Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 7.2
CVE-2024-54082

home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore function. An arbitrary OS command ma…

Mitigation only
Fix from $1,950 2024-12-23
Unclassified HIGH 7.8
CVE-2020-13712

A command injection is possible through the user interface, allowing arbitrary command execution as the root user. oMG2000 running MGOS 3.15.1 or ea…

Mitigation only
Fix from $1,950 2024-12-20
Security Directory Integrator HIGH 8.8
CVE-2024-28767

IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary c…

Fix: after 10.0.3
Fix from $1,950 2024-12-20
Ng Firewall HIGH 8.8
CVE-2024-12829

Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit…

Mitigation only
Fix from $1,950 2024-12-20
Fortiwan HIGH 7.8
CVE-2021-26115

An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unpriv…

Fix: 4.5.8+
Fix from $1,950 2024-12-19
Qufirewall HIGH 7.2
CVE-2023-23356

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow rem…

Fix: 2.3.3+
Fix from $1,950 2024-12-19
Privileged Remote Access HIGH 7.2
CVE-2024-12686 KEVEPSS 14%

A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrativ…

Fix: after 24.3.1
Fix from $1,950 2024-12-18
Fortimanager HIGH 7.2
CVE-2024-48889

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, v…

Fix: 6.4.15 / 7.0.13+
Fix from $1,950 2024-12-18
Unclassified HIGH 7.2
CVE-2024-53688

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in AE1021 firmware versions 2.0.10 and earlie…

Mitigation only
Fix from $1,950 2024-12-18
Rizin CRITICAL 9.1
CVE-2024-31668

rizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set function in librz/analysis/meta.

Fix: 0.6.3+
Fix from $2,300 2024-12-17
Cyberpanel HIGH 8.8
CVE-2024-53376EPSS 11%

CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the web…

Fix: 2.3.8+
Fix from $1,950 2024-12-16
Radare2 HIGH 7.8
CVE-2024-11858

A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Applicatio…

Fix: after 5.9.8
Fix from $1,950 2024-12-15
Recoverpoint For Virtual Machines MEDIUM 6.5
CVE-2024-48008

Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially explo…

Mitigation only
Fix from $1,600 2024-12-13
Recoverpoint For Virtual Machines HIGH 8.8
CVE-2024-22461

Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially explo…

Mitigation only
Fix from $1,950 2024-12-13
Connext Professional HIGH 7.8
CVE-2024-52058

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in RTI Connext Professional (System Designer…

Fix: 6.1.2.19 / 7.3.0.2+
Fix from $1,950 2024-12-13
Unclassified HIGH 7.2
CVE-2024-54008

An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a rem…

Mitigation only
Fix from $1,950 2024-12-10
Unclassified HIGH 7.3
CVE-2024-28138

An unauthenticated attacker with network access to the affected device's web interface can execute any system command via the "msg_events.php" script…

Mitigation only
Fix from $1,950 2024-12-10
Datax Web HIGH 8.8
CVE-2024-12358

A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. …

No fix yet
Fix from $1,950 2024-12-09
Vios HIGH 7.8
CVE-2024-47115

IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.

Mitigation only
Fix from $1,950 2024-12-07
Unclassified CRITICAL 9.8
CVE-2024-52320

The affected product is vulnerable to a command injection. An unauthenticated attacker could send commands through a malicious HTTP request which cou…

Mitigation only
Fix from $2,300 2024-12-06
Hybrid Backup Sync CRITICAL 9.8
CVE-2024-50388

An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attack…

Mitigation only
Fix from $2,300 2024-12-06
Qts CRITICAL 9.8
CVE-2024-50393

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow rem…

Mitigation only
Fix from $2,300 2024-12-06
License Center CRITICAL 9.8
CVE-2024-48863

A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute…

Fix: 1.9.43+
Fix from $2,300 2024-12-06
Unclassified HIGH 7.2
CVE-2024-47133

UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administrative accou…

Mitigation only
Fix from $1,950 2024-12-05
App Connect Enterprise Certified Container HIGH 8.8
CVE-2024-51465

IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authenticated attacker to execute ar…

Fix: 12.4+
Fix from $1,950 2024-12-04
Emg6726 B10a Firmware HIGH 7.2
CVE-2024-9200

A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions thro…

Fix: 5.13 / 5.15+
Fix from $1,950 2024-12-03
Unclassified HIGH 8.0
CVE-2024-53375EPSS 41%

An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exists in the "tmp_get_sites" fu…

Mitigation only
Fix from $1,950 2024-12-02
Unclassified HIGH 8.8
CVE-2024-53939

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq…

Mitigation only
Fix from $1,950 2024-12-02
Unclassified HIGH 8.8
CVE-2024-53940

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /cgi-bin/luci/admin endpoints …

Mitigation only
Fix from $1,950 2024-12-02
Unclassified HIGH 8.8
CVE-2024-53992

unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malicious commands that are execut…

Patch available
Fix from $1,950 2024-12-02