CVE-2023-27231 | CRITICAL | 9.8 | 0.02023 | 39.91 | No | No | 2023-03-28 | 2025-02-18 | euvd | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setW…TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg. |
CVE-2025-42967 | CRITICAL | 9.9 | 0.00878 | 39.91 | No | No | 2025-07-08 | 2026-02-26 | euvd | SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileg…SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to create a new report with his own code potentially gaining full control of the affected SAP system causing high impact on confidentiality, integrity, and availability of the application. |
CVE-2025-69971 | CRITICAL | 9.8 | 0.02036 | 39.91 | No | No | 2026-02-03 | 2026-02-28 | euvd | FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign…FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remote attackers to forge valid admin tokens and bypass authentication to gain full administrative access. |
CVE-2025-25570 | CRITICAL | 9.8 | 0.02021 | 39.91 | No | No | 2025-02-27 | 2025-02-28 | euvd | Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials. |
CVE-2023-6975 | CRITICAL | 9.8 | 0.02013 | 39.9 | No | No | 2023-12-20 | 2024-08-02 | euvd | A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models information.A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models information. |
CVE-2023-29801 | CRITICAL | 9.8 | 0.02014 | 39.9 | No | No | 2023-04-14 | 2025-02-06 | euvd | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServ…TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function. |
CVE-2023-29800 | CRITICAL | 9.8 | 0.02014 | 39.9 | No | No | 2023-04-14 | 2025-02-06 | euvd | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFir…TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function. |
CVE-2024-48445 | CRITICAL | 9.8 | 0.01992 | 39.9 | No | No | 2025-02-04 | 2025-02-06 | euvd | An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters.An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters. |
CVE-2023-29798 | CRITICAL | 9.8 | 0.02014 | 39.9 | No | No | 2023-04-14 | 2025-02-06 | euvd | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracero…TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function. |
CVE-2023-29802 | CRITICAL | 9.8 | 0.02014 | 39.9 | No | No | 2023-04-14 | 2025-02-06 | euvd | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg…TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function. |
CVE-2023-31587 | CRITICAL | 9.8 | 0.01998 | 39.9 | No | No | 2023-05-16 | 2025-01-27 | euvd | Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/Write…Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac. |
CVE-2024-31286 | CRITICAL | 9.9 | 0.00862 | 39.9 | No | No | 2024-04-07 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Pho…Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005. |
CVE-2022-36786 | CRITICAL | 9.9 | 0.00856 | 39.9 | No | No | 2022-11-17 | 2025-04-29 | euvd | DLINK - DSL-224 Post-auth RCE.
DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via j…DLINK - DSL-224 Post-auth RCE.
DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API.
It is possible to inject a command through this interface that will run with ROOT permissions on the router. |
CVE-2020-14687 | CRITICAL | 9.8 | 0.02006 | 39.9 | No | No | 2020-07-15 | 2024-09-26 | euvd | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are …Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CVE-2026-45663 | CRITICAL | 9.9 | 0.00866 | 39.9 | No | No | 2026-05-29 | 2026-05-29 | euvd, nvd | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker…Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath parameter is not properly sanitized and is directly interpolated into a shell command string. By including shell metacharacters such as ; or ", an attacker can escape the intended docker cp command and execute arbitrary OS commands on the Dokploy host. |
CVE-2023-27533 | CRITICAL | 9.8 | 0.01993 | 39.9 | No | No | 2023-03-30 | 2026-02-13 | euvd | A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on mali…A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system. |
CVE-2024-3799 | HIGH | 8.7 | 0.14573 | 39.9 | No | No | 2024-07-10 | 2024-08-28 | euvd | Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source project Phoniebox allows a…Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local network. If such a request reaches the server, it will cause a shell command execution.
This issue affects Phoniebox in all releases through 2.7. Newer 2.x releases were not tested, but they might also be vulnerable.
Phoniebox in version 3.0 and higher are not affected. |
CVE-2017-15681 | CRITICAL | 9.8 | 0.02006 | 39.9 | No | No | 2020-11-27 | 2026-07-09 | euvd, nvd | In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files fro…In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE. |
CVE-2021-41566 | CRITICAL | 9.8 | 0.02007 | 39.9 | No | No | 2021-10-08 | 2024-09-17 | euvd | The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arb…The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in. |
CVE-2021-37909 | CRITICAL | 9.8 | 0.02007 | 39.9 | No | No | 2021-09-15 | 2024-09-17 | euvd | WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite to the registry witho…WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite to the registry without permissions thus perform hijack attacks to execute arbitrary code. |
CVE-2022-26775 | CRITICAL | 9.8 | 0.01998 | 39.9 | No | No | 2022-05-26 | 2025-05-30 | euvd | An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 1…An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4. An attacker may be able to cause unexpected application termination or arbitrary code execution. |
CVE-2021-23140 | CRITICAL | 9.9 | 0.00853 | 39.9 | No | No | 2021-06-11 | 2024-08-03 | euvd | Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command…Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre Operator. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); version 8.10 and prior versions. |
CVE-2025-49220 | CRITICAL | 9.8 | 0.02014 | 39.9 | No | No | 2025-06-17 | 2026-02-26 | euvd | An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code exec…An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method. |
CVE-2019-6957 | CRITICAL | 9.8 | 0.01988 | 39.9 | No | No | 2019-05-29 | 2024-09-16 | euvd | A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5…A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Video Recording Manager (VRM), Video Streaming Gateway (VSG), Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC) and Video SDK (VSDK). The vulnerability potentially allows the unauthorized execution of code in the system via the network interface. |
CVE-2023-27602 | CRITICAL | 9.8 | 0.01996 | 39.9 | No | No | 2023-04-10 | 2025-02-13 | euvd | In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.
W…In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.
We recommend users upgrade the version of Linkis to version 1.3.2.
For versions
<=1.3.1, we suggest turning on the file path check switch in linkis.properties
`wds.linkis.workspace.filesystem.owner.check=true`
`wds.linkis.workspace.filesystem.path.check=true` |
CVE-2024-1644 | CRITICAL | 9.9 | 0.00856 | 39.9 | No | No | 2024-02-19 | 2024-08-01 | euvd | Suite CRM version 7.14.2 allows including local php files. This is possible
because the application is vulnerable to LFI.Suite CRM version 7.14.2 allows including local php files. This is possible
because the application is vulnerable to LFI. |
CVE-2022-40200 | CRITICAL | 9.9 | 0.00868 | 39.9 | No | No | 2022-11-17 | 2026-04-28 | euvd | Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. |
CVE-2024-9933 | CRITICAL | 9.8 | 0.0199 | 39.9 | No | No | 2024-10-26 | 2026-04-08 | euvd | The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.10.1. This is due to the 'w…The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.10.1. This is due to the 'watchtower_ota_token' default value is empty, and the not empty check is missing in the 'Password_Less_Access::login' function. This makes it possible for unauthenticated attackers to log in to the WatchTowerHQ client administrator user. |
CVE-2026-26478 | CRITICAL | 9.8 | 0.02003 | 39.9 | No | No | 2026-03-04 | 2026-03-04 | euvd | A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a speci…A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary shell code as the root account. |
CVE-2021-27649 | CRITICAL | 9.8 | 0.02007 | 39.9 | No | No | 2021-06-23 | 2024-09-16 | euvd | Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote at…Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors. |
CVE-2025-45491 | CRITICAL | 9.8 | 0.01992 | 39.9 | No | No | 2025-05-06 | 2025-05-07 | euvd | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the userna…Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter. |
CVE-2025-66489 | CRITICAL | 9.9 | 0.00852 | 39.9 | No | No | 2025-12-03 | 2025-12-03 | euvd | Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password v…Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic in the authentication flow. This vulnerability is fixed in 5.9.8. |
CVE-2018-12470 | CRITICAL | 9.8 | 0.01988 | 39.9 | No | No | 2018-10-04 | 2024-09-16 | euvd | A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affec…A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37. |
CVE-2021-32538 | CRITICAL | 9.8 | 0.02007 | 39.9 | No | No | 2021-07-07 | 2024-09-17 | euvd | ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary f…ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further execute code unrestrictedly. |
CVE-2021-41301 | CRITICAL | 9.8 | 0.01989 | 39.9 | No | No | 2021-09-30 | 2024-09-16 | euvd | ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET r…ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access. |
CVE-2023-45163 | CRITICAL | 9.9 | 0.00856 | 39.9 | No | No | 2023-11-06 | 2025-06-18 | euvd | The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate…The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions. This instruction only runs on Windows clients.
To remediate this issue download the updated Network product pack from the 1E Exchange and update the 1E-Exchange-CommandLinePing instruction to v18.1 by uploading it through the 1E Platform instruction upload UI |
CVE-2024-38650 | CRITICAL | 9.9 | 0.00851 | 39.9 | No | No | 2024-09-07 | 2024-09-09 | euvd | An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server. |
CVE-2007-4039 | CRITICAL | 9.8 | 0.02014 | 39.9 | No | No | 2007-07-27 | 2025-04-03 | euvd | Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scrip…Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670. |
CVE-2024-24398 | CRITICAL | 9.8 | 0.02007 | 39.9 | No | No | 2024-02-06 | 2026-07-09 | euvd | Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary…Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function. |
CVE-2021-25320 | CRITICAL | 9.9 | 0.00855 | 39.9 | No | Yes | 2021-07-15 | 2024-09-16 | euvd, packetstorm | A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with…A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without further checks This issue affects: Rancher versions prior to 2.5.9; Rancher versions prior to 2.4.16. |
CVE-2022-1571 | CRITICAL | 9.9 | 0.00856 | 39.9 | No | No | 2022-05-04 | 2024-08-03 | euvd | Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. This vulnerability can…Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. This vulnerability can be arbitrarily executed javascript code to steal user'cookie, perform HTTP request, get content of `same origin` page, etc ... |
CVE-2020-5368 | CRITICAL | 9.8 | 0.0199 | 39.9 | No | No | 2020-07-06 | 2024-09-16 | euvd | Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit…Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form. |
CVE-2024-33109 | CRITICAL | 9.9 | 0.00854 | 39.9 | No | No | 2024-09-19 | 2026-07-05 | euvd | Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files…Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function. |
CVE-2025-29269 | CRITICAL | 9.8 | 0.01964 | 39.89 | No | No | 2025-12-04 | 2026-07-05 | euvd | ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoin…ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint. |
CVE-2024-20997 | CRITICAL | 9.9 | 0.00833 | 39.89 | No | No | 2024-04-16 | 2025-03-13 | euvd | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). …Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). |
CVE-2022-31605 | CRITICAL | 9.8 | 0.01976 | 39.89 | No | No | 2022-07-01 | 2024-08-03 | euvd | NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.…NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity. |
CVE-2021-21821 | CRITICAL | 9.8 | 0.01963 | 39.89 | No | No | 2021-07-08 | 2024-08-03 | euvd | A stack-based buffer overflow vulnerability exists in the PDF process_fontname functionality of Accusoft ImageGear 19.9. A specially crafted…A stack-based buffer overflow vulnerability exists in the PDF process_fontname functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. |
CVE-2022-48123 | CRITICAL | 9.8 | 0.01958 | 39.89 | No | No | 2023-01-20 | 2025-04-03 | euvd | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the setti…TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the setting/delStaticDhcpRules function. |
CVE-2022-48122 | CRITICAL | 9.8 | 0.01958 | 39.89 | No | No | 2023-01-20 | 2025-04-03 | euvd | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid parameter in the setting…TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid parameter in the setting/delStaticDhcpRules function. |
CVE-2026-47370 | CRITICAL | 9.9 | 0.00834 | 39.89 | No | No | 2026-06-12 | 2026-06-13 | euvd | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain de…A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances. |