Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Fortisandbox HIGH 8.8
CVE-2024-21756

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…

Fix: 4.0.5 / 4.2.7+
Fix from $1,950 2024-04-09
Fortisandbox HIGH 8.8
CVE-2024-21755

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…

Fix: 4.0.5 / 4.2.7+
Fix from $1,950 2024-04-09
Fortisandbox MEDIUM 6.7
CVE-2023-47540

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.…

Fix: 4.2.7 / 4.4.3+
Fix from $1,600 2024-04-09
Webos HIGH 7.2
CVE-2023-6319EPSS 6%

A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 …

No fix yet
Fix from $1,950 2024-04-09
Webos HIGH 7.2
CVE-2023-6320

A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A ser…

No fix yet
Fix from $1,950 2024-04-09
Webos HIGH 7.2
CVE-2023-6318

A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 throu…

No fix yet
Fix from $1,950 2024-04-09
Unclassified HIGH 8.8
CVE-2023-1082

An remote attacker with low privileges can perform a command injection which can lead to root access.

No fix yet
Fix from $1,950 2024-04-09
Emui HIGH 7.5
CVE-2024-30414

Command injection vulnerability in the AccountManager module. Impact: Successful exploitation of this vulnerability may affect service confidentialit…

No fix yet
Fix from $1,950 2024-04-07
Unclassified MEDIUM 6.3
CVE-2024-3346EPSS 49%

A vulnerability was found in Byzoro Smart S80 up to 20240328. It has been declared as critical. This vulnerability affects unknown code of the file /…

Mitigation only
Fix from $1,600 2024-04-05
Fabric Operating System CRITICAL 9.8
CVE-2023-3454

Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use…

Fix: 9.1.1d1+
Fix from $2,300 2024-04-04
Unclassified HIGH 7.1
CVE-2024-26258

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OS command…

Mitigation only
Fix from $1,950 2024-04-04
Unclassified HIGH 7.2
CVE-2024-29167

SVR-116 firmware version 1.6.0.30028871 allows a remote authenticated attacker with an administrative privilege to execute arbitrary OS commands by s…

Mitigation only
Fix from $1,950 2024-04-04
Unclassified HIGH 8.8
CVE-2024-25568

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands…

Mitigation only
Fix from $1,950 2024-04-04
Omada Er605 Firmware HIGH 8.0
CVE-2024-1180

TP-Link Omada ER605 Access Control Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to exe…

Fix: 2.2.3+
Fix from $1,950 2024-04-03
Videowhisper Live Streaming Integration CRITICAL 9.8
CVE-2023-25699

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Stream…

Fix: 5.5.16+
Fix from $2,300 2024-04-03
Flowmon CRITICAL 9.8
CVE-2024-2389EPSS 93%

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user ca…

Fix: 11.1.14 / 12.3.5+
Fix from $2,300 2024-04-02
Viewpower CRITICAL 9.8
CVE-2023-51572EPSS 38%

Voltronic Power ViewPower Pro getMacAddressByIp Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $2,300 2024-04-01
Unclassified CRITICAL 9.8
CVE-2024-29640

An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in th…

Mitigation only
Fix from $2,300 2024-03-29
Ac15 Firmware HIGH 8.0
CVE-2024-30645

Tenda AC15V1.0 V15.03.20_multi has a command injection vulnerability via the deviceName parameter.

Mitigation only
Fix from $1,950 2024-03-29
Nextcloudpi CRITICAL 9.8
CVE-2024-30247

NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command injection vulnerability in Nex…

Fix: 1.53.1+
Fix from $2,300 2024-03-29
Powermax Eem HIGH 8.8
CVE-2024-25946

Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnera…

Fix: 9.2.4.6 / 9.2.4.9+
Fix from $1,950 2024-03-28
Powermax Eem HIGH 8.8
CVE-2024-25955

Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnera…

Fix: 9.2.4.6 / 9.2.4.9+
Fix from $1,950 2024-03-28
Unclassified CRITICAL 9.8
CVE-2023-6437

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TP-Link TP-Link EX20v AX1800, Tp-Link Arc…

Mitigation only
Fix from $2,300 2024-03-28
Aterm Wg1800hp4 Firmware CRITICAL 9.8
CVE-2024-28015

Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, …

Mitigation only
Fix from $2,300 2024-03-28
A3300r Firmware HIGH 8.0
CVE-2024-27521

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parame…

Mitigation only
Fix from $1,950 2024-03-26
Rg Eg350 Firmware HIGH 8.8
CVE-2024-2909

A vulnerability classified as critical was found in Ruijie RG-EG350 up to 20240318. Affected by this vulnerability is the function setAction of the f…

Fix: after 2024-03-18
Fix from $1,950 2024-03-26
Rg Eg350 Firmware HIGH 8.8
CVE-2024-2910

A vulnerability, which was classified as critical, has been found in Ruijie RG-EG350 up to 20240318. Affected by this issue is the function vpnAction…

Fix: after 2024-03-18
Fix from $1,950 2024-03-26
Ac7 Firmware HIGH 8.8
CVE-2024-2897EPSS 8%

A vulnerability classified as critical has been found in Tenda AC7 15.03.06.44. Affected is the function formWriteFacMac of the file /goform/WriteFac…

No fix yet
Fix from $1,950 2024-03-26
Unclassified HIGH 7.3
CVE-2024-28033

OS command injection vulnerability exists in WebProxy 1.7.8 and 1.7.9, which may allow a remote unauthenticated attacker to execute an arbitrary OS c…

Mitigation only
Fix from $1,950 2024-03-26
Unclassified CRITICAL 9.8
CVE-2024-28048

OS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execute an arbitrary OS command wi…

Mitigation only
Fix from $2,300 2024-03-26