Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Pyansys Geometry HIGH 7.8
CVE-2024-29189

PyAnsys Geometry is a Python client library for the Ansys Geometry service and other CAD Ansys products. On file src/ansys/geometry/core/connection/p…

Fix: 0.3.3 / 0.4.12+
Fix from $1,950 2024-03-26
Unclassified HIGH 8.8
CVE-2024-25002

Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.

Mitigation only
Fix from $1,950 2024-03-25
Unclassified HIGH 8.1
CVE-2024-24892

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Management vulnerability in openEuler …

Mitigation only
Fix from $1,950 2024-03-25
Unclassified HIGH 7.2
CVE-2024-24899

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-zeus on Linux allows Comma…

Mitigation only
Fix from $1,950 2024-03-25
Unclassified HIGH 7.8
CVE-2024-24890

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler gala-gopher on Linux allows Com…

Mitigation only
Fix from $1,950 2024-03-25
Ac18 Firmware CRITICAL 9.8
CVE-2024-2854

A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetSambaConf of the file /goform/setsam…

No fix yet
Fix from $2,300 2024-03-24
Ac10u Firmware CRITICAL 9.8
CVE-2024-2853

A vulnerability was found in Tenda AC10U 15.03.06.48/15.03.06.49. It has been rated as critical. This issue affects the function formSetSambaConf of …

No fix yet
Fix from $2,300 2024-03-24
Ac15 Firmware CRITICAL 9.8
CVE-2024-2851

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been classified as critical. This affects the function formSetSambaConf of…

No fix yet
Fix from $2,300 2024-03-24
Unclassified HIGH 7.3
CVE-2021-33633

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-ceres on Linux allows Comm…

Mitigation only
Fix from $1,950 2024-03-23
Freescout CRITICAL 9.0
CVE-2024-29185

FreeScout is a self-hosted help desk and shared mailbox. Versions prior to 1.8.128 are vulnerable to OS Command Injection in the /public/tools.php so…

Fix: 1.8.128+
Fix from $2,300 2024-03-22
Loadmaster HIGH 8.8
CVE-2024-2448EPSS 55%

An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject…

Fix: 7.2.54.9 / 7.2.59.3+
Fix from $1,950 2024-03-22
Ac15 Firmware HIGH 8.8
CVE-2024-2812

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been classified as critical. This affects the function formWriteFacMac of …

No fix yet
Fix from $1,950 2024-03-22
Unclassified HIGH 8.8
CVE-2024-2162

An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on the device with high privile…

Mitigation only
Fix from $1,950 2024-03-21
Ac10u Firmware HIGH 8.8
CVE-2024-2707

A vulnerability has been found in Tenda AC10U 15.03.06.49 and classified as critical. This vulnerability affects the function formWriteFacMac of the …

No fix yet
Fix from $1,950 2024-03-20
Pandora Fms CRITICAL 9.1
CVE-2023-44092

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Pandora FMS on all allows OS Command Inje…

Fix: 776+
Fix from $2,300 2024-03-19
Unilogic HIGH 8.8
CVE-2024-27772

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-78: 'OS Command Injection' may allow RCE

Fix: 1.35.227+
Fix from $1,950 2024-03-18
Unclassified CRITICAL 9.8
CVE-2024-28125

FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this …

No fix yet
Fix from $2,300 2024-03-18
Openmetadata HIGH 8.8
CVE-2024-28254EPSS 46%

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml…

Fix: 1.2.4+
Fix from $1,950 2024-03-15
Nuclei HIGH 7.4
CVE-2024-27920

projectdiscovery/nuclei is a fast and customisable vulnerability scanner based on simple YAML based DSL. A significant security oversight was identif…

Fix: 3.2.0+
Fix from $1,950 2024-03-15
Fluid MEDIUM 6.0
CVE-2023-51699

Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection v…

Fix: 0.9.3+
Fix from $1,600 2024-03-15
Unclassified HIGH 7.8
CVE-2024-2415

Command injection vulnerability in Movistar 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an authenticated user to e…

Mitigation only
Fix from $1,950 2024-03-13
Soy Cms HIGH 7.2
CVE-2024-28187

SOY CMS is an open source CMS (content management system) that allows you to build blogs and online shops. SOY CMS versions prior to 3.14.2 are vulne…

Fix: 3.14.2+
Fix from $1,950 2024-03-11
X6000r Firmware HIGH 8.8
CVE-2024-2353

A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the function setDiagnos…

No fix yet
Fix from $1,950 2024-03-10
Qts HIGH 8.4
CVE-2023-34980

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Fix: 4.5.4.2627+
Fix from $1,950 2024-03-08
Paddlepaddle HIGH 8.8
CVE-2024-0815

Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0

No fix yet
Fix from $1,950 2024-03-07
Ctm 200 Firmware HIGH 7.5
CVE-2023-47415EPSS 14%

Cypress Solutions CTM-200 v2.7.1.5600 and below was discovered to contain an OS command injection vulnerability via the cli_text parameter.

Fix: after 2.7.1.5600-113
Fix from $1,950 2024-03-07
Wap121 Firmware MEDIUM 6.5
CVE-2024-20335

A vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, rem…

Mitigation only
Fix from $1,600 2024-03-06
Clamav MEDIUM 5.3
CVE-2024-20328EPSS 85%

A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the privileges of the application …

Fix: 1.0.5 / 1.2.2+
Fix from $1,600 2024-03-01
Unclassified CRITICAL 9.4
CVE-2024-1624

An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2…

Mitigation only
Fix from $2,300 2024-03-01
Live Helper Chat CRITICAL 9.8
CVE-2024-27516

Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sens…

Fix: 4.34+
Fix from $2,300 2024-02-29