Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Netmodule Router Software MEDIUM 6.6
CVE-2023-46306

The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command constructed…

Fix: 4.6.0.105 / 4.7.0.103+
Fix from $1,600 2023-10-22
Smart S85f Firmware CRITICAL 9.8
CVE-2023-5684EPSS 78%

A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231012. It has been declared as critical. Affected by this vulnerability i…

Fix: after 2023-10-12
Fix from $2,300 2023-10-21
Smart S85f Firmware CRITICAL 9.8
CVE-2023-5683EPSS 18%

A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231010 and classified as critical. This issue affects some unknown process…

Fix: after 2023-10-10
Fix from $2,300 2023-10-21
Reconftw HIGH 8.8
CVE-2023-46117

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulner…

Fix: 2.7.1.1+
Fix from $1,950 2023-10-20
Qusbcam2 HIGH 8.8
CVE-2023-23373

An OS command injection vulnerability has been reported to affect QUSBCam2. If exploited, the vulnerability could allow users to execute commands via…

Fix: 2.0.3+
Fix from $1,950 2023-10-20
Cmt Fhd Firmware HIGH 8.8
CVE-2023-40145

In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to the device.

Fix: 20210206 / 20210212+
Fix from $1,950 2023-10-19
Sip T19p E2 Firmware HIGH 8.8
CVE-2023-43959

An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of …

No fix yet
Fix from $1,950 2023-10-17
Freshtomato CRITICAL 9.8
CVE-2023-3991

An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially crafted HTTP request can lead…

Mitigation only
Fix from $2,300 2023-10-16
Web2py CRITICAL 9.8
CVE-2023-45158

An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not t…

Fix: after 2.24.1
Fix from $2,300 2023-10-16
Axis Os HIGH 7.2
CVE-2023-21413

GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis …

Fix: 10.12.199 / 11.6.94+
Fix from $1,950 2023-10-16
Node Qpdf CRITICAL 9.8
CVE-2023-26155

All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt() fails to sanitize its param…

No fix yet
Fix from $2,300 2023-10-14
Container Station HIGH 7.2
CVE-2023-32976

An OS command injection vulnerability has been reported to affect Container Station. If exploited, the vulnerability could allow authenticated admini…

Fix: 2.6.7.44+
Fix from $1,950 2023-10-13
Video Station HIGH 8.8
CVE-2023-34975

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Fix: 5.7.0+
Fix from $1,950 2023-10-13
N3m Firmware CRITICAL 9.8
CVE-2023-45467

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Time Settings.

No fix yet
Fix from $2,300 2023-10-13
Surf Soho Firmware HIGH 8.8
CVE-2023-34356EPSS 6%

An OS command injection vulnerability exists in the data.cgi xfer_dns functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HT…

No fix yet
Fix from $1,950 2023-10-11
Surf Soho Firmware HIGH 8.8
CVE-2023-35193EPSS 6%

An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially …

No fix yet
Fix from $1,950 2023-10-11
Surf Soho Firmware HIGH 8.8
CVE-2023-35194EPSS 6%

An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially …

No fix yet
Fix from $1,950 2023-10-11
Surf Soho Firmware HIGH 8.8
CVE-2023-27380EPSS 6%

An OS command injection vulnerability exists in the admin.cgi USSD_send functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted …

No fix yet
Fix from $1,950 2023-10-11
Surf Soho Firmware HIGH 8.8
CVE-2023-28381EPSS 6%

An OS command injection vulnerability exists in the admin.cgi MVPN_trial_init functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially cr…

No fix yet
Fix from $1,950 2023-10-11
Fortiwlm CRITICAL 9.8
CVE-2023-36550

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5…

Fix: after 8.6.5
Fix from $2,300 2023-10-10
Fortianalyzer HIGH 7.1
CVE-2023-41838

An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow…

Fix: after 7.2.3
Fix from $1,950 2023-10-10
Fortianalyzer MEDIUM 6.7
CVE-2023-42788

An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer …

Fix: after 7.2.3
Fix from $1,600 2023-10-10
Fortiadc HIGH 7.8
CVE-2023-25607

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 through 7…

Fix: after 7.0.7
Fix from $1,950 2023-10-10
Fortiwlm HIGH 8.8
CVE-2023-34985

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5…

Fix: after 8.6.5
Fix from $1,950 2023-10-10
Fortiwlm HIGH 8.8
CVE-2023-34986

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5…

Fix: after 8.6.5
Fix from $1,950 2023-10-10
Fortiwlm HIGH 8.8
CVE-2023-34987

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5…

Fix: after 8.6.5
Fix from $1,950 2023-10-10
Fortiwlm HIGH 8.8
CVE-2023-34988

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5…

Fix: after 8.6.5
Fix from $1,950 2023-10-10
Fortiwlm HIGH 8.8
CVE-2023-34989

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5…

Fix: after 8.6.5
Fix from $1,950 2023-10-10
Fortisiem CRITICAL 9.8
CVE-2023-34992EPSS 80%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute un…

Fix: after 6.7.5
Fix from $2,300 2023-10-10
Fortiwlm CRITICAL 9.8
CVE-2023-34993EPSS 18%

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5…

Fix: after 8.6.5
Fix from $2,300 2023-10-10