Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Rut200 Firmware HIGH 8.8
CVE-2023-32350

Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua servi…

Fix: after 00.07.03
Fix from $1,950 2023-05-22
Archer Vr1600v Firmware MEDIUM 6.7
CVE-2023-31756

A command injection vulnerability exists in the administrative web portal in TP-Link Archer VR1600V devices running firmware Versions <= 0.1.0. 0.9.1…

Fix: after 0.1.0_0.9.1_v5006.0_build_200810_rel.53181n
Fix from $1,600 2023-05-19
Identity Services Engine HIGH 7.2
CVE-2023-20163

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the un…

Fix: after 2.7
Fix from $1,950 2023-05-18
Identity Services Engine HIGH 7.2
CVE-2023-20164

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the un…

Fix: after 2.7
Fix from $1,950 2023-05-18
Fedora HIGH 8.8
CVE-2023-24805

cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. …

Fix: 2.0+
Fix from $1,950 2023-05-17
Compact Controller 100 Firmware CRITICAL 9.8
CVE-2023-1698EPSS 82%

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which…

Fix: after 23
Fix from $2,300 2023-05-15
Enterprise Va Max HIGH 8.8
CVE-2020-13378

Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to execute arb…

Fix: after 8.3.8
Fix from $1,950 2023-05-12
My Cloud Os CRITICAL 9.8
CVE-2022-29841

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files…

Fix: 5.26.119+
Fix from $2,300 2023-05-10
Infoscale Operations Manager HIGH 7.2
CVE-2023-32568

An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not val…

Fix: 7.4.2.800 / 8.0.410+
Fix from $1,950 2023-05-10
Scalance Lpe9403 Firmware CRITICAL 9.9
CVE-2023-27407

A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate…

Fix: 2.1+
Fix from $2,300 2023-05-09
Eki 1521 Firmware HIGH 8.8
CVE-2023-2573

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which c…

Fix: after 1.21
Fix from $1,950 2023-05-08
Eki 1521 Firmware HIGH 8.8
CVE-2023-2574

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which …

Fix: after 1.21
Fix from $1,950 2023-05-08
Metersphere CRITICAL 9.8
CVE-2023-29944

Metersphere v1.20.20-lts-79d354a6 is vulnerable to Remote Command Execution. The system command reverse-shell can be executed at the custom code snip…

No fix yet
Fix from $2,300 2023-05-08
Scanservjs CRITICAL 10.0
CVE-2023-2564EPSS 41%

OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.

Fix: 2.27.0+
Fix from $2,300 2023-05-07
A7100ru Firmware CRITICAL 9.8
CVE-2023-30053

TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.

No fix yet
Fix from $2,300 2023-05-05
A7100ru Firmware CRITICAL 9.8
CVE-2023-30054

TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially construc…

No fix yet
Fix from $2,300 2023-05-05
X5000r Firmware CRITICAL 9.8
CVE-2023-30013EPSS 26%

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnera…

No fix yet
Fix from $2,300 2023-05-05
Vec40g Firmware HIGH 7.2
CVE-2023-2522EPSS 34%

A vulnerability was found in Chengdu VEC40G 3.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

No fix yet
Fix from $1,950 2023-05-04
3957 Vec Firmware HIGH 8.8
CVE-2023-24958

A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow an authenticated user to submi…

Fix: 8.51.2.12 / 8.52.102.13+
Fix from $1,950 2023-05-04
Fortiadc HIGH 7.8
CVE-2023-27999

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 through 7.1.1 may allow an authe…

Fix: 7.1.2+
Fix from $1,950 2023-05-03
Opentsdb CRITICAL 9.8
CVE-2023-25826EPSS 36%

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple paramete…

Fix: after 2.4.1
Fix from $2,300 2023-05-03
Big Ip Domain Name System HIGH 8.8
CVE-2023-28742

When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note: Software versions which have r…

Fix: 14.1.5.4 / 15.1.8.2+
Fix from $1,950 2023-05-03
Gl Mt3000 Firmware CRITICAL 9.8
CVE-2023-29778EPSS 16%

GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.

Mitigation only
Fix from $2,300 2023-05-02
Appium Desktop CRITICAL 9.8
CVE-2023-2479EPSS 22%

OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4.

Fix: 1.22.3-4+
Fix from $2,300 2023-05-02
Nbg6604 Firmware HIGH 8.8
CVE-2023-22919

The post-authentication command injection vulnerability in the Zyxel NBG6604 firmware version V1.01(ABIR.0)C0 could allow an authenticated attacker t…

Patch available
Fix from $1,950 2023-05-01
Avideo HIGH 8.8
CVE-2023-30854EPSS 5%

AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite…

Fix: 12.4+
Fix from $1,950 2023-04-28
Vios HIGH 7.8
CVE-2023-28528

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary c…

Patch available
Fix from $1,950 2023-04-28
Mypro HIGH 8.8
CVE-2023-29150

mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.

Fix: after 8.26.0
Fix from $1,950 2023-04-27
Mypro HIGH 8.8
CVE-2023-29169

mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.

Fix: after 8.26.0
Fix from $1,950 2023-04-27
Mypro HIGH 8.8
CVE-2023-28384EPSS 45%

mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.

Fix: after 8.26.0
Fix from $1,950 2023-04-27