Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified MEDIUM 6.8
CVE-2024-25579

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbi…

Mitigation only
Fix from $1,600 2024-02-28
Security Guardium Key Lifecycle Manager HIGH 8.8
CVE-2023-25925

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands…

Fix: 4.1.1.7+
Fix from $1,950 2024-02-28
Identity Exposure HIGH 7.3
CVE-2024-1683

A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay hos…

Fix: 3.59.4+
Fix from $1,950 2024-02-23
Basercms HIGH 8.1
CVE-2023-51450

baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of bas…

Fix: 5.0.9+
Fix from $1,950 2024-02-22
Wf2780 Firmware HIGH 8.0
CVE-2024-25851

Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in other_para of cgitest.cgi.

No fix yet
Fix from $1,950 2024-02-22
Loadmaster CRITICAL 9.8
CVE-2024-1212 KEVEPSS 95%

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Fix: 7.2.48.10 / 7.2.54.8+
Fix from $2,300 2024-02-21
Atp100 Firmware HIGH 7.2
CVE-2023-6398

A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1,…

Fix: 5.37+
Fix from $1,950 2024-02-20
Loomio HIGH 7.2
CVE-2024-1297

Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Inject…

Patch available
Fix from $1,950 2024-02-20
Acs100 Firmware HIGH 8.8
CVE-2023-6260

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Brivo ACS100, ACS300 allows OS Command In…

Fix: 6.2.4.3+
Fix from $1,950 2024-02-19
Yocto CRITICAL 9.8
CVE-2024-25626

Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture…

Fix: 3.1.31 / 4.0.16+
Fix from $2,300 2024-02-19
Less HIGH 7.8
CVE-2022-48624

close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.

Fix: 606+
Fix from $1,950 2024-02-19
X5000r Firmware HIGH 7.5
CVE-2024-25468

An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of the NTPSyncW…

No fix yet
Fix from $1,950 2024-02-17
Recoverpoint For Virtual Machines CRITICAL 9.8
CVE-2024-22426

Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potent…

Mitigation only
Fix from $2,300 2024-02-16
Commerce CRITICAL 9.1
CVE-2024-20720

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command…

Mitigation only
Fix from $2,300 2024-02-15
Smartfabric Os10 CRITICAL 9.8
CVE-2023-32462

Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remot…

Fix: 10.5.2.12 / 10.5.3.8+
Fix from $2,300 2024-02-15
Oaklouds Organization 2.0 CRITICAL 9.8
CVE-2024-26260

The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inj…

Fix: 188 / 1051+
Fix from $2,300 2024-02-15
Security Center HIGH 7.2
CVE-2024-1367

A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application cou…

Fix: 6.3.0+
Fix from $1,950 2024-02-14
Big Ip Access Policy Manager MEDIUM 6.7
CVE-2024-21782

BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced…

Fix: 15.1.9 / 16.1.4+
Fix from $1,600 2024-02-14
Jh Rvb1 Firmware HIGH 8.8
CVE-2024-23789

Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to exec…

Mitigation only
Fix from $1,950 2024-02-14
Sinec Nms HIGH 8.8
CVE-2024-23812

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application incorrectly neutralizes special elements when cr…

Fix: 2.0+
Fix from $1,950 2024-02-13
Powerprotect Data Manager HIGH 7.2
CVE-2024-22445

Dell PowerProtect Data Manager, version 19.15 and prior versions, contain an OS command injection vulnerability. A remote high privileged attacker co…

Fix: after 19.15
Fix from $1,950 2024-02-13
Ides Ecc MEDIUM 6.3
CVE-2024-22132

SAP IDES ECC-systems contain code that permits the execution of arbitrary program code of user's choice.An attacker can therefore control the behavio…

Mitigation only
Fix from $1,600 2024-02-13
Qts HIGH 8.3
CVE-2023-47218EPSS 90%

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Fix: 5.1.5.2645+
Fix from $1,950 2024-02-13
Qts MEDIUM 5.8
CVE-2023-50358EPSS 14%

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Fix: 4.2.6 / 4.3.3.2644+
Fix from $1,600 2024-02-13
Unity Operating Environment HIGH 7.8
CVE-2024-22227

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could potentially …

Fix: 5.4.0.0.5.094+
Fix from $1,950 2024-02-12
Unity Operating Environment HIGH 7.8
CVE-2024-22228

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could pot…

Fix: 5.4.0.0.5.094+
Fix from $1,950 2024-02-12
Unity Operating Environment HIGH 7.8
CVE-2024-22222

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated malicious user wit…

Fix: 5.4.0.0.5.094+
Fix from $1,950 2024-02-12
Unity Operating Environment HIGH 7.8
CVE-2024-22223

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with lo…

Fix: 5.4.0.0.5.094+
Fix from $1,950 2024-02-12
Unity Operating Environment HIGH 7.8
CVE-2024-22224

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially…

Fix: 5.4.0.0.5.094+
Fix from $1,950 2024-02-12
Unity Operating Environment HIGH 7.8
CVE-2024-22225

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attacker could p…

Fix: 5.4.0.0.5.094+
Fix from $1,950 2024-02-12