Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Fedora HIGH 7.2
CVE-2023-39362EPSS 82%

Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged…

Fix: 1.2.25+
Fix from $1,950 2023-09-05
Privileged Remote Access CRITICAL 9.8
CVE-2023-4310

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be …

Mitigation only
Fix from $2,300 2023-09-05
Splunk HIGH 8.8
CVE-2023-40598

In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The at…

Fix: 8.2.12 / 9.0.6+
Fix from $1,950 2023-08-30
Sense Firmware CRITICAL 9.8
CVE-2023-38027

SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit …

Fix: 2.2046+
Fix from $2,300 2023-08-28
K2 Firmware HIGH 7.8
CVE-2023-40796

Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.

Mitigation only
Fix from $1,950 2023-08-25
Mf286r Firmware HIGH 8.8
CVE-2023-25649

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter,…

Mitigation only
Fix from $1,950 2023-08-25
Casaos HIGH 8.8
CVE-2023-37469

CasaOS is an open-source personal cloud system. Prior to version 0.4.4, if an authenticated user using CasaOS is able to successfully connect to a co…

Fix: 0.4.4+
Fix from $1,950 2023-08-24
Pbootcms CRITICAL 9.8
CVE-2023-39834

PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.

Fix: 3.2.0+
Fix from $2,300 2023-08-24
Xl824 Firmware MEDIUM 6.8
CVE-2023-4212

​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as …

Fix: after 5.9.8
Fix from $1,600 2023-08-22
Isigeo Web HIGH 8.8
CVE-2023-23564

An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to execute commands.

No fix yet
Fix from $1,950 2023-08-22
Memcached HIGH 7.5
CVE-2020-22570

Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.

Fix: 1.6.3+
Fix from $1,950 2023-08-22
X5000r Firmware CRITICAL 9.8
CVE-2023-39617

TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via…

No fix yet
Fix from $2,300 2023-08-21
X5000r Firmware CRITICAL 9.8
CVE-2023-39618

TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface.

No fix yet
Fix from $2,300 2023-08-21
Intelligent Broadband Subscriber Gateway CRITICAL 9.8
CVE-2023-39809

N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname…

Mitigation only
Fix from $2,300 2023-08-21
Smart S85f CRITICAL 9.8
CVE-2023-4414EPSS 9%

A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230807. It has been declared as critical. Affected by this vulnerability i…

Fix: after 2023-08-07
Fix from $2,300 2023-08-18
Rg Ew1200 Firmware HIGH 8.8
CVE-2023-38902

A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B…

No fix yet
Fix from $1,950 2023-08-17
Data Master HIGH 8.8
CVE-2023-2910

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Ma…

Fix: 4.2.3.rk91+
Fix from $1,950 2023-08-17
Tn 5900 Firmware CRITICAL 9.8
CVE-2023-34215

TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient inp…

Fix: after 3.3
Fix from $2,300 2023-08-17
Tn 5900 Firmware CRITICAL 9.8
CVE-2023-33238

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnera…

Fix: after 3.3
Fix from $2,300 2023-08-17
Tn 5900 Firmware CRITICAL 9.8
CVE-2023-33239

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnera…

Fix: after 3.3
Fix from $2,300 2023-08-17
Tn 5900 Firmware CRITICAL 9.8
CVE-2023-34213

TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability stems from insufficient input v…

Fix: after 3.3
Fix from $2,300 2023-08-17
Tn 5900 Firmware CRITICAL 9.8
CVE-2023-34214

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnera…

Fix: after 3.3
Fix from $2,300 2023-08-17
Intersight Private Virtual Appliance CRITICAL 9.1
CVE-2023-20017

Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands us…

Mitigation only
Fix from $2,300 2023-08-16
Intersight Private Virtual Appliance CRITICAL 9.1
CVE-2023-20013

Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands us…

Mitigation only
Fix from $2,300 2023-08-16
Telepresence Video Communication Server HIGH 7.2
CVE-2023-20209EPSS 41%

A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow …

Fix: 14.3.1+
Fix from $1,950 2023-08-16
Cf Xr11 Firmware CRITICAL 9.8
CVE-2023-38866

COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/we…

No fix yet
Fix from $2,300 2023-08-15
Cf Xr11 Firmware CRITICAL 9.8
CVE-2023-38864

An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function a…

No fix yet
Fix from $2,300 2023-08-15
Wl Wn575a3 Firmware CRITICAL 9.8
CVE-2023-38861

An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the set_sys_adm fun…

No fix yet
Fix from $2,300 2023-08-15
Cf Xr11 Firmware CRITICAL 9.8
CVE-2023-38862

An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bin/webmgnt.

No fix yet
Fix from $2,300 2023-08-15
Cf Xr11 Firmware CRITICAL 9.8
CVE-2023-38863

An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 function at bin/…

No fix yet
Fix from $2,300 2023-08-15