Vulnerabilities (CVE)

Filtered by CWE-77
Total 3844 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57685 1 Sparkshop 1 Sparkshop 2026-06-17 N/A 5.3 MEDIUM
An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.
CVE-2024-57608 2026-06-17 N/A 6.5 MEDIUM
An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.
CVE-2024-57590 1 Trendnet 2 Tew-632brp, Tew-632brp Firmware 2026-06-17 N/A 9.8 CRITICAL
TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request.
CVE-2024-57583 1 Tenda 2 Ac18, Ac18 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.
CVE-2024-57539 1 Linksys 2 E8450, E8450 Firmware 2026-06-17 N/A 8.2 HIGH
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail.
CVE-2024-57536 1 Linksys 2 E8450, E8450 Firmware 2026-06-17 N/A 8.0 HIGH
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status.
CVE-2024-57338 2026-06-17 N/A 6.5 MEDIUM
An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.
CVE-2024-57337 2026-06-17 N/A 6.5 MEDIUM
An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.
CVE-2024-57235 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.
CVE-2024-57234 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.
CVE-2024-57233 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.
CVE-2024-57232 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.
CVE-2024-57231 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.
CVE-2024-57230 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.
CVE-2024-57229 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.
CVE-2024-57228 1 Linksys 2 E7350, E7350 Firmware 2026-06-17 N/A 8.0 HIGH
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.
CVE-2024-57227 1 Linksys 2 E7350, E7350 Firmware 2026-06-17 N/A 8.0 HIGH
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.
CVE-2024-57226 1 Linksys 2 E7350, E7350 Firmware 2026-06-17 N/A 8.0 HIGH
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.
CVE-2024-57225 1 Linksys 2 E7350, E7350 Firmware 2026-06-17 N/A 9.8 CRITICAL
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.
CVE-2024-57224 1 Linksys 2 E7350, E7350 Firmware 2026-06-17 N/A 9.8 CRITICAL
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.