Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Sl1 HIGH 8.8
CVE-2022-48586

A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it …

Fix: after 11.1.2
Fix from $1,950 2023-08-09
Sl1 HIGH 8.8
CVE-2022-48580

A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and…

Fix: after 11.1.2
Fix from $1,950 2023-08-09
Sl1 HIGH 8.8
CVE-2022-48581

A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes…

Fix: after 11.1.2
Fix from $1,950 2023-08-09
Commerce HIGH 7.2
CVE-2023-38208

Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Improper Neutralization of Speci…

Fix: 2.4.4+
Fix from $1,950 2023-08-09
Wp 6070 Wvps Firmware HIGH 8.8
CVE-2023-37861

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions wit…

Fix: 4.0.10+
Fix from $1,950 2023-08-09
Wp 6070 Wvps Firmware HIGH 7.2
CVE-2023-37863

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP re…

Fix: 4.0.10+
Fix from $1,950 2023-08-09
Emagic Data Center Management HIGH 8.8
CVE-2023-37569EPSS 34%

This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated …

Fix: after 6.0
Fix from $1,950 2023-08-08
Wp 6070 Wvps Firmware HIGH 8.8
CVE-2023-3570

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE reques…

Fix: 4.0.10+
Fix from $1,950 2023-08-08
Wp 6070 Wvps Firmware HIGH 8.8
CVE-2023-3571

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP POST releated…

Fix: 4.0.10+
Fix from $1,950 2023-08-08
Wp 6070 Wvps Firmware CRITICAL 10.0
CVE-2023-3572

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP …

Fix: 4.0.10+
Fix from $2,300 2023-08-08
Wp 6070 Wvps Firmware HIGH 8.8
CVE-2023-3573

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP…

Fix: 4.0.10+
Fix from $1,950 2023-08-08
Cloudexplorer Lite CRITICAL 9.8
CVE-2023-38692

CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the…

Fix: 1.3.1+
Fix from $2,300 2023-08-04
Connected Io CRITICAL 9.8
CVE-2023-33374

Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands f…

Fix: after 2.1.0
Fix from $2,300 2023-08-04
Connected Io CRITICAL 9.8
CVE-2023-33377

Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, enabling a…

Fix: after 2.1.0
Fix from $2,300 2023-08-04
Biostar 2 HIGH 8.8
CVE-2023-33364

An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to execute arbitrary OS commands on…

Fix: 2.9.1+
Fix from $1,950 2023-08-03
License Plate Verifier HIGH 8.8
CVE-2023-21411

User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution.

Fix: after 2.8.3
Fix from $1,950 2023-08-03
License Plate Verifier HIGH 8.8
CVE-2023-21410

User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution.

Fix: after 2.8.3
Fix from $1,950 2023-08-03
Xiaomi Router Firmware CRITICAL 9.8
CVE-2023-26317

Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external…

Fix: 2023.2+
Fix from $2,300 2023-08-02
Fabric Operating System HIGH 7.8
CVE-2023-31425

A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local a…

Mitigation only
Fix from $1,950 2023-08-01
Mlflow HIGH 7.8
CVE-2023-4033

OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.

Fix: 2.6.0+
Fix from $1,950 2023-08-01
H12dst B Firmware CRITICAL 9.8
CVE-2023-35861

A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to injec…

Fix: 03.10.35+
Fix from $2,300 2023-07-31
Security Verify Governance HIGH 8.8
CVE-2023-35019

IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by send…

Mitigation only
Fix from $1,950 2023-07-31
Synergy\/a Firmware CRITICAL 9.8
CVE-2023-37213

Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'

Fix: 3015.1+
Fix from $2,300 2023-07-30
Drawio CRITICAL 9.8
CVE-2023-3974

OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0.

Fix: 21.4.0+
Fix from $2,300 2023-07-27
Drawio CRITICAL 9.8
CVE-2023-3975

OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0.

Fix: 21.5.0+
Fix from $2,300 2023-07-27
Paddlepaddle CRITICAL 9.8
CVE-2023-38673

PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.

Fix: 2.5.0+
Fix from $2,300 2023-07-26
Otrs HIGH 7.2
CVE-2023-38056

Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows …

Fix: 7.0.45 / 8.0.35+
Fix from $1,950 2023-07-24
Vm2 CRITICAL 10.0
CVE-2023-37903

vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to esc…

Fix: after 3.9.19
Fix from $2,300 2023-07-21
Isherlock CRITICAL 9.8
CVE-2023-37292

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modul…

Fix: 4.5-174 / 5.5-174+
Fix from $2,300 2023-07-21
Ngc Indoor Unit Firmware CRITICAL 9.8
CVE-2023-36670

A remotely exploitable command injection vulnerability was found on the Kratos NGC-IDU 9.1.0.4. An attacker can execute arbitrary Linux commands as r…

Mitigation only
Fix from $2,300 2023-07-18