Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Qumagie HIGH 8.8
CVE-2023-47560

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute…

Mitigation only
Fix from $1,950 2024-01-05
Video Station HIGH 8.8
CVE-2023-41288

An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to execute command…

Fix: 5.7.2+
Fix from $1,950 2024-01-05
Qcalagent HIGH 8.8
CVE-2023-41289

An OS command injection vulnerability has been reported to affect QcalAgent. If exploited, the vulnerability could allow authenticated users to execu…

Fix: 1.1.8+
Fix from $1,950 2024-01-05
Qts HIGH 7.2
CVE-2023-39294

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $1,950 2024-01-05
Paddlepaddle CRITICAL 9.8
CVE-2023-52314

PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operati…

Fix: 2.6.0+
Fix from $2,300 2024-01-03
Paddlepaddle CRITICAL 9.8
CVE-2023-52310

PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the oper…

Fix: 2.6.0+
Fix from $2,300 2024-01-03
Paddlepaddle CRITICAL 9.8
CVE-2023-52311

PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating syst…

Fix: 2.6.0+
Fix from $2,300 2024-01-03
Rengine HIGH 8.8
CVE-2023-50094EPSS 14%

reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_d…

Fix: after 2.0.2
Fix from $1,950 2024-01-01
X6000r Firmware CRITICAL 9.8
CVE-2023-50651

TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cg…

Mitigation only
Fix from $2,300 2023-12-30
Ccx 400 Firmware HIGH 7.2
CVE-2023-4464

A vulnerability, which was classified as critical, has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 5…

Mitigation only
Fix from $1,950 2023-12-29
Gl Mt1300 Firmware HIGH 7.8
CVE-2023-50445EPSS 9%

Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N…

No fix yet
Fix from $1,950 2023-12-28
Datax Web CRITICAL 9.8
CVE-2023-7116EPSS 9%

A vulnerability, which was classified as critical, has been found in WeiYe-Jing datax-web 2.1.2. Affected by this issue is some unknown functionality…

No fix yet
Fix from $2,300 2023-12-27
M3 Firmware CRITICAL 9.8
CVE-2023-51094

Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet.

No fix yet
Fix from $2,300 2023-12-26
W9 Firmware CRITICAL 9.8
CVE-2023-51098

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formSetDiagnoseInfo .

No fix yet
Fix from $2,300 2023-12-26
W9 Firmware CRITICAL 9.8
CVE-2023-51099

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand .

No fix yet
Fix from $2,300 2023-12-26
W9 Firmware CRITICAL 9.8
CVE-2023-51100

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseInfo .

No fix yet
Fix from $2,300 2023-12-26
Vr S1000 Firmware MEDIUM 6.8
CVE-2023-45741

VR-S1000 firmware Ver. 2.37 and earlier allows an attacker with access to the product's web management page to execute arbitrary OS commands.

Fix: after 2.37
Fix from $1,600 2023-12-26
Network Functions Manager For Transport HIGH 8.8
CVE-2022-39818

In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. T…

No fix yet
Fix from $1,950 2023-12-25
Kylin System Updater HIGH 7.8
CVE-2023-7093

A vulnerability classified as critical has been found in KylinSoft kylin-system-updater up to 2.0.5.16-0k2.33. Affected is an unknown function of the…

Fix: after 2.0.5.16-0k2.33
Fix from $1,950 2023-12-25
Backup Migration HIGH 7.2
CVE-2023-7002EPSS 46%

The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter.…

Fix: 1.4.0+
Fix from $1,950 2023-12-23
Ex1200l Firmware CRITICAL 9.8
CVE-2023-51033

TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi setOpModeCfg interface.

No fix yet
Fix from $2,300 2023-12-22
Ex1200l Firmware CRITICAL 9.8
CVE-2023-51035

TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost interface.

No fix yet
Fix from $2,300 2023-12-22
A3700r Firmware CRITICAL 9.8
CVE-2023-50147

There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its…

No fix yet
Fix from $2,300 2023-12-22
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51028

TOTOLINK EX1800T 9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the apcliChannel parameter of the setWiFiExtende…

No fix yet
Fix from $2,300 2023-12-22
Rg Ws6008 Firmware CRITICAL 9.8
CVE-2023-50993

Ruijie WS6008 v1.x v2.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 and WS6108 v1.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 was discovered to contain a command i…

Mitigation only
Fix from $2,300 2023-12-20
Informix Jdbc CRITICAL 9.8
CVE-2023-35895

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a cert…

Mitigation only
Fix from $2,300 2023-12-20
Toby L200 Firmware MEDIUM 6.8
CVE-2023-0011

A flaw in the input validation in TOBY-L2 allows a user to execute arbitrary operating system commands using specifically crafted AT commands. This v…

Mitigation only
Fix from $1,600 2023-12-20
Cmt2078x Firmware HIGH 8.8
CVE-2023-50466

An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2023-12-19
Tts Api CRITICAL 9.8
CVE-2019-25158

A vulnerability has been found in pedroetb tts-api up to 2.1.4 and classified as critical. This vulnerability affects the function onSpeechDone of th…

Fix: 2.2.0+
Fix from $2,300 2023-12-19
Debian Linux MEDIUM 6.5
CVE-2023-51385EPSS 20%

In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by a…

Fix: 9.6+
Fix from $1,600 2023-12-18