Skip to main content

CVE-2024-3483

7.8
HIGHCVSS v3.1 Base Score
0.24%
LOW RiskEPSS (47th percentile)

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.

Published: 5/15/2024
Modified: 1/21/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.8HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

0.24%LOW Exploitation Risk
47th percentile

This vulnerability has a 0.24% probability of being exploited in the next 30 days, ranking higher than 47% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-434, CWE-502...)

CVE-2026-7629MEDIUM 6.3

A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Review Tool. Executing a manipulation can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet.

5/2/2026
CVE-2026-6195CRITICAL 9.8

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

4/13/2026
CVE-2026-6131CRITICAL 9.8

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument command results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used.

4/12/2026
CVE-2026-4416HIGH 7.8

The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escalation.

3/30/2026
CVE-2026-5030MEDIUM 6.3

A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument host_time leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

3/29/2026

Similar SeverityHIGH