Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2023-44827 An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitr… Zentao after 18.6 Fix from $1,9502023-10-10 HIGH 8.8 CVE-2023-44959EPSS 21% An issue found in D-Link DSL-3782 v.1.03 and before allows remote authenticated users to execute arbitrary code as root via the Router IP Address fie… Dsl 3782 Firmware after 1.03 Fix from $1,9502023-10-10 HIGH 8.8 CVE-2023-45355 Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command inje… Unify Openscape 4000 Assistant Mitigation only Fix from $1,9502023-10-09 HIGH 8.8 CVE-2023-45356 Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injectio… Unify Openscape 4000 Assistant Mitigation only Fix from $1,9502023-10-09 HIGH 8.8 CVE-2023-45351 Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.1, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.42.1, and 4000 Manager V10 R0… Unify Openscape 4000 Assistant Mitigation only Fix from $1,9502023-10-09 HIGH 8.8 CVE-2023-4401 Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of the ‘more’ command. A local or … Smartfabric Storage Software 1.4.1+ Fix from $1,9502023-10-05 CRITICAL 9.8 CVE-2023-43891 Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability… N3m Firmware No fix yet Fix from $2,3002023-10-02 HIGH 8.1 CVE-2023-26145 This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_ma… Pydash 6.0.0+ Fix from $1,9502023-09-28 HIGH 7.5 CVE-2023-41303 Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock … Emui Mitigation only Fix from $1,9502023-09-25 HIGH 8.8 CVE-2023-41031 Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authenticated attackers to execute com… Rx4 1500 Firmware Mitigation only Fix from $1,9502023-09-22 HIGH 8.8 CVE-2023-41029 Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allo… Rx4 1500 Firmware Mitigation only Fix from $1,9502023-09-22 CRITICAL 9.8 CVE-2023-43128 D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of HTTP_ST parameters. Dir 806 Firmware No fix yet Fix from $2,3002023-09-21 CRITICAL 9.8 CVE-2023-42810 systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem… Systeminformation 5.21.7+ Fix from $2,3002023-09-21 HIGH 8.8 CVE-2023-43137 TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rules after authentication, and … Tl Er5120g Firmware No fix yet Fix from $1,9502023-09-20 HIGH 8.8 CVE-2023-43138 TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and… Tl Er5120g Firmware No fix yet Fix from $1,9502023-09-20 CRITICAL 9.8 CVE-2023-43202 D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_download_handler. This vulnerabili… Dwl 6610ap Firmware No fix yet Fix from $2,3002023-09-20 CRITICAL 9.8 CVE-2023-43204 D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function sub_2EF50. This vulnerability allows at… Dwl 6610ap Firmware No fix yet Fix from $2,3002023-09-20 CRITICAL 9.8 CVE-2023-43206 D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function web_cert_download_handler. This vulnera… Dwl 6610ap Firmware No fix yet Fix from $2,3002023-09-20 CRITICAL 9.8 CVE-2023-43207 D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function config_upload_handler. This vulnerabili… Dwl 6610ap Firmware No fix yet Fix from $2,3002023-09-20 HIGH 8.8 CVE-2023-43477EPSS 16% The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, was not prop… Arcadyan Lh1000 Firmware 0.18.15r+ Fix from $1,9502023-09-20 CRITICAL 9.8 CVE-2023-33831EPSS 23% A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a cra… Fuxa No fix yet Fix from $2,3002023-09-18 HIGH 7.2 CVE-2023-34999 A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perfo… Rts Vlink Virtual Matrix 5.7.6 / 6.5.0+ Fix from $1,9502023-09-18 CRITICAL 9.8 CVE-2023-39638 D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/c… Dir 859 A1 Firmware No fix yet Fix from $2,3002023-09-14 CRITICAL 9.8 CVE-2023-41011 Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute a… Intelligent Home Gateway Firmware No fix yet Fix from $2,3002023-09-14 HIGH 7.8 CVE-2023-36642 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through … Fortitester after 7.2.3 Fix from $1,9502023-09-13 CRITICAL 9.8 CVE-2023-3710EPSS 33% Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 … Pm43 Firmware Mitigation only Fix from $2,3002023-09-12 HIGH 7.0 CVE-2023-36805 Windows MSHTML Platform Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.20162 / 10.0.14393.6252+ Fix from $1,9502023-09-12 HIGH 8.8 CVE-2023-33136 Azure DevOps Server Remote Code Execution Vulnerability Azure Devops Server Patch available Fix from $1,9502023-09-12 CRITICAL 9.8 CVE-2023-39637 D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis. Dir 816 Firmware Mitigation only Fix from $2,3002023-09-12 HIGH 8.8 CVE-2023-38829 An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnos… Wf2409e Firmware No fix yet Fix from $1,9502023-09-11