Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Ac Pd Wapu Firmware HIGH 7.2
CVE-2023-31198

OS command injection vulnerability exists in Wi-Fi AP UNIT allows. If this vulnerability is exploited, a remote authenticated attacker with an admini…

Fix: after 1.05_b04p
Fix from $1,950 2023-06-13
Wps Office HIGH 8.1
CVE-2023-32548

OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects…

Mitigation only
Fix from $1,950 2023-06-13
Fortiadc HIGH 7.8
CVE-2023-26210

Multiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-78] vulnerability in Fortinet…

Fix: after 7.0.5
Fix from $1,950 2023-06-13
Fortiadc HIGH 7.8
CVE-2023-28000

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0 through 7.0.3, 6.2.0 through…

Fix: after 7.0.3
Fix from $1,950 2023-06-13
Megarac Sp X HIGH 8.8
CVE-2023-34334

AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, which may l…

Fix: 12.7 / 13.5+
Fix from $1,950 2023-06-12
Megarac Sp X HIGH 8.8
CVE-2023-34343

AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, which may l…

Fix: 12.7 / 13.5+
Fix from $1,950 2023-06-12
Simple Realtime Server HIGH 7.5
CVE-2023-34105EPSS 9%

SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5.0.157, 5.0-b1, and 6.0.48, S…

Fix: 5.0.157 / 6.0.48+
Fix from $1,950 2023-06-12
Mailcow\ HIGH 8.8
CVE-2023-34108

mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration…

Fix: after 2023-05
Fix from $1,950 2023-06-07
Gpt 2741gnac Firmware HIGH 7.2
CVE-2023-33381EPSS 22%

A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0b7_2). Th…

No fix yet
Fix from $1,950 2023-06-06
Kylin Software Properties HIGH 7.8
CVE-2023-3097

A vulnerability was found in KylinSoft kylin-software-properties on KylinOS. It has been rated as critical. This issue affects the function setMainSo…

Fix: 0.0.1-130+
Fix from $1,950 2023-06-05
Rt Ac86u Firmware HIGH 8.8
CVE-2023-28702

ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this …

Mitigation only
Fix from $1,950 2023-06-02
Dog Camera Firmware HIGH 8.8
CVE-2023-28704

Furbo dog camera has insufficient filtering for special parameter of device log management function. An unauthenticated remote attacker in the Blueto…

Mitigation only
Fix from $1,950 2023-06-02
Coda 5310 Firmware HIGH 7.2
CVE-2022-47616

Hitron CODA-5310 has insufficient filtering for specific parameters in the connection test function. A remote attacker authenticated as an administra…

Mitigation only
Fix from $1,950 2023-06-02
Brook HIGH 8.8
CVE-2023-33965

Brook is a cross-platform programmable network tool. The `tproxy` server is vulnerable to a drive-by command injection. An attacker may fool a victim…

Fix: 20230606+
Fix from $1,950 2023-06-01
Networker CRITICAL 9.8
CVE-2023-25539

Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially …

Fix: 19.7.0.4+
Fix from $2,300 2023-05-31
Fedora CRITICAL 9.8
CVE-2023-34152EPSS 8%

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

Fix: 7.1.1-11+
Fix from $2,300 2023-05-30
Onewireless Network Wireless Device Manager Firmware MEDIUM 6.8
CVE-2022-46361

An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system com…

Mitigation only
Fix from $1,600 2023-05-30
Nas326 Firmware HIGH 7.2
CVE-2023-27988

The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an authenticated …

Fix: 5.21+
Fix from $1,950 2023-05-30
Dolibarr Erp\/crm HIGH 8.8
CVE-2023-30253EPSS 79%

Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.

Fix: 17.0.1+
Fix from $1,950 2023-05-29
N158 HIGH 7.8
CVE-2023-26127

All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function. **Note:** …

Mitigation only
Fix from $1,950 2023-05-27
Keep Module Latest HIGH 7.8
CVE-2023-26128

All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes be…

No fix yet
Fix from $1,950 2023-05-27
Bwm Ng HIGH 7.8
CVE-2023-26129

All versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check' function in the bwm-ng.js fi…

No fix yet
Fix from $1,950 2023-05-27
Cookbook HIGH 8.8
CVE-2023-31128

NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `main-0.9.x` branch, the `pull…

Fix: 0.9.19+
Fix from $1,950 2023-05-26
Fiberlink 210 Firmware HIGH 7.2
CVE-2023-33617EPSS 5%

An OS Command Injection vulnerability in Parks Fiberlink 210 firmware version V2.1.14_X000 was found via the /boaform/admin/formPing target_addr para…

No fix yet
Fix from $1,950 2023-05-23
Vxrail Hyperconverged Infrastructure HIGH 8.2
CVE-2023-23693

Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utility. A local high privileged att…

Fix: 7.0.450+
Fix from $1,950 2023-05-23
Vxrail Hyperconverged Infrastructure HIGH 7.8
CVE-2023-23694

Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local authenticated attacker could p…

Fix: 7.0.450+
Fix from $1,950 2023-05-23
Ac Wapu 300 Firmware HIGH 7.2
CVE-2023-28392

Wi-Fi AP UNIT AC-PD-WAPU v1.05_B04 and earlier, AC-PD-WAPUM v1.05_B04 and earlier, AC-PD-WAPU-P v1.05_B04P and earlier, AC-PD-WAPUM-P v1.05_B04P and …

Fix: after 1.00_b08p
Fix from $1,950 2023-05-23
Beekeeper Studio HIGH 8.8
CVE-2023-28394

Beekeeper Studio versions prior to 3.9.9 allows a remote authenticated attacker to execute arbitrary JavaScript code with the privilege of the applic…

Fix: 3.9.9+
Fix from $1,950 2023-05-23
Sv Cpt Mc310f Firmware HIGH 8.8
CVE-2023-27514

OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior…

Fix: 8.10+
Fix from $1,950 2023-05-23
Sv Cpt Mc310f Firmware HIGH 8.8
CVE-2023-27521

OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions p…

Fix: 8.10+
Fix from $1,950 2023-05-23