Vulnerabilities (CVE)

Filtered by CWE-78
Total 4696 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-37902 1 Arubanetworks 12 7005, 7008, 7010 and 9 more 2025-05-02 N/A 7.2 HIGH
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2025-24351 2025-05-02 N/A 8.8 HIGH
A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to execute arbitrary OS commands in the context of user “root” via a crafted HTTP request.
CVE-2025-29041 1 Dlink 2 Dir-823x, Dir-823x Firmware 2025-05-01 N/A 9.8 CRITICAL
An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c
CVE-2025-29040 1 Dlink 2 Dir-823x, Dir-823x Firmware 2025-05-01 N/A 9.8 CRITICAL
An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c
CVE-2023-0830 1 Easynas 1 Easynas 2025-05-01 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
CVE-2022-37900 1 Arubanetworks 12 7005, 7008, 7010 and 9 more 2025-05-01 N/A 7.2 HIGH
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2025-31692 1 Drupal 1 Artificial Intelligence 2025-05-01 N/A 7.5 HIGH
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.
CVE-2024-27516 1 Livehelperchat 1 Live Helper Chat 2025-04-30 N/A 9.8 CRITICAL
Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.
CVE-2024-48954 1 Logpoint 1 Siem 2025-04-30 N/A 6.4 MEDIUM
An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.
CVE-2022-41396 1 Tenda 2 W15e, W15e Firmware 2025-04-30 N/A 7.8 HIGH
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.
CVE-2022-41395 1 Tenda 2 W15e, W15e Firmware 2025-04-30 N/A 7.8 HIGH
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDMZ function.
CVE-2025-3729 1 Senior-walter 1 Web-based Pharmacy Product Management System 2025-04-29 7.5 HIGH 7.3 HIGH
A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of the file backup.php of the component Database Backup Handler. The manipulation of the argument txtdbname leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-28137 1 Totolink 2 A810r, A810r Firmware 2025-04-29 N/A 9.8 CRITICAL
The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
CVE-2025-28034 1 Totolink 12 A3000ru, A3000ru Firmware, A3100r and 9 more 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost function through the hostTime parameter.
CVE-2022-41131 1 Apache 2 Airflow, Apache-airflow-providers-apache-hive 2025-04-29 N/A 7.8 HIGH
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG files. This issue affects Hive Provider versions prior to 4.1.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case HIve Provider is installed (Hive Provider 4.1.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install the HIve Provider version 4.1.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version that has lower version of the Hive Provider installed).
CVE-2025-28035 1 Totolink 12 A3000ru, A3000ru Firmware, A3100r and 9 more 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
CVE-2025-28036 1 Totolink 12 A3000ru, A3000ru Firmware, A3100r and 9 more 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
CVE-2025-28037 1 Totolink 4 A810r, A810r Firmware, A950rg and 1 more 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution vulnerability in the setDiagnosisCfg function through the ipDomain parameter.
CVE-2025-28038 1 Totolink 2 Ex1200t, Ex1200t Firmware 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.
CVE-2025-28039 1 Totolink 2 Ex1200t, Ex1200t Firmware 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.