Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Fortiwlm CRITICAL 9.8
CVE-2023-36547

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5…

Fix: after 8.6.5
Fix from $2,300 2023-10-10
Fortiwlm CRITICAL 9.8
CVE-2023-36548

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5…

Fix: after 8.6.5
Fix from $2,300 2023-10-10
Fortiwlm CRITICAL 9.8
CVE-2023-36549

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5…

Fix: after 8.6.5
Fix from $2,300 2023-10-10
Fortiisolator HIGH 7.8
CVE-2022-22298

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator version 1.0.0, FortiIsolator v…

Fix: after 2.3.4
Fix from $1,950 2023-10-10
Smart S45f Firmware HIGH 8.8
CVE-2023-5494EPSS 15%

A vulnerability was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928 and classified as critical…

Fix: after 20230928
Fix from $1,950 2023-10-10
Next Gen Application Firewall CRITICAL 9.8
CVE-2023-30805EPSS 66%

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unaut…

No fix yet
Fix from $2,300 2023-10-10
Next Gen Application Firewall CRITICAL 9.8
CVE-2023-30806EPSS 66%

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unaut…

No fix yet
Fix from $2,300 2023-10-10
Geokit Rails CRITICAL 9.8
CVE-2023-26153

Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location'…

Fix: 2.5.0+
Fix from $2,300 2023-10-06
Smartfabric Storage Software HIGH 8.8
CVE-2023-4401

Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of the ‘more’ command. A local or …

Fix: 1.4.1+
Fix from $1,950 2023-10-05
Smartfabric Storage Software HIGH 8.8
CVE-2023-43068

Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the restricted shell in SSH. An authenticated …

Fix: 1.4.1+
Fix from $1,950 2023-10-05
Smartfabric Storage Software HIGH 7.8
CVE-2023-43069

Dell SmartFabric Storage Software v1.4 (and earlier) contain(s) an OS Command Injection Vulnerability in the CLI. An authenticated local attacker cou…

Fix: 1.4.1+
Fix from $1,950 2023-10-05
Session Border Controller HIGH 8.8
CVE-2023-36618

Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticated user…

No fix yet
Fix from $1,950 2023-10-04
Monitoring CRITICAL 9.8
CVE-2023-33269

An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind).

No fix yet
Fix from $2,300 2023-10-03
Monitoring CRITICAL 9.8
CVE-2023-33270

An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind).

No fix yet
Fix from $2,300 2023-10-03
Monitoring CRITICAL 9.8
CVE-2023-33271

An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS command inj…

No fix yet
Fix from $2,300 2023-10-03
Monitoring CRITICAL 9.8
CVE-2023-33272

An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind).

No fix yet
Fix from $2,300 2023-10-03
Monitoring CRITICAL 9.8
CVE-2023-33273

An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind).

No fix yet
Fix from $2,300 2023-10-03
Monitoring CRITICAL 9.8
CVE-2023-33268

An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulnerable to OS command injection …

No fix yet
Fix from $2,300 2023-10-03
Acera 1310 Firmware HIGH 8.8
CVE-2023-39222

OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to execute an arbitrary OS comman…

Fix: after 02.36
Fix from $1,950 2023-10-03
N3m Firmware CRITICAL 9.8
CVE-2023-43892

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerabi…

No fix yet
Fix from $2,300 2023-10-02
N3m Firmware CRITICAL 9.8
CVE-2023-43893

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. Th…

No fix yet
Fix from $2,300 2023-10-02
N3m Firmware HIGH 8.8
CVE-2023-43890

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vulnerability is exploited via …

No fix yet
Fix from $1,950 2023-10-02
Dedecms HIGH 8.8
CVE-2023-5301EPSS 6%

A vulnerability classified as critical was found in DedeCMS 5.7.111. This vulnerability affects the function AddMyAddon of the file album_add.php. Th…

No fix yet
Fix from $1,950 2023-09-30
Pydash HIGH 8.1
CVE-2023-26145

This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_ma…

Fix: 6.0.0+
Fix from $1,950 2023-09-28
Codefever CRITICAL 9.8
CVE-2023-44080

An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchList component.

Mitigation only
Fix from $2,300 2023-09-27
Ios Xe HIGH 8.8
CVE-2023-20231

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affect…

Mitigation only
Fix from $1,950 2023-09-27
Webserver CRITICAL 9.8
CVE-2023-3767

An OS command injection vulnerability has been found on EasyPHP Webserver affecting version 14.1. This vulnerability could allow an attacker to get …

Mitigation only
Fix from $2,300 2023-09-27
Yt Dlp HIGH 7.8
CVE-2023-40581

yt-dlp is a youtube-dl fork with additional features and fixes. yt-dlp allows the user to provide shell command lines to be executed at various stage…

Fix: 2023.09.24+
Fix from $1,950 2023-09-25
Dir 806 Firmware CRITICAL 9.8
CVE-2023-43130

D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection.

No fix yet
Fix from $2,300 2023-09-22
Dir 806 Firmware CRITICAL 9.8
CVE-2023-43129

D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of REMOTE_PORT parameters.

No fix yet
Fix from $2,300 2023-09-22