Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Ac21000 G6 Firmware MEDIUM 6.8
CVE-2023-24046

An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in the ping ut…

No fix yet
Fix from $1,600 2023-12-04
X6000r Firmware CRITICAL 9.8
CVE-2023-48800

In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the …

No fix yet
Fix from $2,300 2023-12-04
Dm5500 Firmware HIGH 8.8
CVE-2023-44304

Dell DM5500 contains a privilege escalation vulnerability in the appliance. A remote attacker with low privileges could potentially exploit this vuln…

Fix: after 5.14.0.0
Fix from $1,950 2023-12-04
Powerprotect Data Manager Dm5500 Firmware HIGH 7.2
CVE-2023-44291

Dell DM5500 5.14.0.0 contains an OS command injection vulnerability in the appliance. A remote attacker with high privileges could potentially exploi…

Fix: after 5.14.0.0
Fix from $1,950 2023-12-04
Go Rt Ac750 Firmware CRITICAL 9.8
CVE-2023-48842

D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.

No fix yet
Fix from $2,300 2023-12-01
X6000r Firmware CRITICAL 9.8
CVE-2023-48808

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48810

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48811

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48812

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function t…

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48802

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48803

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48804

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48805

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48806

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48807

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30
Nas326 Firmware HIGH 8.8
CVE-2023-37928EPSS 60%

A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware ve…

Fix: after 5.21
Fix from $1,950 2023-11-30
Nas326 Firmware CRITICAL 9.8
CVE-2023-4473EPSS 41%

A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C…

Fix: after 5.21
Fix from $2,300 2023-11-30
Nas326 Firmware CRITICAL 9.8
CVE-2023-4474EPSS 30%

The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version …

Fix: after 5.21
Fix from $2,300 2023-11-30
Nas326 Firmware CRITICAL 9.8
CVE-2023-35138EPSS 40%

A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firm…

Fix: after 5.21
Fix from $2,300 2023-11-30
Nas326 Firmware HIGH 8.8
CVE-2023-37927

The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version …

Fix: after 5.21
Fix from $1,950 2023-11-30
Itk 6dgs 1\(bk\)tel Firmware CRITICAL 9.8
CVE-2023-3741

An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on the device.

Mitigation only
Fix from $2,300 2023-11-30
Netlink Ccd Firmware CRITICAL 9.8
CVE-2023-23325

Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the NetHostname parameter.

Mitigation only
Fix from $2,300 2023-11-29
Panorama HIGH 8.8
CVE-2023-6201

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Univera Computer System Panorama allows C…

Fix: 8.0+
Fix from $1,950 2023-11-28
Chamilo Lms HIGH 8.8
CVE-2023-4222

Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtai…

Fix: after 1.11.24
Fix from $1,950 2023-11-28
Chamilo Lms HIGH 8.8
CVE-2023-4221

Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain…

Fix: after 1.11.24
Fix from $1,950 2023-11-28
Chamilo CRITICAL 9.8
CVE-2023-3368EPSS 69%

Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code…

Fix: 1.11.20+
Fix from $2,300 2023-11-28
Mosesdecoder CRITICAL 9.8
CVE-2023-6309

A vulnerability, which was classified as critical, was found in moses-smt mosesdecoder up to 4.0. This affects an unknown part of the file contrib/iS…

Fix: 4.0+
Fix from $2,300 2023-11-27
Tr118 Firmware HIGH 8.0
CVE-2023-6304EPSS 10%

A vulnerability was found in Tecno 4G Portable WiFi TR118 TR118-M30E-RR-D-EnFrArSwHaPo-OP-V008-20220830. It has been declared as critical. This vulne…

No fix yet
Fix from $1,950 2023-11-27
0852 0602 Firmware CRITICAL 9.8
CVE-2023-4149

A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system contro…

Fix: 1.0.6.s0 / 1.2.5.s0+
Fix from $2,300 2023-11-21
Me Rtu Firmware CRITICAL 9.8
CVE-2023-35762

Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could allow remote code execution.

Fix: 3.37+
Fix from $2,300 2023-11-20