Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 8.8
CVE-2024-48895

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware version V1.3.18 …

Mitigation only
Fix from $1,950 2024-11-20
Deep Security Agent HIGH 8.8
CVE-2024-51503

A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges…

Mitigation only
Fix from $1,950 2024-11-19
Debian Linux HIGH 7.8
CVE-2024-10224EPSS 9%

Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute …

Fix: 1.36+
Fix from $1,950 2024-11-19
Needrestart HIGH 7.8
CVE-2024-11003EPSS 11%

Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input. This could…

Fix: 3.8+
Fix from $1,950 2024-11-19
Unclassified HIGH 8.8
CVE-2024-52587

StepSecurity's Harden-Runner provides network egress filtering and runtime security for GitHub-hosted and self-hosted runners. Versions of step-secur…

Patch available
Fix from $1,950 2024-11-18
Pan Os HIGH 7.2
CVE-2024-9474 KEVEPSS 95%

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface …

Fix: 10.1.14 / 10.2.12+
Fix from $1,950 2024-11-18
Nus M9 Erp HIGH 7.5
CVE-2024-44759

An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arb…

Mitigation only
Fix from $1,950 2024-11-15
Unclassified HIGH 7.5
CVE-2024-24426

Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cau…

Mitigation only
Fix from $1,950 2024-11-15
Open5gs HIGH 7.5
CVE-2024-24431

A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS pack…

No fix yet
Fix from $1,950 2024-11-15
Industrial Network Director CRITICAL 9.9
CVE-2023-20036EPSS 13%

A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges…

Fix: 1.11.3+
Fix from $2,300 2024-11-15
Asyncos HIGH 8.8
CVE-2022-20871

A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance…

Mitigation only
Fix from $1,950 2024-11-15
Unclassified MEDIUM 6.5
CVE-2022-20652

A vulnerability in the web-based management interface and in the API subsystem of Cisco Tetration could allow an authenticated, remote attacker …

Mitigation only
Fix from $1,600 2024-11-15
Unclassified HIGH 8.8
CVE-2022-20655

A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command …

Mitigation only
Fix from $1,950 2024-11-15
Photos CRITICAL 9.8
CVE-2024-10443EPSS 28%

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePho…

Fix: 1.0.2-10026 / 1.1.0-10053+
Fix from $2,300 2024-11-15
Gogs CRITICAL 9.8
CVE-2022-1884

A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to imp…

Fix: after 0.12.7
Fix from $2,300 2024-11-15
Gv Vs12 Firmware CRITICAL 9.8
CVE-2024-11120 KEVEPSS 29%

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject a…

Mitigation only
Fix from $2,300 2024-11-15
Privategpt CRITICAL 9.8
CVE-2024-4343

A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/components/llm/custom/sagemak…

Fix: 0.6.0+
Fix from $2,300 2024-11-14
G3 Firmware HIGH 8.8
CVE-2024-50852

Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.

No fix yet
Fix from $1,950 2024-11-13
G3 Firmware HIGH 8.8
CVE-2024-50853

Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.

No fix yet
Fix from $1,950 2024-11-13
Fortianalyzer MEDIUM 6.7
CVE-2024-32118

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager…

Fix: 7.2.6 / 7.2.8+
Fix from $1,600 2024-11-12
Unclassified HIGH 8.6
CVE-2024-52010

Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. A command injection vulnerability in the Web SSH feature allows an authenticated …

Patch available
Fix from $1,950 2024-11-12
Connect Secure HIGH 7.2
CVE-2024-11005

Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap…

Fix: 9.1 / 22.7+
Fix from $1,950 2024-11-12
Connect Secure HIGH 7.2
CVE-2024-11006

Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap…

Fix: 9.1 / 22.7+
Fix from $1,950 2024-11-12
Connect Secure HIGH 7.2
CVE-2024-11007

Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap…

Fix: 22.7+
Fix from $1,950 2024-11-12
Sinec Ins CRITICAL 9.1
CVE-2024-46890

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent t…

Fix: 1.0+
Fix from $2,300 2024-11-12
Unclassified HIGH 8.0
CVE-2024-45827

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Mesh Wi-Fi router RP562B firmware version …

Mitigation only
Fix from $1,950 2024-11-12
Gs1900 8 Firmware MEDIUM 6.8
CVE-2024-8881

A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier c…

Fix: 2.90+
Fix from $1,600 2024-11-12
Ews356 Fit Firmware CRITICAL 9.8
CVE-2024-36061

EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metac…

Fix: after 1.1.30
Fix from $2,300 2024-11-11
Dsl6740c Firmware HIGH 7.2
CVE-2024-11065

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute ar…

Mitigation only
Fix from $1,950 2024-11-11
Dsl6740c Firmware HIGH 7.2
CVE-2024-11066

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute ar…

Mitigation only
Fix from $1,950 2024-11-11