Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
1panel HIGH 8.8
CVE-2023-37477EPSS 6%

1Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability exists in 1Panel firewall fun…

Fix: 1.4.3+
Fix from $1,950 2023-07-18
Ras Collection Instrument CRITICAL 9.8
CVE-2020-36762

A vulnerability was found in ONS Digital RAS Collection Instrument up to 2.0.27 and classified as critical. Affected by this issue is the function jo…

Fix: 2.0.28+
Fix from $2,300 2023-07-18
Usg 20w Vpn Firmware HIGH 8.8
CVE-2023-33012EPSS 10%

A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series fi…

Fix: 5.37+
Fix from $1,950 2023-07-17
Usg 20w Vpn Firmware HIGH 8.0
CVE-2023-34138

A command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USG FLEX ser…

Fix: 5.37+
Fix from $1,950 2023-07-17
Usg 2200 Vpn Firmware HIGH 8.8
CVE-2023-34139

A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and …

Fix: 5.37+
Fix from $1,950 2023-07-17
Usg 20w Vpn Firmware HIGH 8.0
CVE-2023-34141

A command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions 5.00 through 5.36 Patch 2, US…

Fix: 5.37+
Fix from $1,950 2023-07-17
Usg 2200 Vpn Firmware HIGH 8.8
CVE-2023-28767

The configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX series firmwar…

Fix: 5.37+
Fix from $1,950 2023-07-17
Mso5000 Firmware CRITICAL 9.8
CVE-2023-38378

The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to execute arbitrary code via shell …

No fix yet
Fix from $2,300 2023-07-16
Wrc 1167ghbk S Firmware HIGH 8.0
CVE-2023-37564

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute an arbitrary OS command…

Fix: after 1.24
Fix from $1,950 2023-07-13
Analytics HIGH 8.8
CVE-2023-34127EPSS 86%

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enable…

Fix: 9.3.2+
Fix from $1,950 2023-07-13
Zoom HIGH 8.8
CVE-2023-34116

Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of priv…

Fix: 5.15.0+
Fix from $1,950 2023-07-11
Fortiweb HIGH 7.2
CVE-2023-23777

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0.1 and be…

Fix: after 6.4.3
Fix from $1,950 2023-07-11
Netweaver HIGH 8.8
CVE-2023-36922

Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arb…

Mitigation only
Fix from $1,950 2023-07-11
Bcr810w Firmware HIGH 8.8
CVE-2023-3608EPSS 12%

A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracer…

No fix yet
Fix from $1,950 2023-07-10
Tamronos HIGH 8.8
CVE-2023-3606EPSS 7%

A vulnerability was found in TamronOS up to 20230703. It has been classified as critical. This affects an unknown part of the file /api/ping. The man…

Fix: after 20230703
Fix from $1,950 2023-07-10
Kodbox HIGH 8.0
CVE-2023-3607EPSS 6%

A vulnerability was found in kodbox 1.26. It has been declared as critical. This vulnerability affects the function Execute of the file webconsole.ph…

No fix yet
Fix from $1,950 2023-07-10
Quantastor HIGH 7.2
CVE-2021-42081

An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC http://<IP_ADDRESS>/qstorapi/storageSystemMo…

Fix: 6.0.0.355+
Fix from $1,950 2023-07-10
A3300r Firmware CRITICAL 9.8
CVE-2023-37170

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the lang parameter…

No fix yet
Fix from $2,300 2023-07-07
A3300r Firmware CRITICAL 9.8
CVE-2023-37171

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg f…

No fix yet
Fix from $2,300 2023-07-07
A3300r Firmware CRITICAL 9.8
CVE-2023-37172

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg funct…

No fix yet
Fix from $2,300 2023-07-07
A3300r Firmware CRITICAL 9.8
CVE-2023-37173

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg…

No fix yet
Fix from $2,300 2023-07-07
Ur32l Firmware HIGH 7.2
CVE-2023-25582

Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 7.2
CVE-2023-25583

Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 8.8
CVE-2023-24519

Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-craf…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 8.8
CVE-2023-24520

Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-craf…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 8.8
CVE-2023-24582

Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted ne…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 7.2
CVE-2023-24595

An OS command injection vulnerability exists in the ys_thirdparty system_user_script functionality of Milesight UR32L v32.3.0.5. A specially crafted …

No fix yet
Fix from $1,950 2023-07-06
Milesightvpn HIGH 8.1
CVE-2023-22371

An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2. A specially-crafted network…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 8.8
CVE-2023-22653EPSS 6%

An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP …

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 7.2
CVE-2023-22659

An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted netwo…

No fix yet
Fix from $1,950 2023-07-06