, Vap11g-300 Firmware 2026-06-17 N/A 7.4 HIGH
VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun object.
CVE-2024-46329 1 Vonets 2 Vap11g-300, Vap11g-300 Firmware 2026-06-17 N/A 8.0 HIGH
VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object.
CVE-2024-46316 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.0 HIGH
DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This vulnerability allows attackers to execute arbitrary commands via supplying a crafted HTTP message.
CVE-2024-45893 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.0 HIGH
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMOption.`
CVE-2024-45891 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.0 HIGH
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.`
CVE-2024-45890 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.0 HIGH
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.`
CVE-2024-45889 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.0 HIGH
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.`
CVE-2024-45888 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.0 HIGH
DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `set_ap_map_config.'