Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2023-38865 COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/we… Cf Xr11 Firmware No fix yet Fix from $2,3002023-08-15 CRITICAL 9.8 CVE-2023-39293 A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor t… Mivoice Office 400 after 7.0.9281 Fix from $2,3002023-08-14 MEDIUM 6.8 CVE-2023-40293 Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object. Harman Infotainment No fix yet Fix from $1,6002023-08-14 CRITICAL 9.8 CVE-2023-38034 A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a … Unifi Uap Firmware after 6.5.53 Fix from $2,3002023-08-10 CRITICAL 9.8 CVE-2023-39008 A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 2… Opnsense 23.7+ Fix from $2,3002023-08-09 CRITICAL 9.8 CVE-2023-39001 A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow… Opnsense 23.7+ Fix from $2,3002023-08-09 HIGH 7.2 CVE-2023-32781EPSS 14% A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write p… Prtg Network Monitor 23.3.86.1520+ Fix from $1,9502023-08-09 HIGH 7.2 CVE-2023-32782EPSS 56% A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permis… Prtg Network Monitor 23.3.86.1520+ Fix from $1,9502023-08-09 CRITICAL 9.8 CVE-2023-26310 There is a command injection problem in the old version of the mobile phone backup app. Coloros No fix yet Fix from $2,3002023-08-09 HIGH 7.8 CVE-2023-35390 .NET and Visual Studio Remote Code Execution Vulnerability .net 6.0.21 / 7.0.10+ Fix from $1,9502023-08-08 HIGH 8.8 CVE-2023-39523 ScanCode.io is a server to script and automate software composition analysis with ScanPipe pipelines. Prior to version 32.5.1, the software has a pos… Scancode.io 32.5.1+ Fix from $1,9502023-08-07 HIGH 8.8 CVE-2023-38921 Netgear WG302v2 v5.2.9 and WAG302v2 v5.1.19 were discovered to contain multiple command injection vulnerabilities in the upgrade_handler function via… Wg302v2 Firmware Mitigation only Fix from $1,9502023-08-07 CRITICAL 9.8 CVE-2023-38928 Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi. R7100lg Firmware Mitigation only Fix from $2,3002023-08-07 CRITICAL 9.8 CVE-2023-38690 matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be … Matrix Irc Bridge 1.0.1+ Fix from $2,3002023-08-04 CRITICAL 9.8 CVE-2023-38941 django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCre… Django Sspanel Mitigation only Fix from $2,3002023-08-04 CRITICAL 9.8 CVE-2023-38942 Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json. Dango Translator Patch available Fix from $2,3002023-08-03 CRITICAL 9.8 CVE-2023-4120EPSS 65% A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical. This issue affects some unknown process… Smart S85f after 20230722 Fix from $2,3002023-08-03 CRITICAL 9.8 CVE-2023-37679EPSS 99% A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server. Mirth Connect Mitigation only Fix from $2,3002023-08-03 CRITICAL 9.8 CVE-2023-26317 Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external… Xiaomi Router Firmware 2023.2+ Fix from $2,3002023-08-02 MEDIUM 6.3 CVE-2023-3739 Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbit… Chrome 115.0.5790.131+ Fix from $1,6002023-08-01 MEDIUM 5.5 CVE-2023-31429 Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, … Fabric Operating System 9.1.1c+ Fix from $1,6002023-08-01 HIGH 8.8 CVE-2023-3718 An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results i… Arubaos Cx after 10.11.1010 Fix from $1,9502023-08-01 CRITICAL 9.8 CVE-2022-39986EPSS 99% A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter … Raspap after 2.8.7 Fix from $2,3002023-08-01 HIGH 8.8 CVE-2022-39987EPSS 39% A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entit… Raspap after 2.9.2 Fix from $1,9502023-08-01 CRITICAL 9.8 CVE-2023-34960EPSS 99% A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via … Chamilo after 1.11.18 Fix from $2,3002023-08-01 CRITICAL 9.8 CVE-2023-37214 Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025. Ero1xs Pro Firmware No fix yet Fix from $2,3002023-07-30 HIGH 8.8 CVE-2023-28012 HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server. Bigfix Mobile Mitigation only Fix from $1,9502023-07-27 HIGH 7.2 CVE-2023-28130EPSS 21% Local user may lead to privilege escalation using Gaia Portal hostnames page. Gaia Portal No fix yet Fix from $1,9502023-07-26 CRITICAL 9.8 CVE-2023-37794 WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp. Fbm 291w Firmware No fix yet Fix from $2,3002023-07-14 CRITICAL 9.8 CVE-2023-38336 netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-20… Netkit No fix yet Fix from $2,3002023-07-14