Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
X18 Firmware CRITICAL 9.8
CVE-2023-29802

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.

No fix yet
Fix from $2,300 2023-04-14
X18 Firmware CRITICAL 9.8
CVE-2023-29803

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function.

No fix yet
Fix from $2,300 2023-04-14
X18 Firmware CRITICAL 9.8
CVE-2023-29798

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg fu…

No fix yet
Fix from $2,300 2023-04-14
X18 Firmware CRITICAL 9.8
CVE-2023-29799

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg funct…

No fix yet
Fix from $2,300 2023-04-14
Unify Openscape Bcf HIGH 7.2
CVE-2023-30638

Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated ad…

Fix: 10r3.1.2 / 10r3.1.3+
Fix from $1,950 2023-04-14
Manageengine Admanager Plus HIGH 7.2
CVE-2023-29084EPSS 98%

Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.

Fix: 7.1+
Fix from $1,950 2023-04-13
Rv016 Firmware HIGH 7.2
CVE-2023-20118 KEVEPSS 54%

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could all…

Mitigation only
Fix from $1,950 2023-04-13
Cp 8031 Firmware CRITICAL 9.8
CVE-2023-28489

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected…

No fix yet
Fix from $2,300 2023-04-11
A7100ru Firmware CRITICAL 9.8
CVE-2023-26978

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIe…

No fix yet
Fix from $2,300 2023-04-07
A7100ru Firmware CRITICAL 9.8
CVE-2023-26848

TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRul…

No fix yet
Fix from $2,300 2023-04-07
Unify Openscape 4000 CRITICAL 9.8
CVE-2023-29473

webservice in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to ru…

Mitigation only
Fix from $2,300 2023-04-06
Unify Openscape 4000 CRITICAL 9.8
CVE-2023-29474

inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run…

Mitigation only
Fix from $2,300 2023-04-06
Unify Openscape 4000 CRITICAL 9.8
CVE-2023-29475

inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run…

Mitigation only
Fix from $2,300 2023-04-06
GitLab CRITICAL 9.8
CVE-2023-1708

An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-p…

Fix: 15.8.5 / 15.9.4+
Fix from $2,300 2023-04-05
Identity Services Engine MEDIUM 6.7
CVE-2023-20153

Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform comman…

Mitigation only
Fix from $1,600 2023-04-05
Evolved Programmable Network Manager MEDIUM 6.7
CVE-2023-20121

Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisc…

Fix: 3.10.4 / 7.0.1+
Fix from $1,600 2023-04-05
Identity Services Engine HIGH 7.8
CVE-2023-20122

Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisc…

Mitigation only
Fix from $1,950 2023-04-05
Identity Services Engine MEDIUM 6.7
CVE-2023-20152

Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform comman…

Mitigation only
Fix from $1,600 2023-04-05
Rv016 Firmware HIGH 7.2
CVE-2023-20124

A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an au…

Mitigation only
Fix from $1,950 2023-04-05
Microweber CRITICAL 9.8
CVE-2023-1877

Command Injection in GitHub repository microweber/microweber prior to 1.3.3.

Fix: 1.3.3+
Fix from $2,300 2023-04-05
Wr 1200 Firmware CRITICAL 9.8
CVE-2023-26866

GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respectively are vulnerable to rem…

Mitigation only
Fix from $2,300 2023-04-04
Web Appliance HIGH 7.2
CVE-2022-4934

A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to exec…

Fix: 4.3.10.4+
Fix from $1,950 2023-04-04
Web Appliance CRITICAL 9.8
CVE-2023-1671 KEVEPSS 100%

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitr…

Fix: 4.3.10.4+
Fix from $2,300 2023-04-04
Nophp HIGH 8.8
CVE-2023-28854

nophp is a PHP web framework. Prior to version 0.0.1, nophp is vulnerable to shell command injection on httpd user. A patch was made available at com…

Fix: 0.0.1+
Fix from $1,950 2023-04-03
Convert To Pipeline CRITICAL 9.8
CVE-2023-28677

Jenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build Environment, Build Steps, and…

Fix: after 1.0
Fix from $2,300 2023-04-02
Go Rt Ac750 Firmware CRITICAL 9.8
CVE-2023-26822

D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at soapcgi.main.

No fix yet
Fix from $2,300 2023-04-01
Unstructured Information Management Architecture HIGH 8.8
CVE-2023-28935

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software …

Mitigation only
Fix from $1,950 2023-03-30
Dir 1935 Firmware MEDIUM 6.8
CVE-2022-43623

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although au…

Fix: after 1.02
Fix from $1,600 2023-03-29
Hadsky HIGH 7.2
CVE-2023-1685

A vulnerability was found in HadSky up to 7.11.8. It has been declared as critical. This vulnerability affects unknown code of the file /install/inde…

Fix: after 7.11.8
Fix from $1,950 2023-03-29
Qvr HIGH 7.2
CVE-2023-23355

An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote auth…

Fix: 5.0.1.2346+
Fix from $1,950 2023-03-29