Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Devops Deploy HIGH 7.2
CVE-2024-55904

IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, a…

Fix: 7.0.5.26 / 7.1.2.22+
Fix from $1,950 2025-02-14
Mypro CRITICAL 9.8
CVE-2025-25067

mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.

Fix: 1.4+
Fix from $2,300 2025-02-13
Unclassified MEDIUM 6.3
CVE-2025-1229

A vulnerability classified as critical was found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378ddd6. Affected by this vulnerability …

Mitigation only
Fix from $1,600 2025-02-12
Unclassified HIGH 8.6
CVE-2025-0110

A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an authenticated administrator with the ability to make …

Mitigation only
Fix from $1,950 2025-02-12
Unclassified HIGH 8.8
CVE-2025-1244

A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on…

Mitigation only
Fix from $1,950 2025-02-12
Fortiweb HIGH 7.2
CVE-2024-50569

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 through 7.6.0 allows attacker…

Fix: 7.4.6+
Fix from $1,950 2025-02-11
Fortimanager Cloud HIGH 7.2
CVE-2024-40584

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer versio…

Fix: 7.2.6 / 7.2.8+
Fix from $1,950 2025-02-11
Fortiweb HIGH 7.2
CVE-2024-50567

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0 through 7.6.0 allows attacke…

Fix: 7.4.6+
Fix from $1,950 2025-02-11
Cloud Services Appliance HIGH 7.2
CVE-2024-47908EPSS 22%

OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achi…

Fix: 5.0.5+
Fix from $1,950 2025-02-11
Unclassified HIGH 8.3
CVE-2024-8684

OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated…

Mitigation only
Fix from $1,950 2025-02-10
Unclassified HIGH 7.5
CVE-2025-24366

SFTPGo is an open source, event-driven file transfer solution. SFTPGo supports execution of a defined set of commands via SSH. Besides a set of defau…

Patch available
Fix from $1,950 2025-02-07
Tl Wpa8630 Firmware HIGH 8.0
CVE-2024-57357EPSS 5%

An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to execute arbitrary code via function sub_4256CC, whi…

Mitigation only
Fix from $1,950 2025-02-07
Security Verify Directory HIGH 8.8
CVE-2024-51450

IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sendin…

Fix: after 10.0.3
Fix from $1,950 2025-02-06
Big Ip Access Policy Manager HIGH 8.8
CVE-2025-20029EPSS 7%

Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execu…

Fix: 15.1.10.6 / 16.1.5.2+
Fix from $1,950 2025-02-05
Multi Tenant Loadmaster MEDIUM 6.8
CVE-2024-56132EPSS 6%

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product …

Fix: 7.1.35.13 / 7.2.54.13+
Fix from $1,600 2025-02-05
Unclassified CRITICAL 9.5
CVE-2025-24971

DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Command Injection vulnerability…

Patch available
Fix from $2,300 2025-02-04
Clearpass Policy Manager HIGH 8.8
CVE-2025-25039

A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to ru…

Fix: 6.11.10 / 6.12.4+
Fix from $1,950 2025-02-04
Unclassified HIGH 7.2
CVE-2024-23690

The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interface. An authenticated and remot…

Mitigation only
Fix from $1,950 2025-02-04
Vmg1312 B10a Firmware HIGH 8.8
CVE-2024-40890 KEVEPSS 22%

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmw…

Mitigation only
Fix from $1,950 2025-02-04
Vmg1312 B10a Firmware HIGH 8.8
CVE-2024-40891 KEVEPSS 22%

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B1…

Mitigation only
Fix from $1,950 2025-02-04
Openpanel CRITICAL 9.8
CVE-2024-53584

OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.

No fix yet
Fix from $2,300 2025-01-31
Unclassified CRITICAL 9.8
CVE-2025-0680

Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arb…

No fix yet
Fix from $2,300 2025-01-30
Unclassified CRITICAL 9.8
CVE-2025-20014

mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by a…

Mitigation only
Fix from $2,300 2025-01-29
Unclassified CRITICAL 9.8
CVE-2025-20061

mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an …

Mitigation only
Fix from $2,300 2025-01-29
Escan Anti Virus HIGH 8.1
CVE-2025-0798EPSS 7%

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of…

No fix yet
Fix from $1,950 2025-01-29
Unclassified CRITICAL 9.3
CVE-2025-24480

A Remote Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to lack of input sanitation and could …

No fix yet
Fix from $2,300 2025-01-28
Cacti HIGH 7.2
CVE-2025-22604EPSS 5%

Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject ma…

Fix: 1.2.29+
Fix from $1,950 2025-01-27
Unclassified CRITICAL 9.8
CVE-2024-57595

DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to …

Mitigation only
Fix from $2,300 2025-01-27
Coolify HIGH 7.8
CVE-2025-22606

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In version 4.0.0-beta.358 and possibly earlier ve…

No fix yet
Fix from $1,950 2025-01-24
Coolify HIGH 7.8
CVE-2025-22605

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Starting in version 4.0.0-beta.18 and prior to 4.…

Patch available
Fix from $1,950 2025-01-24