Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Cubecart HIGH 7.2
CVE-2023-47675

CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command.

Fix: 6.5.3+
Fix from $1,950 2023-11-17
Ray CRITICAL 9.8
CVE-2023-6019EPSS 75%

A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remo…

No fix yet
Fix from $2,300 2023-11-16
Mlflow CRITICAL 9.8
CVE-2023-6018EPSS 48%

An attacker can overwrite any file on the server hosting MLflow without any authentication.

No fix yet
Fix from $2,300 2023-11-16
Wrc X3000gs2 W Firmware HIGH 8.0
CVE-2023-43752

OS command injection vulnerability in WRC-X3000GS2-W v1.05 and earlier, WRC-X3000GS2-B v1.05 and earlier, and WRC-X3000GS2A-B v1.05 and earlier allow…

Fix: after 1.05
Fix from $1,950 2023-11-16
Fortisiem CRITICAL 9.8
CVE-2023-36553

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.…

Fix: after 5.1.3
Fix from $2,300 2023-11-14
Ano L6012r Firmware HIGH 7.2
CVE-2023-5037

badmonkey, a Security Researcher has found a flaw that allows for a authenticated command injection on the camera. An attacker could inject malicious…

Fix: 1.41.16+
Fix from $1,950 2023-11-13
Qumagie HIGH 8.8
CVE-2023-39295

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute…

Fix: 2.1.4+
Fix from $1,950 2023-11-10
Qts HIGH 7.2
CVE-2023-23367

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $1,950 2023-11-10
Chromedriver HIGH 7.5
CVE-2023-26156

Versions of the package chromedriver before 119.0.1 are vulnerable to Command Injection when setting the chromedriver.path to an arbitrary system bin…

Fix: 119.0.1+
Fix from $1,950 2023-11-09
Cf7500 Firmware CRITICAL 9.8
CVE-2023-4249EPSS 10%

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 has a …

Mitigation only
Fix from $2,300 2023-11-08
Qts CRITICAL 9.8
CVE-2023-23368EPSS 19%

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $2,300 2023-11-03
Qts CRITICAL 9.8
CVE-2023-23369EPSS 15%

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $2,300 2023-11-03
G 040w Q Firmware HIGH 7.2
CVE-2023-41352

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege can expl…

Mitigation only
Fix from $1,950 2023-11-03
Rt Ax55 Firmware HIGH 8.8
CVE-2023-41345

ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module.…

Mitigation only
Fix from $1,950 2023-11-03
Rt Ax55 Firmware HIGH 8.8
CVE-2023-41346

ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. A…

Mitigation only
Fix from $1,950 2023-11-03
Rt Ax55 Firmware HIGH 8.8
CVE-2023-41347

ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module. An …

Mitigation only
Fix from $1,950 2023-11-03
Rt Ax55 Firmware HIGH 8.8
CVE-2023-41348

ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication mod…

Mitigation only
Fix from $1,950 2023-11-03
Identity Services Engine MEDIUM 6.7
CVE-2023-20170

A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlyi…

Mitigation only
Fix from $1,600 2023-11-01
Identity Services Engine HIGH 8.8
CVE-2023-20175

A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlyi…

Mitigation only
Fix from $1,950 2023-11-01
Secure Firewall Management Center HIGH 8.8
CVE-2023-20219

Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote att…

Fix: after 7.3.1.1
Fix from $1,950 2023-11-01
Franfinance CRITICAL 9.8
CVE-2023-43139

An issue in franfinance before v.2.0.27 allows a remote attacker to execute arbitrary code via the validation.php, and controllers/front/validation.p…

Fix: 1.9.0 / 2.0.27+
Fix from $2,300 2023-10-31
Tinyfiledialogs CRITICAL 9.8
CVE-2023-47104

tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and oth…

Fix: 3.15.0+
Fix from $2,300 2023-10-30
A7000r Firmware CRITICAL 9.8
CVE-2023-46510

An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to th…

Mitigation only
Fix from $2,300 2023-10-27
Tvip 10000 Firmware CRITICAL 9.8
CVE-2018-17558

Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP100…

No fix yet
Fix from $2,300 2023-10-26
Tvip 10000 Firmware CRITICAL 9.8
CVE-2018-17879EPSS 22%

An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several …

No fix yet
Fix from $2,300 2023-10-26
Mirth Connect CRITICAL 9.8
CVE-2023-43208 KEVEPSS 83%

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused …

Fix: 4.4.1+
Fix from $2,300 2023-10-26
Ios Xe HIGH 7.2
CVE-2023-20273 KEVEPSS 90%

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges o…

Mitigation only
Fix from $1,950 2023-10-25
Security Verify Governance HIGH 8.8
CVE-2023-33839

IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially cr…

Patch available
Fix from $1,950 2023-10-23
Unity Operating Environment HIGH 7.8
CVE-2023-43066

Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local attacker to exploit this vulnerabi…

Fix: 5.3.0.0.5.120+
Fix from $1,950 2023-10-23
Client Connector CRITICAL 9.8
CVE-2023-28805

An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affects Client Connector: bef…

Fix: 1.4.0.105+
Fix from $2,300 2023-10-23