Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50359

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Virtualenv HIGH 7.8
CVE-2024-53899

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted co…

Fix: 20.26.6+
Fix from $1,950 2024-11-24
Unclassified CRITICAL 10.0
CVE-2024-47407EPSS 64%

A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to …

Mitigation only
Fix from $2,300 2024-11-22
Unclassified CRITICAL 10.0
CVE-2024-52034

An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacke…

Mitigation only
Fix from $2,300 2024-11-22
Infotainment MEDIUM 6.8
CVE-2024-8358

Visteon Infotainment UPDATES_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attacker…

Mitigation only
Fix from $1,600 2024-11-22
Infotainment MEDIUM 6.8
CVE-2024-8359

Visteon Infotainment REFLASH_DDU_FindFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attacke…

Mitigation only
Fix from $1,600 2024-11-22
Infotainment MEDIUM 6.8
CVE-2024-8360

Visteon Infotainment REFLASH_DDU_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present atta…

Mitigation only
Fix from $1,600 2024-11-22
Vns3 HIGH 8.8
CVE-2024-8809

Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

Fix: 6.2.8 / 6.6.7+
Fix from $1,950 2024-11-22
Vns3 CRITICAL 9.8
CVE-2024-8806

Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

Fix: 6.2.8 / 6.6.7+
Fix from $2,300 2024-11-22
Vns3 CRITICAL 9.8
CVE-2024-8807

Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

Fix: 6.2.8 / 6.6.7+
Fix from $2,300 2024-11-22
Vns3 HIGH 8.8
CVE-2024-8808

Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

Fix: 6.2.8 / 6.6.7+
Fix from $1,950 2024-11-22
Cam V3 Firmware MEDIUM 6.8
CVE-2024-6247

Wyze Cam v3 Wi-Fi SSID OS Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute ar…

Fix: 4.36.11.8391+
Fix from $1,600 2024-11-22
Unified Secops Platform HIGH 8.8
CVE-2024-5717

Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Fix: 6.4.8+
Fix from $1,950 2024-11-22
Unified Secops Platform HIGH 8.8
CVE-2024-5719

Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Fix: 6.4.8+
Fix from $1,950 2024-11-22
Unified Secops Platform HIGH 8.8
CVE-2024-5720

Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Fix: 6.4.8+
Fix from $1,950 2024-11-22
X6000r Firmware CRITICAL 9.8
CVE-2024-52723

In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can a…

Mitigation only
Fix from $2,300 2024-11-22
Qurouter CRITICAL 9.8
CVE-2024-48860

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attack…

Mitigation only
Fix from $2,300 2024-11-22
Qurouter HIGH 7.8
CVE-2024-48861

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network…

Mitigation only
Fix from $1,950 2024-11-22
Notes Station 3 HIGH 8.8
CVE-2024-38644

An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated a…

Fix: 3.9.7+
Fix from $1,950 2024-11-22
Imanager CRITICAL 9.8
CVE-2023-24467

Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.

Fix: 3.2.6+
Fix from $2,300 2024-11-22
Unclassified HIGH 8.0
CVE-2024-31408

OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS …

Mitigation only
Fix from $1,950 2024-11-22
Llama Factory CRITICAL 9.8
CVE-2024-52803

LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Fac…

Fix: 0.9.1+
Fix from $2,300 2024-11-21
Gocast CRITICAL 9.8
CVE-2024-28892EPSS 6%

An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command ex…

Mitigation only
Fix from $2,300 2024-11-21
Gocast CRITICAL 9.8
CVE-2024-29224EPSS 6%

An OS command injection vulnerability exists in the NAT parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command exe…

Mitigation only
Fix from $2,300 2024-11-21
Mc Lr Router Firmware HIGH 7.2
CVE-2024-28025EPSS 8%

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A speci…

No fix yet
Fix from $1,950 2024-11-21
Mc Lr Router Firmware HIGH 7.2
CVE-2024-28026EPSS 6%

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A speci…

No fix yet
Fix from $1,950 2024-11-21
Mc Lr Router Firmware HIGH 7.2
CVE-2024-28027EPSS 8%

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A speci…

No fix yet
Fix from $1,950 2024-11-21
Mc Lr Router Firmware HIGH 7.2
CVE-2024-21786EPSS 11%

An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies MC LR Router 2.10.5. A specia…

No fix yet
Fix from $1,950 2024-11-21
Fabric Operating System HIGH 7.8
CVE-2024-7517

A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenti…

Fix: after 9.2.1a
Fix from $1,950 2024-11-21
Di 8200 Firmware CRITICAL 9.8
CVE-2024-51151EPSS 30%

D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter.

No fix yet
Fix from $2,300 2024-11-21