Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 8.6
CVE-2023-47105

exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authenticati…

Mitigation only
Fix from $1,950 2024-09-18
Unclassified HIGH 8.8
CVE-2024-43778

OS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attac…

Mitigation only
Fix from $1,950 2024-09-18
Pt30x Sdi Firmware HIGH 7.2
CVE-2024-8957 KEVEPSS 82%

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_a…

Fix: 6.3.40+
Fix from $1,950 2024-09-17
Unclassified CRITICAL 9.9
CVE-2024-45798

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. The `arduino-esp32` CI is vulne…

Mitigation only
Fix from $2,300 2024-09-17
Unclassified HIGH 7.2
CVE-2024-42502

Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in t…

Mitigation only
Fix from $1,950 2024-09-17
Unclassified HIGH 7.2
CVE-2024-42503

Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities res…

Mitigation only
Fix from $1,950 2024-09-17
Proroute H685t W Firmware CRITICAL 9.8
CVE-2024-45682

There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system.

No fix yet
Fix from $2,300 2024-09-17
Dir X4860 Firmware CRITICAL 9.8
CVE-2024-45698

Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use…

Mitigation only
Fix from $2,300 2024-09-16
A720r Firmware HIGH 8.1
CVE-2024-8869

A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os comm…

Mitigation only
Fix from $1,950 2024-09-15
Unclassified HIGH 7.2
CVE-2024-8280

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injec…

Mitigation only
Fix from $1,950 2024-09-13
Unclassified HIGH 7.2
CVE-2024-8281

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injec…

Mitigation only
Fix from $1,950 2024-09-13
Unclassified HIGH 7.2
CVE-2024-8278

A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform comma…

Mitigation only
Fix from $1,950 2024-09-13
Unclassified HIGH 7.2
CVE-2024-8279

A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform comma…

Mitigation only
Fix from $1,950 2024-09-13
Pan Os HIGH 7.2
CVE-2024-8686

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run …

Fix: after 11.2.2
Fix from $1,950 2024-09-11
Ios Xr HIGH 7.2
CVE-2024-20483

Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Soft…

Mitigation only
Fix from $1,950 2024-09-11
Ios Xr HIGH 7.8
CVE-2024-20398

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the under…

Mitigation only
Fix from $1,950 2024-09-11
Autogpt Classic CRITICAL 9.8
CVE-2024-6091

A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises whe…

Patch available
Fix from $2,300 2024-09-11
Cloud Services Appliance HIGH 7.2
CVE-2024-8190 KEVEPSS 89%

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to …

Mitigation only
Fix from $1,950 2024-09-10
Unclassified HIGH 8.8
CVE-2024-8504EPSS 76%

An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained w…

Mitigation only
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.8
CVE-2024-7699

An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.8
CVE-2024-43385

A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.8
CVE-2024-43386

A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.8
CVE-2024-43387

A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASS…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Unclassified MEDIUM 5.7
CVE-2024-44072

OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and se…

Mitigation only
Fix from $1,600 2024-09-10
Nas326 Firmware CRITICAL 9.8
CVE-2024-6342

**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 …

Fix: 5.21+
Fix from $2,300 2024-09-10
Unclassified HIGH 8.8
CVE-2024-44333EPSS 12%

D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.…

Mitigation only
Fix from $1,950 2024-09-09
T8 Firmware HIGH 8.8
CVE-2024-8574

A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This vulnerability affects the function setPar…

No fix yet
Fix from $1,950 2024-09-08
Vigor3900 Firmware HIGH 8.8
CVE-2024-44844

DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command funct…

No fix yet
Fix from $1,950 2024-09-06
Vigor3900 Firmware HIGH 8.8
CVE-2024-44845

DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string fu…

No fix yet
Fix from $1,950 2024-09-06
Qts HIGH 7.8
CVE-2024-38641

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $1,950 2024-09-06