Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 7.2
CVE-2024-31162

The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative p…

Mitigation only
Fix from $1,950 2024-06-14
Unclassified CRITICAL 9.8
CVE-2024-27172EPSS 27%

Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL.

No fix yet
Fix from $2,300 2024-06-14
Unclassified HIGH 7.5
CVE-2024-4696

A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be…

Mitigation only
Fix from $1,950 2024-06-13
Unclassified MEDIUM 6.8
CVE-2024-36103

OS command injection vulnerability in WRC-X5400GS-B v1.0.10 and earlier, and WRC-X5400GSA-B v1.0.10 and earlier allows a network-adjacent attacker wi…

Mitigation only
Fix from $1,600 2024-06-12
Unclassified CRITICAL 9.8
CVE-2024-36360

OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlier. If a remote unauthent…

Mitigation only
Fix from $2,300 2024-06-11
Pandora Fms CRITICAL 9.8
CVE-2024-35304

System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This iss…

Fix: 777+
Fix from $2,300 2024-06-10
Pandora Fms CRITICAL 9.8
CVE-2024-35306

OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: f…

Fix: 777+
Fix from $2,300 2024-06-10
Unclassified HIGH 8.0
CVE-2024-5785

Command injection vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability could allow an authenti…

Mitigation only
Fix from $1,950 2024-06-10
PHP CRITICAL 9.8
CVE-2024-4577 KEVEPSS 100%

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to us…

Fix: 8.1.29 / 8.2.20+
Fix from $2,300 2024-06-09
PHP HIGH 8.8
CVE-2024-5585EPSS 29%

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes tr…

Fix: 8.1.29 / 8.2.20+
Fix from $1,950 2024-06-09
Lollms Web Ui CRITICAL 9.8
CVE-2024-2359

A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and execute arbitrary code. The issu…

No fix yet
Fix from $2,300 2024-06-06
Autogpt Classic HIGH 7.8
CVE-2024-1880

An OS command injection vulnerability exists in the MacOS Text-To-Speech class MacOSTTS of the significant-gravitas/autogpt project, affecting versio…

Fix: 0.5.1+
Fix from $1,950 2024-06-06
Autogpt Classic CRITICAL 9.8
CVE-2024-1881

AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements used in an OS command ('OS Comm…

Fix: 0.5.1+
Fix from $2,300 2024-06-06
Anythingllm CRITICAL 9.8
CVE-2024-3104

A remote code execution vulnerability exists in mintplex-labs/anything-llm due to improper handling of environment variables. Attackers can exploit t…

Fix: 1.0.0+
Fix from $2,300 2024-06-06
Advanced Core Operating System HIGH 8.8
CVE-2024-30368

A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2024-06-06
Sysaid CRITICAL 9.8
CVE-2024-36394

SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Fix: after 23.3.38
Fix from $2,300 2024-06-06
Unclassified HIGH 8.7
CVE-2024-5421

Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated c…

Mitigation only
Fix from $1,950 2024-06-04
Gradio CRITICAL 9.1
CVE-2024-4253

A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerabili…

Fix: 4.29.0+
Fix from $2,300 2024-06-04
Nas326 Firmware CRITICAL 9.8
CVE-2024-29973EPSS 86%

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.…

Fix: 5.21+
Fix from $2,300 2024-06-04
Nas326 Firmware CRITICAL 9.8
CVE-2024-29972EPSS 89%

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.…

Fix: 5.21+
Fix from $2,300 2024-06-04
Unclassified CRITICAL 9.8
CVE-2024-32850

Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earli…

Mitigation only
Fix from $2,300 2024-05-31
Lenels2 Netbox CRITICAL 9.8
CVE-2024-2421

LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions prior to and including 5.6.1, …

Fix: 5.6.2+
Fix from $2,300 2024-05-30
Iap 420 Firmware HIGH 8.8
CVE-2024-5411EPSS 23%

Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue…

Fix: after 2.01e
Fix from $1,950 2024-05-28
Unclassified HIGH 7.2
CVE-2024-5403

ASKEY 5G NR Small Cell fails to properly filter user input for certain functionality, allowing remote attackers with administrator privilege to execu…

Mitigation only
Fix from $1,950 2024-05-27
Mail2000 HIGH 8.8
CVE-2024-5400

Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to exe…

Mitigation only
Fix from $1,950 2024-05-27
Mail2000 HIGH 7.2
CVE-2024-5399

Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability…

Mitigation only
Fix from $1,950 2024-05-27
Rg Uac 6000 E20c Firmware HIGH 7.2
CVE-2024-5340EPSS 8%

A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been rated as critical. Affected by this issue is some unknown functionality of the…

Mitigation only
Fix from $1,950 2024-05-25
Rg Uac 6000 Cc Firmware HIGH 7.2
CVE-2024-5339EPSS 8%

A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been declared as critical. Affected by this vulnerability is an unknown functionali…

Mitigation only
Fix from $1,950 2024-05-25
Rg Uac 6000 Cc Firmware HIGH 7.2
CVE-2024-5338EPSS 8%

A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been classified as critical. Affected is an unknown function of the file /view/vpn/…

Mitigation only
Fix from $1,950 2024-05-25
Rg Uac 6000 Cc Firmware HIGH 7.2
CVE-2024-5336EPSS 9%

A vulnerability has been found in Ruijie RG-UAC up to 20240516 and classified as critical. This vulnerability affects the function addVlan of the fil…

Mitigation only
Fix from $1,950 2024-05-25