Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Ur32l Firmware HIGH 7.2
CVE-2023-23550

An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5. A specially crafted network…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 8.8
CVE-2023-22299

An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. A specially crafted network r…

No fix yet
Fix from $1,950 2023-07-06
Ur32l Firmware HIGH 7.2
CVE-2023-22365

An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32.3.0.5. A specially crafted s…

Mitigation only
Fix from $1,950 2023-07-06
Pax A930 Firmware MEDIUM 6.8
CVE-2023-27198

PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the exec service and including a s…

Mitigation only
Fix from $1,600 2023-07-05
Miniserver Go Gen 2 Firmware HIGH 7.2
CVE-2023-36622

The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary…

Fix: 14.1.5.9+
Fix from $1,950 2023-07-05
Enterprise Security Manager HIGH 8.8
CVE-2023-3314

A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands u…

Fix: 11.6.7+
Fix from $1,950 2023-07-03
Enterprise Security Manager HIGH 7.8
CVE-2023-3313

An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthor…

Fix: 11.6.7+
Fix from $1,950 2023-07-03
My Cloud Os MEDIUM 6.7
CVE-2023-22815

Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in t…

Fix: 5.26.300+
Fix from $1,600 2023-06-30
My Cloud Os HIGH 8.8
CVE-2023-22816

A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to b…

Fix: 5.26.300+
Fix from $1,950 2023-06-30
Wl Wn531ax2 Firmware HIGH 7.2
CVE-2023-32622

Improper neutralization of special elements in WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to …

Fix: 2023526+
Fix from $1,950 2023-06-30
Maxlink 1200g Firmware HIGH 8.8
CVE-2023-36143

Maxprint Maxlink 1200G v3.4.11E has an OS command injection vulnerability in the "Diagnostic tool" functionality of the device.

Mitigation only
Fix from $1,950 2023-06-30
Wireless Appliance Firmware CRITICAL 9.8
CVE-2022-44720

An issue was discovered in Weblib Ucopia before 6.0.13. OS Command Injection injection can occur, related to chroot.

Fix: 6.0.13+
Fix from $2,300 2023-06-29
Dir 823g Firmware CRITICAL 9.8
CVE-2023-26613EPSS 31%

An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system…

No fix yet
Fix from $2,300 2023-06-29
Rg Bcr860 Firmware HIGH 7.2
CVE-2023-3450EPSS 50%

A vulnerability was found in Ruijie RG-BCR860 2.5.13 and classified as critical. This issue affects some unknown processing of the component Network …

No fix yet
Fix from $1,950 2023-06-28
Txpert Hub Coretec 4 Firmware HIGH 8.0
CVE-2023-2625

A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, having any le…

Fix: 3.0.1+
Fix from $1,950 2023-06-28
Git Commit Info CRITICAL 9.8
CVE-2023-26134

Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails…

Fix: 2.0.2+
Fix from $2,300 2023-06-28
Aterm Wf300hp Firmware HIGH 7.2
CVE-2023-3333

Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG…

Mitigation only
Fix from $1,950 2023-06-28
Xclarity Administrator HIGH 7.2
CVE-2023-34420

A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.

Fix: 4.0.0+
Fix from $1,950 2023-06-26
Openwb CRITICAL 9.8
CVE-2023-30261EPSS 32%

Command Injection vulnerability in OpenWB 1.6 and 1.7 allows remote attackers to run arbitrary commands via crafted GET request.

Patch available
Fix from $2,300 2023-06-26
Glpi Agent HIGH 7.2
CVE-2023-34254

The GLPI Agent is a generic management agent. Prior to version 1.5, if glpi-agent is running remoteinventory task against an Unix platform with ssh c…

Fix: 1.5+
Fix from $1,950 2023-06-23
Magnusbilling CRITICAL 9.8
CVE-2023-30258EPSS 94%

Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTT…

Fix: after 7.3.0
Fix from $2,300 2023-06-23
Livebook CRITICAL 9.8
CVE-2023-35174

Livebook is a web application for writing interactive and collaborative code notebooks. On Windows, it is possible to open a `livebook://` link from …

Fix: 0.8.2 / 0.9.3+
Fix from $2,300 2023-06-22
Gl E750 Firmware HIGH 7.2
CVE-2023-24261EPSS 19%

A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.

Fix: 3.216+
Fix from $1,950 2023-06-21
Envoy Firmware CRITICAL 9.8
CVE-2023-33869

Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands.

Mitigation only
Fix from $2,300 2023-06-20
Nas326 Firmware CRITICAL 9.8
CVE-2023-27992 KEVEPSS 84%

The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prio…

Fix: 5.21+
Fix from $2,300 2023-06-19
Kioware HIGH 7.8
CVE-2023-34642

KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issue can all…

Fix: after 8.33
Fix from $1,950 2023-06-19
Bisheng Wnm Firmware CRITICAL 9.8
CVE-2022-48472

A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected product versions…

Mitigation only
Fix from $2,300 2023-06-16
Go Rt Ac750 Firmware CRITICAL 9.8
CVE-2023-34800EPSS 29%

D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.

No fix yet
Fix from $2,300 2023-06-15
Security Directory Suite Va HIGH 8.8
CVE-2022-32752

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a remote authenticated attacker to execute arbitrary commands on the system by sen…

Fix: after 8.0.1.19
Fix from $1,950 2023-06-15
Kb Ahr04d Firmware CRITICAL 9.8
CVE-2023-30764

OS command injection vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be exe…

Fix: 91110.1.101106.78 / 91210.1.101106.78+
Fix from $2,300 2023-06-13