Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 7.2
CVE-2025-20016

OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporation. A user with an administra…

Mitigation only
Fix from $1,950 2025-01-14
Unclassified CRITICAL 9.8
CVE-2025-20055

OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340 provided by Y'S corporation. An attacker who can access the…

Mitigation only
Fix from $2,300 2025-01-14
Expedition CRITICAL 9.8
CVE-2025-0107EPSS 79%

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-da…

Fix: 1.2.101+
Fix from $2,300 2025-01-11
Dgn1000 Firmware CRITICAL 9.8
CVE-2024-12847EPSS 30%

NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary…

Fix: 1.1.00.48+
Fix from $2,300 2025-01-10
Land Record System CRITICAL 9.8
CVE-2024-57687

An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote atta…

No fix yet
Fix from $2,300 2025-01-10
Unclassified HIGH 8.8
CVE-2024-43654

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware for AC models allows OS Comm…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified CRITICAL 9.3
CVE-2024-43655

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue aff…

Mitigation only
Fix from $2,300 2025-01-09
Unclassified HIGH 8.8
CVE-2024-43656

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue aff…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified HIGH 8.8
CVE-2024-43657

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue aff…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified HIGH 8.8
CVE-2024-43649

Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root user. This issue affects Ioch…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified CRITICAL 9.3
CVE-2024-43650

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware for AC models allows OS Comma…

Mitigation only
Fix from $2,300 2025-01-09
Unclassified CRITICAL 9.3
CVE-2024-43651

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affe…

Mitigation only
Fix from $2,300 2025-01-09
Unclassified HIGH 8.8
CVE-2024-43652

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affe…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified HIGH 8.8
CVE-2024-43653

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability  allows OS Command Injection as root This issue aff…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified HIGH 8.8
CVE-2024-43648

Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root user. This issue affects Iochar…

Mitigation only
Fix from $1,950 2025-01-09
Controller CRITICAL 9.8
CVE-2024-50603 KEVEPSS 99%

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used…

Fix: 7.1.4191 / 7.2.4996+
Fix from $2,300 2025-01-08
Macports MEDIUM 6.8
CVE-2024-11681

A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running port selfupdate against the mirr…

Fix: 2.10.5+
Fix from $1,600 2025-01-07
Unclassified HIGH 8.8
CVE-2024-13129EPSS 18%

A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of …

Patch available
Fix from $1,950 2025-01-03
Unclassified CRITICAL 9.8
CVE-2024-9140

Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability …

Mitigation only
Fix from $2,300 2025-01-03
Maxkb HIGH 7.2
CVE-2024-56137

MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large language model and retrieval-…

Fix: 1.9.0+
Fix from $1,950 2025-01-02
Webmin HIGH 8.8
CVE-2024-12828EPSS 33%

Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…

Patch available
Fix from $1,950 2024-12-30
Websphere Automation HIGH 7.2
CVE-2024-54181

IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using sp…

Mitigation only
Fix from $1,950 2024-12-30
Unclassified MEDIUM 6.1
CVE-2024-47918

Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Mitigation only
Fix from $1,600 2024-12-30
Unclassified CRITICAL 9.8
CVE-2024-47919

Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

No fix yet
Fix from $2,300 2024-12-30
Vigor300b Firmware CRITICAL 9.8
CVE-2024-12987 KEVEPSS 98%

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file …

Mitigation only
Fix from $2,300 2024-12-27
F3x36 Firmware HIGH 7.2
CVE-2024-12856EPSS 82%

The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 …

No fix yet
Fix from $1,950 2024-12-27
Vigor300b Firmware CRITICAL 9.8
CVE-2024-12986EPSS 33%

A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown…

Fix: 1.5.1.5+
Fix from $2,300 2024-12-27
Unclassified MEDIUM 6.3
CVE-2024-12985

A vulnerability classified as critical was found in Overtek OT-E801G OTE801G65.1.1.0. This vulnerability affects unknown code of the file /diag_ping.…

Mitigation only
Fix from $1,600 2024-12-27
Unclassified HIGH 7.8
CVE-2024-53256

Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code which suffered a command inje…

Patch available
Fix from $1,950 2024-12-23
Unclassified HIGH 7.2
CVE-2024-45721

home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST name configuration screen. An …

Mitigation only
Fix from $1,950 2024-12-23