All CVEs — page 5 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This vulnerability allows for command injection through the manipulation of the 'url' argument in the '/api/ZRnetwork/ping' endpoint, leading to potential remote code execution.
This vulnerability allows remote command injection through the manipulation of the hostname/zonename argument in the set_time_zone function of Ziroom ZHOME A0101 1.0.1.0, enabling potential attackers to execute arbitrary commands on the system.
LightLLM through 1.2.0 allows unauthenticated attackers to execute arbitrary code via RPyC cache service with pickle deserialization enabled.
LightLLM versions through 1.2.0 are vulnerable to remote code execution due to an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code via crafted serialized objects.
The vulnerability allows for command injection through the manipulation of the conloglevel/log_size argument in the set_syslog function, enabling remote attackers to execute arbitrary commands.