Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Powerstation Firmware HIGH 8.8
CVE-2023-24837

HGiga PowerStation remote management function has insufficient filtering for user input. An authenticated remote attacker with general user privilege…

Mitigation only
Fix from $1,950 2023-03-27
Pull It CRITICAL 9.8
CVE-2018-25083

The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.

Fix: 1.4.0+
Fix from $2,300 2023-03-27
Cp900 Firmware CRITICAL 9.8
CVE-2022-28495

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWl…

No fix yet
Fix from $2,300 2023-03-24
Wireless Lan Controller Software MEDIUM 5.5
CVE-2023-20056

A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (…

Fix: 8.10.183.0 / 16.12.8+
Fix from $1,600 2023-03-23
Ios Xe MEDIUM 6.8
CVE-2023-20082

A vulnerability in Cisco IOS XE Software for Cisco Catalyst 9300 Series Switches could allow an authenticated, local attacker with level-15 privilege…

Fix: 17.3.7 / 17.6.5+
Fix from $1,600 2023-03-23
Cp900 Firmware CRITICAL 9.8
CVE-2022-28491

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter…

No fix yet
Fix from $2,300 2023-03-23
Cp900 Firmware CRITICAL 9.8
CVE-2022-28494

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgradeFW function via the filena…

No fix yet
Fix from $2,300 2023-03-23
Rbs750 Firmware HIGH 8.8
CVE-2022-37337

A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTP request …

No fix yet
Fix from $1,950 2023-03-21
Org Mode HIGH 7.8
CVE-2023-28617

org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or dire…

Fix: after 9.6.1
Fix from $1,950 2023-03-19
Dir 820l Firmware CRITICAL 9.8
CVE-2023-25280 KEVEPSS 98%

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_a…

Mitigation only
Fix from $2,300 2023-03-16
Vigor2960 Firmware HIGH 7.8
CVE-2023-24229EPSS 7%

DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands v…

No fix yet
Fix from $1,950 2023-03-15
Energy Communication Unit Firmware CRITICAL 9.8
CVE-2023-28343EPSS 85%

OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone param…

No fix yet
Fix from $2,300 2023-03-14
Business Objects Business Intelligence Platform HIGH 8.8
CVE-2023-25617

SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution …

Mitigation only
Fix from $1,950 2023-03-14
Dir 820l Firmware CRITICAL 9.8
CVE-2023-25279EPSS 31%

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.

No fix yet
Fix from $2,300 2023-03-13
Dir 867 Firmware CRITICAL 9.8
CVE-2023-24762

OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress pa…

Mitigation only
Fix from $2,300 2023-03-13
Liferea CRITICAL 9.8
CVE-2023-1350

A vulnerability was found in liferea. It has been rated as critical. Affected by this issue is the function update_job_run of the file src/update.c o…

Fix: 1.14.1+
Fix from $2,300 2023-03-11
Emacs HIGH 7.8
CVE-2023-27985

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack …

Fix: after 28.2
Fix from $1,950 2023-03-09
Kylin System Updater HIGH 7.8
CVE-2023-1277

A vulnerability, which was classified as critical, was found in kylin-system-updater up to 1.4.20kord on Ubuntu Kylin. Affected is the function Insta…

Fix: after 1.4.20kord
Fix from $1,950 2023-03-08
A7100ru Firmware CRITICAL 9.8
CVE-2023-25395

TOTOlink A7100RU V7.4cu.2313_B20191024 router was discovered to contain a command injection vulnerability via the ou parameter at /setting/delStaticD…

No fix yet
Fix from $2,300 2023-03-08
Fortiweb HIGH 8.8
CVE-2022-39951

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiW…

Fix: after 7.0.2
Fix from $1,950 2023-03-07
Mailcow\ HIGH 8.8
CVE-2023-26490

mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - which can be made available to …

Fix: 2023-03+
Fix from $1,950 2023-03-04
T100b Firmware HIGH 7.2
CVE-2023-26213EPSS 8%

On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /aj…

No fix yet
Fix from $1,950 2023-03-03
Email Security Appliance MEDIUM 6.7
CVE-2023-20075

Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerab…

Fix: 12.5.3-041 / 13.0.5-007+
Fix from $1,600 2023-03-01
Erp HIGH 8.8
CVE-2023-26759

Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an OS command injection vulnerability via calls made to the XMService component.

No fix yet
Fix from $1,950 2023-02-27
Gogs CRITICAL 9.8
CVE-2022-2024EPSS 98%

OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.

Fix: 0.12.11+
Fix from $2,300 2023-02-25
Zoneminder HIGH 8.8
CVE-2023-26039

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …

Fix: 1.36.33 / 1.37.33+
Fix from $1,950 2023-02-25
Pdf Info CRITICAL 9.8
CVE-2022-36231

pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.

Patch available
Fix from $2,300 2023-02-23
Ucs Central Software MEDIUM 6.7
CVE-2023-20015

A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series …

Fix: 4.0 / 4.1+
Fix from $1,600 2023-02-23
Nx Os HIGH 7.8
CVE-2023-20050

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…

Fix: 8.2 / 9.3+
Fix from $1,950 2023-02-23
Dolphinphp CRITICAL 9.8
CVE-2023-0935

A vulnerability was found in DolphinPHP up to 1.5.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Fix: after 1.5.1
Fix from $2,300 2023-02-21