Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Zentao HIGH 8.8
CVE-2023-44827

An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitr…

Fix: after 18.6
Fix from $1,950 2023-10-10
Dsl 3782 Firmware HIGH 8.8
CVE-2023-44959EPSS 21%

An issue found in D-Link DSL-3782 v.1.03 and before allows remote authenticated users to execute arbitrary code as root via the Router IP Address fie…

Fix: after 1.03
Fix from $1,950 2023-10-10
Unify Openscape 4000 Assistant HIGH 8.8
CVE-2023-45355

Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command inje…

Mitigation only
Fix from $1,950 2023-10-09
Unify Openscape 4000 Assistant HIGH 8.8
CVE-2023-45356

Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injectio…

Mitigation only
Fix from $1,950 2023-10-09
Unify Openscape 4000 Assistant HIGH 8.8
CVE-2023-45351

Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.1, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.42.1, and 4000 Manager V10 R0…

Mitigation only
Fix from $1,950 2023-10-09
Smartfabric Storage Software HIGH 8.8
CVE-2023-4401

Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of the ‘more’ command. A local or …

Fix: 1.4.1+
Fix from $1,950 2023-10-05
N3m Firmware CRITICAL 9.8
CVE-2023-43891

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability…

No fix yet
Fix from $2,300 2023-10-02
Pydash HIGH 8.1
CVE-2023-26145

This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_ma…

Fix: 6.0.0+
Fix from $1,950 2023-09-28
Emui HIGH 7.5
CVE-2023-41303

Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock …

Mitigation only
Fix from $1,950 2023-09-25
Rx4 1500 Firmware HIGH 8.8
CVE-2023-41031

Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authenticated attackers to execute com…

Mitigation only
Fix from $1,950 2023-09-22
Rx4 1500 Firmware HIGH 8.8
CVE-2023-41029

Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allo…

Mitigation only
Fix from $1,950 2023-09-22
Dir 806 Firmware CRITICAL 9.8
CVE-2023-43128

D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of HTTP_ST parameters.

No fix yet
Fix from $2,300 2023-09-21
Systeminformation CRITICAL 9.8
CVE-2023-42810

systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem…

Fix: 5.21.7+
Fix from $2,300 2023-09-21
Tl Er5120g Firmware HIGH 8.8
CVE-2023-43137

TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rules after authentication, and …

No fix yet
Fix from $1,950 2023-09-20
Tl Er5120g Firmware HIGH 8.8
CVE-2023-43138

TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and…

No fix yet
Fix from $1,950 2023-09-20
Dwl 6610ap Firmware CRITICAL 9.8
CVE-2023-43202

D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_download_handler. This vulnerabili…

No fix yet
Fix from $2,300 2023-09-20
Dwl 6610ap Firmware CRITICAL 9.8
CVE-2023-43204

D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function sub_2EF50. This vulnerability allows at…

No fix yet
Fix from $2,300 2023-09-20
Dwl 6610ap Firmware CRITICAL 9.8
CVE-2023-43206

D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function web_cert_download_handler. This vulnera…

No fix yet
Fix from $2,300 2023-09-20
Dwl 6610ap Firmware CRITICAL 9.8
CVE-2023-43207

D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function config_upload_handler. This vulnerabili…

No fix yet
Fix from $2,300 2023-09-20
Arcadyan Lh1000 Firmware HIGH 8.8
CVE-2023-43477EPSS 16%

The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, was not prop…

Fix: 0.18.15r+
Fix from $1,950 2023-09-20
Fuxa CRITICAL 9.8
CVE-2023-33831EPSS 23%

A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a cra…

No fix yet
Fix from $2,300 2023-09-18
Rts Vlink Virtual Matrix HIGH 7.2
CVE-2023-34999

A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perfo…

Fix: 5.7.6 / 6.5.0+
Fix from $1,950 2023-09-18
Dir 859 A1 Firmware CRITICAL 9.8
CVE-2023-39638

D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/c…

No fix yet
Fix from $2,300 2023-09-14
Intelligent Home Gateway Firmware CRITICAL 9.8
CVE-2023-41011

Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute a…

No fix yet
Fix from $2,300 2023-09-14
Fortitester HIGH 7.8
CVE-2023-36642

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through …

Fix: after 7.2.3
Fix from $1,950 2023-09-13
Pm43 Firmware CRITICAL 9.8
CVE-2023-3710EPSS 33%

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 …

Mitigation only
Fix from $2,300 2023-09-12
Windows 10 1507 HIGH 7.0
CVE-2023-36805

Windows MSHTML Platform Security Feature Bypass Vulnerability

Fix: 10.0.10240.20162 / 10.0.14393.6252+
Fix from $1,950 2023-09-12
Azure Devops Server HIGH 8.8
CVE-2023-33136

Azure DevOps Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-09-12
Dir 816 Firmware CRITICAL 9.8
CVE-2023-39637

D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.

Mitigation only
Fix from $2,300 2023-09-12
Wf2409e Firmware HIGH 8.8
CVE-2023-38829

An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnos…

No fix yet
Fix from $1,950 2023-09-11