Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Mypro HIGH 8.8
CVE-2023-28400EPSS 25%

mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.

Fix: after 8.26.0
Fix from $1,950 2023-04-27
Mypro HIGH 8.8
CVE-2023-28716

mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.

Fix: after 8.26.0
Fix from $1,950 2023-04-27
Avideo CRITICAL 9.8
CVE-2023-25313

OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link …

Fix: 12.4+
Fix from $2,300 2023-04-25
Atp100 Firmware CRITICAL 9.8
CVE-2023-28771 KEVEPSS 99%

Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG F…

Fix: 5.35 / 5.36+
Fix from $2,300 2023-04-25
Kiwi Tcms HIGH 8.8
CVE-2023-30628

Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and prior, the `changelog.yml` wor…

Fix: after 12.2
Fix from $1,950 2023-04-24
Atp200 Firmware HIGH 8.8
CVE-2023-27991

The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series f…

Fix: 5.36+
Fix from $1,950 2023-04-24
Bmc HIGH 8.8
CVE-2023-25507

NVIDIA DGX-1 BMC contains a vulnerability in the SPX REST API, where an attacker with the appropriate level of authorization can inject arbitrary she…

Fix: 3.39.30+
Fix from $1,950 2023-04-22
Gipsy CRITICAL 9.8
CVE-2023-30621

Gipsy is a multi-purpose discord bot which aim to be as modular and user-friendly as possible. In versions prior to 1.3 users can run command on the …

Fix: after 1.3
Fix from $2,300 2023-04-21
Me Rtu Firmware CRITICAL 9.8
CVE-2023-2131

Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary co…

Fix: 3.36+
Fix from $2,300 2023-04-20
Tripleplay MEDIUM 5.4
CVE-2023-25759

OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to run unprivil…

Mitigation only
Fix from $1,600 2023-04-19
Apc Easy Ups Online Monitoring Software CRITICAL 9.8
CVE-2023-29412

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code …

Fix: after 2.5-gs-01-22320
Fix from $2,300 2023-04-18
Struxureware Data Center Expert HIGH 7.8
CVE-2023-25554

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privile…

Fix: after 7.9.2
Fix from $1,950 2023-04-18
Struxureware Data Center Expert HIGH 8.1
CVE-2023-25555

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user tha…

Fix: after 7.9.2
Fix from $1,950 2023-04-18
Junos Os Evolved HIGH 8.8
CVE-2023-28983

An OS Command Injection vulnerability in gRPC Network Operations Interface (gNOI) server module of Juniper Networks Junos OS Evolved allows an authen…

Mitigation only
Fix from $1,950 2023-04-17
Liferay Portal CRITICAL 9.8
CVE-2021-33990EPSS 12%

Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue b…

No fix yet
Fix from $2,300 2023-04-16
E8450 Firmware HIGH 8.8
CVE-2022-38841EPSS 11%

Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.

No fix yet
Fix from $1,950 2023-04-16
Youker Assistant HIGH 7.8
CVE-2023-2091

A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerability is the function adjust_cpuf…

Fix: 3.1.4.13+
Fix from $1,950 2023-04-15
Wfs Sr03w Firmware HIGH 8.8
CVE-2023-29804EPSS 17%

WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.

No fix yet
Fix from $1,950 2023-04-14
Wfs Sr03w Firmware CRITICAL 9.8
CVE-2023-29805

WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.

No fix yet
Fix from $2,300 2023-04-14
Dsl 3782 Firmware HIGH 8.8
CVE-2023-27216

An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page.

Mitigation only
Fix from $1,950 2023-04-12
Swc 5100w Firmware HIGH 8.8
CVE-2023-27826EPSS 12%

SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attacker…

No fix yet
Fix from $1,950 2023-04-12
Fortiadc HIGH 7.8
CVE-2022-40679

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all v…

Fix: 5.7.0 / 6.1.5+
Fix from $1,950 2023-04-11
Fortiadc HIGH 7.8
CVE-2022-43948

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.3, FortiA…

Fix: 6.2.6 / 7.0.4+
Fix from $1,950 2023-04-11
Cps Mg341 Adsc1 111 Firmware HIGH 8.8
CVE-2023-27917

OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenance page t…

Fix: after 3.7.10
Fix from $1,950 2023-04-11
G103 Firmware CRITICAL 9.8
CVE-2023-27076EPSS 23%

Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter.

No fix yet
Fix from $2,300 2023-04-10
Identity Services Engine MEDIUM 6.7
CVE-2023-20153

Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform comman…

Mitigation only
Fix from $1,600 2023-04-05
Evolved Programmable Network Manager MEDIUM 6.7
CVE-2023-20121

Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisc…

Fix: 3.10.4 / 7.0.1+
Fix from $1,600 2023-04-05
Identity Services Engine HIGH 7.8
CVE-2023-20122

Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisc…

Mitigation only
Fix from $1,950 2023-04-05
Rv320 Firmware HIGH 7.2
CVE-2023-20117EPSS 28%

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an au…

Mitigation only
Fix from $1,950 2023-04-05
Identity Services Engine MEDIUM 6.7
CVE-2023-20152

Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform comman…

Mitigation only
Fix from $1,600 2023-04-05