Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Xpc Helpertool HIGH 7.8
CVE-2023-33298

com.perimeter81.osx.HelperTool in Perimeter81 10.0.0.19 on macOS allows Local Privilege Escalation (to root) via shell metacharacters in usingCAPath.

No fix yet
Fix from $1,950 2023-06-30
My Cloud Os MEDIUM 6.7
CVE-2023-22815

Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in t…

Fix: 5.26.300+
Fix from $1,600 2023-06-30
My Cloud Os HIGH 8.8
CVE-2023-22816

A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to b…

Fix: 5.26.300+
Fix from $1,950 2023-06-30
Ikuaios CRITICAL 9.8
CVE-2023-34849

An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai router OS through 3.7.1.

Fix: after 3.7.1
Fix from $2,300 2023-06-29
Git Commit Info CRITICAL 9.8
CVE-2023-26134

Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails…

Fix: 2.0.2+
Fix from $2,300 2023-06-28
Jcvi HIGH 8.8
CVE-2023-35932

jcvi is a Python library to facilitate genome assembly, annotation, and comparative genomics. A configuration injection happens when user input is co…

Fix: after 1.3.5
Fix from $1,950 2023-06-23
Magnusbilling CRITICAL 9.8
CVE-2023-30258EPSS 94%

Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTT…

Fix: after 7.3.0
Fix from $2,300 2023-06-23
Raspap HIGH 8.8
CVE-2023-30260

Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request …

Fix: after 2.8.8
Fix from $1,950 2023-06-23
Open Xchange Appsuite Backend MEDIUM 5.3
CVE-2023-26429

Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and …

Fix: 7.10.6 / 8.11.0+
Fix from $1,600 2023-06-20
Collaboration HIGH 7.8
CVE-2023-24032

In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commands as r…

Patch available
Fix from $1,950 2023-06-15
Vw2100 Firmware CRITICAL 9.8
CVE-2023-31746

There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vuln…

Mitigation only
Fix from $2,300 2023-06-14
Tl Wpa8630p Firmware CRITICAL 9.8
CVE-2023-27836

TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function …

No fix yet
Fix from $2,300 2023-06-13
Tl Wpa8630p Firmware CRITICAL 9.8
CVE-2023-27837

TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the key parameter in the function sub_ 4…

No fix yet
Fix from $2,300 2023-06-13
Cpci85 Firmware HIGH 7.2
CVE-2023-33919EPSS 48%

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The web …

Patch available
Fix from $1,950 2023-06-13
Hp Device Manager HIGH 7.8
CVE-2023-26294

Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

Mitigation only
Fix from $1,950 2023-06-12
Hp Device Manager CRITICAL 9.8
CVE-2023-26295

Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

Mitigation only
Fix from $2,300 2023-06-12
Hp Device Manager HIGH 8.8
CVE-2023-26296

Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

Mitigation only
Fix from $1,950 2023-06-12
Hp Device Manager HIGH 8.8
CVE-2023-26297

Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

Mitigation only
Fix from $1,950 2023-06-12
Hp Device Manager HIGH 8.8
CVE-2023-26298

Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

Mitigation only
Fix from $1,950 2023-06-12
Dir 600 Firmware CRITICAL 9.8
CVE-2023-33625EPSS 33%

D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxm…

No fix yet
Fix from $2,300 2023-06-12
Simple Realtime Server HIGH 7.5
CVE-2023-34105EPSS 9%

SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5.0.157, 5.0-b1, and 6.0.48, S…

Fix: 5.0.157 / 6.0.48+
Fix from $1,950 2023-06-12
Vec40g Firmware HIGH 7.5
CVE-2023-3206EPSS 19%

A vulnerability classified as problematic was found in Chengdu VEC40G 3.0. Affected by this vulnerability is an unknown functionality of the file /se…

No fix yet
Fix from $1,950 2023-06-12
Spectralnet Narrowband Firmware HIGH 7.2
CVE-2022-38156

A remote command injection issues exists in the web server of the Kratos SpectralNet device with SpectralNet Narrowband (NB) before 1.7.5. As an admi…

Fix: 1.7.5+
Fix from $1,950 2023-06-12
Unify Openscape 4000 Assistant HIGH 8.8
CVE-2023-35031

Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, a…

Mitigation only
Fix from $1,950 2023-06-12
Unify Openscape 4000 Assistant HIGH 8.8
CVE-2023-35032

Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow command inj…

Mitigation only
Fix from $1,950 2023-06-12
Unify Openscape 4000 Assistant HIGH 8.8
CVE-2023-35033

Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, a…

Mitigation only
Fix from $1,950 2023-06-12
Unify Openscape 4000 Assistant HIGH 8.8
CVE-2023-35035

Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, a…

Mitigation only
Fix from $1,950 2023-06-12
Ak Em100 Firmware HIGH 8.8
CVE-2023-25911

The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters.

Fix: 2.2.0.12+
Fix from $1,950 2023-06-11
Snowflake Connector HIGH 8.8
CVE-2023-34230

snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 via SSO URL authentication. In …

Fix: 2.0.18+
Fix from $1,950 2023-06-08
Snowflake Connector HIGH 8.8
CVE-2023-34232

snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in …

Fix: 1.6.21+
Fix from $1,950 2023-06-08