Vulnerabilities (CVE)

Filtered by CWE-78
Total 5719 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-2096 1 Totolink 2 Ex1800t, Ex1800t Firmware 2025-04-03 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function setRebootScheCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument mode/week/minute/recHour leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2023-23596 1 Jc21 1 Nginx Proxy Manager 2025-04-03 N/A 8.8 HIGH
jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. NOTE: this is not part of any NGINX software shipped by F5.
CVE-2024-25851 1 Netis-systems 2 Wf2780, Wf2780 Firmware 2025-04-03 N/A 8.0 HIGH
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in other_para of cgitest.cgi.
CVE-2022-37718 1 Edgenexus 1 Application Delivery Controller 2025-04-02 N/A 8.8 HIGH
The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands through a specially crafted payload. This vulnerability can also be exploited from an unauthenticated context via unspecified vectors
CVE-2023-24422 1 Jenkins 1 Script Security 2025-04-02 N/A 8.8 HIGH
A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
CVE-2022-45639 1 Sleuthkit 1 The Sleuth Kit 2025-04-02 N/A 7.8 HIGH
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.
CVE-2022-25908 1 Create-choo-electron Project 1 Create-choo-electron 2025-04-01 N/A 7.4 HIGH
All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.
CVE-2022-25860 1 Simple-git Project 1 Simple-git 2025-04-01 N/A 8.1 HIGH
Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221).
CVE-2022-25350 1 Helecloud 1 Puppet-facter 2025-04-01 N/A 7.4 HIGH
All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.
CVE-2022-25962 1 Vagrant.js Project 1 Vagrant.js 2025-04-01 N/A 7.4 HIGH
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
CVE-2022-21810 1 Smartctl Project 1 Smartctl 2025-04-01 N/A 7.4 HIGH
All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization.
CVE-2024-36491 1 Centurysys 31 Futurenet Nxr-1200, Futurenet Nxr-1200 Firmware, Futurenet Nxr-120\/c and 28 more 2025-04-01 N/A 9.8 CRITICAL
FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain and/or alter sensitive information, and cause a denial-of-service (DoS) condition.
CVE-2024-25468 1 Totolink 2 X5000r, X5000r Firmware 2025-03-28 N/A 7.5 HIGH
An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of the NTPSyncWithHost component.
CVE-2024-57687 1 Phpgurukul 1 Land Record System 2025-03-28 N/A 9.8 CRITICAL
An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "Cookie" GET request parameter.
CVE-2025-25039 1 Arubanetworks 1 Clearpass Policy Manager 2025-03-28 N/A 4.7 MEDIUM
A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the underlying operating system.
CVE-2024-54181 2 Ibm, Linux 2 Websphere Automation, Linux Kernel 2025-03-28 N/A 7.2 HIGH
IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.
CVE-2022-48108 1 Dlink 2 Dir 878, Dir 878 Firmware 2025-03-28 N/A 9.8 CRITICAL
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerability allows attackers to escalate privileges to root via a crafted payload.
CVE-2022-48107 1 Dlink 2 Dir 878, Dir 878 Firmware 2025-03-28 N/A 9.8 CRITICAL
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerability allows attackers to escalate privileges to root via a crafted payload.
CVE-2022-48072 1 Phicomm 2 K2, K2 Firmware 2025-03-28 N/A 7.8 HIGH
Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.
CVE-2022-48070 1 Phicomm 2 K2, K2 Firmware 2025-03-28 N/A 7.8 HIGH
Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.