Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 7.2
CVE-2025-20617

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlie…

Mitigation only
Fix from $1,950 2025-01-22
Unclassified MEDIUM 6.6
CVE-2025-23237

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlie…

Mitigation only
Fix from $1,600 2025-01-22
Magma HIGH 7.5
CVE-2023-37032

A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fe…

Fix: after 1.8.0
Fix from $1,950 2025-01-21
E8450 Firmware HIGH 8.8
CVE-2024-57542

Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_btn.

No fix yet
Fix from $1,950 2025-01-21
Ac8 Firmware HIGH 7.2
CVE-2025-0528EPSS 6%

A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown fun…

No fix yet
Fix from $1,950 2025-01-17
Unclassified CRITICAL 9.3
CVE-2024-13502

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDirect NTC2218, NTC2250, NTC2299 …

Mitigation only
Fix from $2,300 2025-01-17
Unclassified HIGH 8.8
CVE-2025-0457

The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and exe…

Mitigation only
Fix from $1,950 2025-01-16
X5000r Firmware HIGH 8.8
CVE-2024-57022

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in setWiFiScheduleC…

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware MEDIUM 6.8
CVE-2024-57023

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCf…

No fix yet
Fix from $1,600 2025-01-15
X5000r Firmware MEDIUM 6.8
CVE-2024-57024

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiSchedul…

No fix yet
Fix from $1,600 2025-01-15
X5000r Firmware MEDIUM 6.8
CVE-2024-57025

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCf…

No fix yet
Fix from $1,600 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57011

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57012

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setScheduleCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57013

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setScheduleCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57014

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScheduleCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57015

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57016

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in setVpnAccountCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57017

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57018

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAccountCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57019

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAccountCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57020

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute" parameter in setWiFiSchedul…

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57021

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleC…

No fix yet
Fix from $1,950 2025-01-15
Unclassified HIGH 7.2
CVE-2025-0356

NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arbitrary OS commands via the ne…

Mitigation only
Fix from $1,950 2025-01-15
Fortimail MEDIUM 6.7
CVE-2024-56497

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and …

Fix: 6.4.5 / 6.4.8+
Fix from $1,600 2025-01-14
Fortisoar Imap Connector HIGH 8.8
CVE-2024-48890

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector vers…

Fix: 3.5.8+
Fix from $1,950 2025-01-14
Fortimanager HIGH 8.8
CVE-2024-50566

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 throu…

Fix: 7.2.8 / 7.2.9+
Fix from $1,950 2025-01-14
Fortivoice MEDIUM 6.7
CVE-2024-40587

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7…

Fix: 6.4.10 / 7.0.5+
Fix from $1,600 2025-01-14
Fortisandbox HIGH 8.8
CVE-2024-27778

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.…

Fix: 4.0.5 / 4.2.7+
Fix from $1,950 2025-01-14
Fortiap HIGH 7.8
CVE-2024-26012

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 throug…

Fix: 6.4.10 / 7.2.4+
Fix from $1,950 2025-01-14
Fortiswitch HIGH 7.8
CVE-2023-37937

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through…

Fix: 6.2.8 / 6.4.14+
Fix from $1,950 2025-01-14