Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Stupid Simple Cms CRITICAL 9.8
CVE-2023-6901

A vulnerability, which was classified as critical, was found in codelyfe Stupid Simple CMS up to 1.2.3. This affects an unknown part of the file /ter…

Fix: after 1.2.3
Fix from $2,300 2023-12-17
Intercom Broadcast System CRITICAL 9.8
CVE-2023-6895EPSS 89%

A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability…

Fix: 4.1.0+
Fix from $2,300 2023-12-17
Edge CRITICAL 9.8
CVE-2021-42796

An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitra…

Fix: 2020+
Fix from $2,300 2023-12-16
Mail Sqr Expert HIGH 8.0
CVE-2023-48380

Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a spcific function. A remote a…

Fix: 230330+
Fix from $1,950 2023-12-15
Apex Protection Storage HIGH 7.2
CVE-2023-48667

Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administra…

Fix: 2.7.6 / 6.2.1.110+
Fix from $1,950 2023-12-14
Powerprotect Data Domain Management Center MEDIUM 6.7
CVE-2023-48668

Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 on DDMC contain an OS command injection vulnerability in an…

Fix: 6.2.1.110 / 7.7.5.25+
Fix from $1,600 2023-12-14
Solutions Enabler Virtual Appliance HIGH 7.2
CVE-2023-48662

Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentiall…

Fix: 9.2.4.5 / 9.2.4.7+
Fix from $1,950 2023-12-14
Solutions Enabler Virtual Appliance HIGH 7.2
CVE-2023-48663

Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentiall…

Fix: 9.2.4.5 / 9.2.4.7+
Fix from $1,950 2023-12-14
Solutions Enabler Virtual Appliance HIGH 7.2
CVE-2023-48664

Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentiall…

Fix: 9.2.4.5 / 9.2.4.7+
Fix from $1,950 2023-12-14
Solutions Enabler Virtual Appliance HIGH 7.2
CVE-2023-48665

Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentiall…

Fix: 9.2.4.5 / 9.2.4.7+
Fix from $1,950 2023-12-14
Powerprotect Data Protection MEDIUM 6.7
CVE-2023-44279

Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administ…

Fix: 2.7.6 / 6.2.1.110+
Fix from $1,600 2023-12-14
Powerprotect Data Protection HIGH 7.8
CVE-2023-44277

Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A…

Fix: 2.7.6 / 6.2.1.110+
Fix from $1,950 2023-12-14
Pan Os MEDIUM 6.3
CVE-2023-6792

An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system proces…

Fix: 8.1.24 / 9.0.17+
Fix from $1,600 2023-12-13
W Web CRITICAL 9.8
CVE-2023-42495

Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Fix: after 1.27
Fix from $2,300 2023-12-13
Fortiwlm HIGH 8.8
CVE-2023-48782

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows …

Fix: after 8.6.5
Fix from $1,950 2023-12-13
Fortitester HIGH 7.8
CVE-2023-40716

An improper neutralization of special elements used in an OS command vulnerability [CWE-78]  in the command line interpreter of FortiTester 2.3.0 thr…

Mitigation only
Fix from $1,950 2023-12-13
Gl Ar300m Firmware CRITICAL 9.8
CVE-2023-46454EPSS 23%

In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package in…

Mitigation only
Fix from $2,300 2023-12-12
6gk6108 4am00 2ba2 Firmware MEDIUM 6.7
CVE-2023-49692

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK610…

Fix: 7.2.2+
Fix from $1,600 2023-12-12
6gk6108 4am00 2ba2 Firmware MEDIUM 6.7
CVE-2023-49691

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…

Fix: 8.0+
Fix from $1,600 2023-12-12
Sinec Ins HIGH 7.2
CVE-2023-48428

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not…

Fix: 1.0+
Fix from $1,950 2023-12-12
Wrc X3000gsn Firmware MEDIUM 6.8
CVE-2023-49695

OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adj…

Fix: after 1.0.24
Fix from $1,600 2023-12-12
Ar617vw Firmware HIGH 7.5
CVE-2022-48616

A Huawei data communication product has a command injection vulnerability. Successful exploitation of this vulnerability may allow attackers to gain …

No fix yet
Fix from $1,950 2023-12-12
Vigor167 Firmware CRITICAL 9.8
CVE-2023-47254

An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and esca…

No fix yet
Fix from $2,300 2023-12-09
X5000r Firmware CRITICAL 9.8
CVE-2023-6612EPSS 31%

A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. This issue affects the function setDdnsCfg/setDyn…

No fix yet
Fix from $2,300 2023-12-08
Qvr Firmware HIGH 8.8
CVE-2023-47565 KEVEPSS 73%

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerabili…

Fix: 5.0.0+
Fix from $1,950 2023-12-08
Cloudpanel HIGH 8.8
CVE-2023-46157

File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and ch…

Fix: after 2.3.2
Fix from $1,950 2023-12-08
Mx Se Firmware HIGH 7.2
CVE-2023-43744

An OS command injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 1716…

Fix: 16.0.4 / 17.0.10+
Fix from $1,950 2023-12-08
Ae1021 Firmware HIGH 8.8
CVE-2023-49897 KEVEPSS 51%

An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vu…

Fix: 2.0.10+
Fix from $1,950 2023-12-06
Sma 200 Firmware HIGH 7.2
CVE-2023-44221 KEVEPSS 75%

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative pri…

Fix: after 10.2.1.9-57sv
Fix from $1,950 2023-12-05
Control For Beaglebone Sl HIGH 8.8
CVE-2023-6357

A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the…

Fix: 4.11.0.0+
Fix from $1,950 2023-12-05