Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 7.2
CVE-2024-28749

A remote attacker with high privileges may use a writing file function to inject OS commands.

Mitigation only
Fix from $1,950 2024-07-09
Unclassified HIGH 7.2
CVE-2024-28750

A remote attacker with high privileges may use a deleting file function to inject OS commands.

No fix yet
Fix from $1,950 2024-07-09
Unclassified HIGH 7.2
CVE-2024-28748

A remote attacker with high privileges may use a reading file function to inject OS commands.

Mitigation only
Fix from $1,950 2024-07-09
Dir 823x Ax3000 Firmware HIGH 8.8
CVE-2024-39202

D-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd_startip parameter at /goform…

No fix yet
Fix from $1,950 2024-07-08
Rtl819x Jungle Software Development Kit HIGH 7.2
CVE-2023-50382

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series o…

Mitigation only
Fix from $1,950 2024-07-08
Rtl819x Jungle Software Development Kit HIGH 7.2
CVE-2023-50383

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series o…

Mitigation only
Fix from $1,950 2024-07-08
Rtl819x Jungle Software Development Kit HIGH 7.2
CVE-2023-50381

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series o…

No fix yet
Fix from $1,950 2024-07-08
Http File Server HIGH 8.8
CVE-2024-39943EPSS 39%

rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have…

Fix: 0.52.10+
Fix from $1,950 2024-07-04
Nginx Proxy Manager HIGH 8.8
CVE-2024-39935

jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate managem…

Fix: 2.11.3+
Fix from $1,950 2024-07-04
Unclassified HIGH 8.1
CVE-2024-6507

Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API

Patch available
Fix from $1,950 2024-07-04
Unclassified MEDIUM 6.8
CVE-2024-38471

Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring a crafted …

Mitigation only
Fix from $1,600 2024-07-04
Gxp2135 Firmware CRITICAL 9.8
CVE-2024-32937EPSS 26%

An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79.…

No fix yet
Fix from $2,300 2024-07-03
Unclassified HIGH 7.2
CVE-2024-5672

A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in a…

Mitigation only
Fix from $1,950 2024-07-03
Nx Os MEDIUM 6.7
CVE-2024-20399 KEV

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary …

Mitigation only
Fix from $1,600 2024-07-01
Bc500 Firmware HIGH 7.2
CVE-2024-39351

A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP configuratio…

Fix: 1.0.7-0298+
Fix from $1,950 2024-06-28
Bc500 Firmware HIGH 7.2
CVE-2023-47802

A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP block functio…

Fix: 1.0.7-0298+
Fix from $1,950 2024-06-28
Data Domain Operating System HIGH 8.8
CVE-2024-37140

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin oper…

Fix: 7.7.5.40 / 7.10.1.30+
Fix from $1,950 2024-06-26
Localai CRITICAL 9.8
CVE-2024-5181

A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the application's handling of the backen…

Patch available
Fix from $2,300 2024-06-26
Whatsup Gold CRITICAL 9.8
CVE-2024-4883EPSS 65%

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauth…

Fix: 23.1.3+
Fix from $2,300 2024-06-25
Whatsup Gold CRITICAL 9.8
CVE-2024-4884EPSS 24%

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.…

Fix: 23.1.3+
Fix from $2,300 2024-06-25
Finesoft MEDIUM 5.3
CVE-2024-37678

Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker to execute…

Fix: after 8.0
Fix from $1,600 2024-06-24
Cruddiy HIGH 7.8
CVE-2024-4748

The CRUDDIY project is vulnerable to shell command injection via sending a crafted POST request to the application server.  The exploitation risk is …

Fix: after 202312.1
Fix from $1,950 2024-06-24
Consulting Elementor Widgets HIGH 8.8
CVE-2024-37091

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, Sty…

Fix: 1.3.1+
Fix from $1,950 2024-06-24
A6000r Firmware HIGH 8.8
CVE-2024-37626

A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the iface paramete…

Mitigation only
Fix from $1,950 2024-06-20
Rg Uac Firmware CRITICAL 9.8
CVE-2024-6186EPSS 9%

A vulnerability, which was classified as critical, was found in Ruijie RG-UAC 1.0. This affects an unknown part of the file /view/userAuthentication/…

No fix yet
Fix from $2,300 2024-06-20
Rg Uac Firmware CRITICAL 9.8
CVE-2024-6187EPSS 8%

A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects unknown code of the file /view/vpn/autovpn…

No fix yet
Fix from $2,300 2024-06-20
Rg Uac Firmware CRITICAL 9.8
CVE-2024-6184EPSS 10%

A vulnerability classified as critical was found in Ruijie RG-UAC 1.0. Affected by this vulnerability is an unknown functionality of the file /view/s…

No fix yet
Fix from $2,300 2024-06-20
Rg Uac Firmware HIGH 8.8
CVE-2024-6185EPSS 9%

A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC 1.0. Affected by this issue is the function get_ip_addr_details of…

No fix yet
Fix from $1,950 2024-06-20
Unclassified CRITICAL 9.8
CVE-2024-6048

Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticated remote attacker can exploi…

Mitigation only
Fix from $2,300 2024-06-17
Gv Dsp Lpr Firmware CRITICAL 9.8
CVE-2024-6047 KEVEPSS 10%

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vu…

Mitigation only
Fix from $2,300 2024-06-17