Vulnerabilities (CVE)

Filtered by CWE-77
Total 3845 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-45348 1 Mi 2 Ax9000, Ax9000 Firmware 2026-06-17 N/A 6.4 MEDIUM
Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can exploit this vulnerability to execute arbitrary code.
CVE-2024-45257 2026-06-17 N/A 7.3 HIGH
A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py.
CVE-2024-45066 1 Doverfuelingsolutions 4 Progauge Maglink Lx4 Console, Progauge Maglink Lx4 Console Firmware, Progauge Maglink Lx Console and 1 more 2026-06-17 N/A 10.0 CRITICAL
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.
CVE-2024-44845 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.8 HIGH
DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string function.
CVE-2024-44844 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.8 HIGH
DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command function.
CVE-2024-44610 2026-06-17 N/A 5.6 MEDIUM
PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via shell metacharacters in a Software Update to processing.php.
CVE-2024-44466 1 Comfast 2 Cf-xr11, Cf-xr11 Firmware 2026-06-17 N/A 9.8 CRITICAL
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.
CVE-2024-44413 2026-06-17 N/A 8.8 HIGH
A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.
CVE-2024-44410 1 Dlink 2 Di-8300, Di-8300 Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
CVE-2024-44402 1 Dlink 2 Di-8100g, Di-8100g Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
CVE-2024-44401 1 Dlink 2 Di-8100g, Di-8100g Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file
CVE-2024-44400 1 Dlink 2 Di-8400, Di-8400 Firmware 2026-06-17 N/A 9.8 CRITICAL
A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.
CVE-2024-44383 1 Wayos 2 Fbm-291w, Fbm-291w Firmware 2026-06-17 N/A 6.8 MEDIUM
WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.
CVE-2024-44382 1 Dlink 2 Di 8004w, Di 8004w Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.
CVE-2024-44381 1 Dlink 2 Di 8004w, Di 8004w Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.
CVE-2024-44335 2026-06-17 N/A 8.8 HIGH
D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.
CVE-2024-44334 2026-06-17 N/A 8.8 HIGH
D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of upgrade_filter.asp.
CVE-2024-43693 1 Doverfuelingsolutions 4 Progauge Maglink Lx4 Console, Progauge Maglink Lx4 Console Firmware, Progauge Maglink Lx Console and 1 more 2026-06-17 N/A 10.0 CRITICAL
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.
CVE-2024-43613 1 Microsoft 1 Azure Database For Postgresql Flexible Server 2026-06-17 N/A 7.2 HIGH
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
CVE-2024-43601 2 Linux, Microsoft 2 Linux Kernel, Visual Studio Code 2026-06-17 N/A 7.8 HIGH
Visual Studio Code for Linux Remote Code Execution Vulnerability