Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Cf Xr11 Firmware CRITICAL 9.8
CVE-2023-38865

COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/we…

No fix yet
Fix from $2,300 2023-08-15
Mivoice Office 400 CRITICAL 9.8
CVE-2023-39293

A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor t…

Fix: after 7.0.9281
Fix from $2,300 2023-08-14
Harman Infotainment MEDIUM 6.8
CVE-2023-40293

Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object.

No fix yet
Fix from $1,600 2023-08-14
Unifi Uap Firmware CRITICAL 9.8
CVE-2023-38034

A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a …

Fix: after 6.5.53
Fix from $2,300 2023-08-10
Opnsense CRITICAL 9.8
CVE-2023-39008

A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 2…

Fix: 23.7+
Fix from $2,300 2023-08-09
Opnsense CRITICAL 9.8
CVE-2023-39001

A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow…

Fix: 23.7+
Fix from $2,300 2023-08-09
Prtg Network Monitor HIGH 7.2
CVE-2023-32781EPSS 14%

A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write p…

Fix: 23.3.86.1520+
Fix from $1,950 2023-08-09
Prtg Network Monitor HIGH 7.2
CVE-2023-32782EPSS 56%

A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permis…

Fix: 23.3.86.1520+
Fix from $1,950 2023-08-09
Coloros CRITICAL 9.8
CVE-2023-26310

There is a command injection problem in the old version of the mobile phone backup app.

No fix yet
Fix from $2,300 2023-08-09
.net HIGH 7.8
CVE-2023-35390

.NET and Visual Studio Remote Code Execution Vulnerability

Fix: 6.0.21 / 7.0.10+
Fix from $1,950 2023-08-08
Scancode.io HIGH 8.8
CVE-2023-39523

ScanCode.io is a server to script and automate software composition analysis with ScanPipe pipelines. Prior to version 32.5.1, the software has a pos…

Fix: 32.5.1+
Fix from $1,950 2023-08-07
Wg302v2 Firmware HIGH 8.8
CVE-2023-38921

Netgear WG302v2 v5.2.9 and WAG302v2 v5.1.19 were discovered to contain multiple command injection vulnerabilities in the upgrade_handler function via…

Mitigation only
Fix from $1,950 2023-08-07
R7100lg Firmware CRITICAL 9.8
CVE-2023-38928

Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi.

Mitigation only
Fix from $2,300 2023-08-07
Matrix Irc Bridge CRITICAL 9.8
CVE-2023-38690

matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be …

Fix: 1.0.1+
Fix from $2,300 2023-08-04
Django Sspanel CRITICAL 9.8
CVE-2023-38941

django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCre…

Mitigation only
Fix from $2,300 2023-08-04
Dango Translator CRITICAL 9.8
CVE-2023-38942

Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json.

Patch available
Fix from $2,300 2023-08-03
Smart S85f CRITICAL 9.8
CVE-2023-4120EPSS 65%

A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical. This issue affects some unknown process…

Fix: after 20230722
Fix from $2,300 2023-08-03
Mirth Connect CRITICAL 9.8
CVE-2023-37679EPSS 99%

A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.

Mitigation only
Fix from $2,300 2023-08-03
Xiaomi Router Firmware CRITICAL 9.8
CVE-2023-26317

Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external…

Fix: 2023.2+
Fix from $2,300 2023-08-02
Chrome MEDIUM 6.3
CVE-2023-3739

Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbit…

Fix: 115.0.5790.131+
Fix from $1,600 2023-08-01
Fabric Operating System MEDIUM 5.5
CVE-2023-31429

Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, …

Fix: 9.1.1c+
Fix from $1,600 2023-08-01
Arubaos Cx HIGH 8.8
CVE-2023-3718

An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results i…

Fix: after 10.11.1010
Fix from $1,950 2023-08-01
Raspap CRITICAL 9.8
CVE-2022-39986EPSS 99%

A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter …

Fix: after 2.8.7
Fix from $2,300 2023-08-01
Raspap HIGH 8.8
CVE-2022-39987EPSS 39%

A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entit…

Fix: after 2.9.2
Fix from $1,950 2023-08-01
Chamilo CRITICAL 9.8
CVE-2023-34960EPSS 99%

A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via …

Fix: after 1.11.18
Fix from $2,300 2023-08-01
Ero1xs Pro Firmware CRITICAL 9.8
CVE-2023-37214

Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.

No fix yet
Fix from $2,300 2023-07-30
Bigfix Mobile HIGH 8.8
CVE-2023-28012

HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.

Mitigation only
Fix from $1,950 2023-07-27
Gaia Portal HIGH 7.2
CVE-2023-28130EPSS 21%

Local user may lead to privilege escalation using Gaia Portal hostnames page.

No fix yet
Fix from $1,950 2023-07-26
Fbm 291w Firmware CRITICAL 9.8
CVE-2023-37794

WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp.

No fix yet
Fix from $2,300 2023-07-14
Netkit CRITICAL 9.8
CVE-2023-38336

netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-20…

No fix yet
Fix from $2,300 2023-07-14