Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Mailcleaner CRITICAL 9.8
CVE-2024-3191EPSS 5%

A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects some unknown processing of the …

Fix: after 2023.03.14
Fix from $2,300 2024-04-29
Mailcleaner HIGH 8.8
CVE-2024-3193

A vulnerability has been found in MailCleaner up to 2023.03.14 and classified as critical. Affected by this vulnerability is an unknown functionality…

Fix: after 2023.03.14
Fix from $1,950 2024-04-29
Unclassified HIGH 8.8
CVE-2024-4301

N-Reporter and N-Cloud, products of the N-Partner, have an OS Command Injection vulnerability. Remote attackers with normal user privilege can execut…

Mitigation only
Fix from $1,950 2024-04-29
Isherlock HIGH 7.2
CVE-2024-4299

The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in cert…

Fix: 4.5-147 / 5.5-147+
Fix from $1,950 2024-04-29
Isherlock HIGH 7.2
CVE-2024-4298

The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain func…

Fix: 4.5-188 / 5.5-188+
Fix from $1,950 2024-04-29
Siem HIGH 8.8
CVE-2022-48684

An issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search template uses jinja templating for g…

Fix: 7.1.1+
Fix from $1,950 2024-04-27
Rg Uac 6000 Cc Firmware HIGH 7.2
CVE-2024-4255EPSS 5%

A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240419. This issue affects some unknown processing of the …

Mitigation only
Fix from $1,950 2024-04-27
Dir 822\+ Firmware HIGH 8.8
CVE-2024-33343EPSS 8%

D-Link DIR-822+ V1.0.5 was found to contain a command injection in ChgSambaUserSettings function of prog.cgi, which allows remote attackers to execut…

No fix yet
Fix from $1,950 2024-04-26
Qts HIGH 7.5
CVE-2024-27124

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Fix: 4.5.4.2627 / 5.1.3.2578+
Fix from $1,950 2024-04-26
Qts CRITICAL 10.0
CVE-2024-32766

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Fix: 4.5.4.2627 / 5.1.3.2578+
Fix from $2,300 2024-04-26
Target Management CRITICAL 9.8
CVE-2024-0740

Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vulnerability that does not requi…

Fix: after 4.5.400
Fix from $2,300 2024-04-26
Unclassified HIGH 8.8
CVE-2024-20295

A vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to perform command inject…

Mitigation only
Fix from $1,950 2024-04-24
Unclassified HIGH 8.7
CVE-2024-20356EPSS 33%

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker w…

Mitigation only
Fix from $1,950 2024-04-24
Adaptive Security Appliance Software MEDIUM 6.7
CVE-2024-20358

A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Thre…

Mitigation only
Fix from $1,600 2024-04-24
Deno HIGH 7.4
CVE-2024-32477

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. By using ANSI escape sequences and a race between `libc::tcflush(0, l…

Fix: 1.42.2+
Fix from $1,950 2024-04-18
Smart Reader Firmware HIGH 7.2
CVE-2023-39367EPSS 38%

An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafte…

No fix yet
Fix from $1,950 2024-04-17
W30e Firmware HIGH 8.8
CVE-2024-3880

A vulnerability has been found in Tenda W30E 1.0.1.25(633) and classified as critical. This vulnerability affects the function formWriteFacMac of the…

Mitigation only
Fix from $1,950 2024-04-16
Nextscale N1200 Enclosure Firmware HIGH 7.2
CVE-2024-2659

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute syste…

Mitigation only
Fix from $1,950 2024-04-15
Unclassified HIGH 7.2
CVE-2023-4855

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unaut…

Mitigation only
Fix from $1,950 2024-04-15
Unclassified HIGH 8.8
CVE-2023-4856

A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific A…

Mitigation only
Fix from $1,950 2024-04-15
Wbsairback CRITICAL 9.1
CVE-2024-3781

Command injection vulnerability in the operating system. Improper neutralisation of special elements in Active Directory integration allows the inten…

Mitigation only
Fix from $2,300 2024-04-15
Unclassified HIGH 8.8
CVE-2024-1655

Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system com…

Mitigation only
Fix from $1,950 2024-04-15
Nginxwebui CRITICAL 9.8
CVE-2024-3739

A vulnerability classified as critical was found in cym1102 nginxWebUI up to 3.9.9. This vulnerability affects unknown code of the file /adminPage/ma…

Fix: 4.2.4+
Fix from $2,300 2024-04-13
Unclassified MEDIUM 6.3
CVE-2024-3721EPSS 86%

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the f…

Mitigation only
Fix from $1,600 2024-04-13
Unclassified MEDIUM 6.4
CVE-2024-2742

Operating system command injection vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. An authenticated attacker could e…

Mitigation only
Fix from $1,600 2024-04-11
Localai CRITICAL 9.8
CVE-2024-2029

A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioToWav` function used for conver…

Fix: 2.10.0+
Fix from $2,300 2024-04-10
Lollms Web Ui CRITICAL 9.8
CVE-2024-1520EPSS 48%

An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation…

Fix: 9.2+
Fix from $2,300 2024-04-10
Csmock HIGH 8.8
CVE-2024-2243

A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclo…

Fix: 3.5.3+
Fix from $1,950 2024-04-10
Yt Dlp CRITICAL 9.8
CVE-2024-22423

yt-dlp is a youtube-dl fork with additional features and fixes. The patch that addressed CVE-2023-40581 attempted to prevent RCE when using `--exec` …

Fix: 2024.04.09+
Fix from $2,300 2024-04-09
Fedora CRITICAL 10.0
CVE-2024-24576EPSS 20%

Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly es…

Fix: 1.77.2+
Fix from $2,300 2024-04-09