Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Security Verify Access HIGH 8.8
CVE-2024-49803

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitrary commands on the system by…

Fix: after 10.0.8
Fix from $1,950 2024-11-29
Enterprise Security Manager CRITICAL 9.8
CVE-2024-11482

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command inject…

No fix yet
Fix from $2,300 2024-11-29
Unclassified HIGH 7.2
CVE-2024-11983

Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to…

Mitigation only
Fix from $1,950 2024-11-29
Logo Slider MEDIUM 5.4
CVE-2024-10896

The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and Slider settings, which could allow high privilege us…

Fix: 4.5.0+
Fix from $1,600 2024-11-28
Unclassified MEDIUM 6.8
CVE-2024-51228

An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and T…

Mitigation only
Fix from $1,600 2024-11-27
Ews356 Fir Firmware HIGH 8.0
CVE-2024-31976

EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity parameter.

Fix: after 1.1.30
Fix from $1,950 2024-11-27
Total Upkeep HIGH 7.2
CVE-2024-9461

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all vers…

Fix: 1.16.7+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware MEDIUM 5.2
CVE-2024-50376

A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufa…

Fix: 1.2.2 / 1.6.5+
Fix from $1,600 2024-11-26
Eki 6333ac 2g Firmware MEDIUM 6.5
CVE-2024-50377

A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-633…

Fix: 1.2.2 / 1.6.5+
Fix from $1,600 2024-11-26
Eki 6333ac 2g Firmware CRITICAL 9.8
CVE-2024-50374

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $2,300 2024-11-26
Eki 6333ac 2g Firmware CRITICAL 9.8
CVE-2024-50375

A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= …

Fix: 1.2.2 / 1.6.5+
Fix from $2,300 2024-11-26
Eki 6333ac 2g Firmware CRITICAL 9.8
CVE-2024-50371

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $2,300 2024-11-26
Eki 6333ac 2g Firmware CRITICAL 9.8
CVE-2024-50372

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $2,300 2024-11-26
Eki 6333ac 2g Firmware CRITICAL 9.8
CVE-2024-50373

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $2,300 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50369

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware CRITICAL 9.8
CVE-2024-50370

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $2,300 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50367

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50368

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50365

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50366

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50362

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50363

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50364

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50360

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50361

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50359

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Virtualenv HIGH 7.8
CVE-2024-53899

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted co…

Fix: 20.26.6+
Fix from $1,950 2024-11-24
Unclassified CRITICAL 10.0
CVE-2024-47407EPSS 64%

A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to …

Mitigation only
Fix from $2,300 2024-11-22
Unclassified CRITICAL 10.0
CVE-2024-52034

An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacke…

Mitigation only
Fix from $2,300 2024-11-22
Infotainment MEDIUM 6.8
CVE-2024-8358

Visteon Infotainment UPDATES_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attacker…

Mitigation only
Fix from $1,600 2024-11-22