Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Pgadmin 4 HIGH 8.8
CVE-2023-5002

A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a user selects to external PostgreSQL utilities su…

Fix: 7.7+
Fix from $1,950 2023-09-22
Satellite CRITICAL 9.1
CVE-2022-3874

A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile comm…

Mitigation only
Fix from $2,300 2023-09-22
Qts HIGH 8.8
CVE-2023-23362

An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated…

Fix: 4.5.4.2374 / 5.0.1.2376+
Fix from $1,950 2023-09-22
Satellite CRITICAL 9.1
CVE-2023-0118

An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on …

Fix: 6.13.3+
Fix from $2,300 2023-09-20
Dolibarr Erp\/crm HIGH 7.2
CVE-2023-38886EPSS 29%

An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.

Fix: after 17.0.1
Fix from $1,950 2023-09-20
Ekorrci Firmware HIGH 8.8
CVE-2022-47555

Operating system command injection in ekorCCP and ekorRCI, which could allow an authenticated attacker to execute commands, create new users with ele…

Mitigation only
Fix from $1,950 2023-09-19
Wmpro HIGH 7.2
CVE-2023-35850

SUNNET WMPro portal's file management function has a vulnerability of insufficient filtering for user input. A remote attacker with administrator pri…

Mitigation only
Fix from $1,950 2023-09-18
Smart Trade CRITICAL 9.8
CVE-2023-28614

Freewill iFIS (aka SMART Trade) 20.01.01.04 allows OS Command Injection via shell metacharacters to a report page.

Mitigation only
Fix from $2,300 2023-09-15
Fortitester HIGH 7.8
CVE-2023-36642

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through …

Fix: after 7.2.3
Fix from $1,950 2023-09-13
Fortiadc HIGH 8.8
CVE-2022-35849

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 through 7.1…

Fix: 6.2.6 / 7.0.4+
Fix from $1,950 2023-09-13
Rt Ax55 Firmware HIGH 8.8
CVE-2023-39780 KEVEPSS 34%

On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist paramete…

Mitigation only
Fix from $1,950 2023-09-11
Smart S45f Firmware CRITICAL 9.8
CVE-2023-4873EPSS 75%

A vulnerability, which was classified as critical, was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to …

Fix: after 20230906
Fix from $2,300 2023-09-10
Identity Services Engine MEDIUM 6.7
CVE-2023-20193

A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary fi…

Fix: after 3.3
Fix from $1,600 2023-09-07
Rt Ac86u Firmware HIGH 8.8
CVE-2023-38032

ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege …

Mitigation only
Fix from $1,950 2023-09-07
Rt Ac86u Firmware HIGH 8.8
CVE-2023-38033

ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user …

Mitigation only
Fix from $1,950 2023-09-07
Rt Ac86u Firmware HIGH 8.8
CVE-2023-39236

ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege ca…

Mitigation only
Fix from $1,950 2023-09-07
Rt Ac86u Firmware HIGH 8.8
CVE-2023-39237

ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privileg…

Mitigation only
Fix from $1,950 2023-09-07
Rt Ac86u Firmware HIGH 8.8
CVE-2023-38031

ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can …

Mitigation only
Fix from $1,950 2023-09-07
Magento HIGH 7.2
CVE-2021-36023

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the W…

Fix: 2.3.7 / 2.4.2+
Fix from $1,950 2023-09-06
F Revocrm CRITICAL 9.8
CVE-2023-41149

F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can acces…

Mitigation only
Fix from $2,300 2023-09-06
Archer Ax6000 Firmware HIGH 8.0
CVE-2023-40531

Archer AX6000 firmware versions prior to 'Archer AX6000(JP)_V1_1.3.0 Build 20221208' allows a network-adjacent authenticated attacker to execute arbi…

Fix: 1.3.0+
Fix from $1,950 2023-09-06
Archer C1200 Firmware HIGH 8.8
CVE-2023-38563

Archer C1200 firmware versions prior to 'Archer C1200(JP)_V2_230508' and Archer C9 firmware versions prior to 'Archer C9(JP)_V3_230508' allow a netwo…

Fix: 230508+
Fix from $1,950 2023-09-06
Archer A10 Firmware HIGH 8.8
CVE-2023-38568

Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504' allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands.

Fix: 230504+
Fix from $1,950 2023-09-06
Archer C3150 Firmware HIGH 8.0
CVE-2023-38588

Archer C3150 firmware versions prior to 'Archer C3150(JP)_V2_230511' allows a network-adjacent authenticated attacker to execute arbitrary OS command…

Fix: 230511+
Fix from $1,950 2023-09-06
Archer C7 Firmware HIGH 8.0
CVE-2023-39224

Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to…

Fix: 230602+
Fix from $1,950 2023-09-06
Archer C5400 Firmware HIGH 8.0
CVE-2023-39935

Archer C5400 firmware versions prior to 'Archer C5400(JP)_V2_230506' allows a network-adjacent authenticated attacker to execute arbitrary OS command…

Fix: 230506+
Fix from $1,950 2023-09-06
Deco M4 Firmware HIGH 8.0
CVE-2023-40193

Deco M4 firmware versions prior to 'Deco M4(JP)_V2_1.5.8 Build 20230619' allows a network-adjacent authenticated attacker to execute arbitrary OS com…

Fix: 1.5.8+
Fix from $1,950 2023-09-06
Archer Ax50 Firmware HIGH 8.0
CVE-2023-40357

Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows…

Fix: 230508 / 230523+
Fix from $1,950 2023-09-06
Archer C55 Firmware HIGH 8.0
CVE-2023-31188

Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows…

Fix: 230505 / 230506+
Fix from $1,950 2023-09-06
Tl Wr902ac Firmware HIGH 8.8
CVE-2023-36489

Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follo…

Fix: 221008 / 230506+
Fix from $1,950 2023-09-06