Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2023-47560 An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute… Qumagie Mitigation only Fix from $1,9502024-01-05 HIGH 8.8 CVE-2023-41288 An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to execute command… Video Station 5.7.2+ Fix from $1,9502024-01-05 HIGH 8.8 CVE-2023-41289 An OS command injection vulnerability has been reported to affect QcalAgent. If exploited, the vulnerability could allow authenticated users to execu… Qcalagent 1.1.8+ Fix from $1,9502024-01-05 HIGH 7.2 CVE-2023-39294 An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… Qts Mitigation only Fix from $1,9502024-01-05 CRITICAL 9.8 CVE-2023-52314 PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operati… Paddlepaddle 2.6.0+ Fix from $2,3002024-01-03 CRITICAL 9.8 CVE-2023-52310 PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the oper… Paddlepaddle 2.6.0+ Fix from $2,3002024-01-03 CRITICAL 9.8 CVE-2023-52311 PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating syst… Paddlepaddle 2.6.0+ Fix from $2,3002024-01-03 HIGH 8.8 CVE-2023-50094EPSS 14% reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_d… Rengine after 2.0.2 Fix from $1,9502024-01-01 CRITICAL 9.8 CVE-2023-50651 TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cg… X6000r Firmware Mitigation only Fix from $2,3002023-12-30 HIGH 7.2 CVE-2023-4464 A vulnerability, which was classified as critical, has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 5… Ccx 400 Firmware Mitigation only Fix from $1,9502023-12-29 HIGH 7.8 CVE-2023-50445EPSS 9% Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N… Gl Mt1300 Firmware No fix yet Fix from $1,9502023-12-28 CRITICAL 9.8 CVE-2023-7116EPSS 9% A vulnerability, which was classified as critical, has been found in WeiYe-Jing datax-web 2.1.2. Affected by this issue is some unknown functionality… Datax Web No fix yet Fix from $2,3002023-12-27 CRITICAL 9.8 CVE-2023-51094 Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet. M3 Firmware No fix yet Fix from $2,3002023-12-26 CRITICAL 9.8 CVE-2023-51098 Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formSetDiagnoseInfo . W9 Firmware No fix yet Fix from $2,3002023-12-26 CRITICAL 9.8 CVE-2023-51099 Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand . W9 Firmware No fix yet Fix from $2,3002023-12-26 CRITICAL 9.8 CVE-2023-51100 Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseInfo . W9 Firmware No fix yet Fix from $2,3002023-12-26 MEDIUM 6.8 CVE-2023-45741 VR-S1000 firmware Ver. 2.37 and earlier allows an attacker with access to the product's web management page to execute arbitrary OS commands. Vr S1000 Firmware after 2.37 Fix from $1,6002023-12-26 HIGH 8.8 CVE-2022-39818 In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. T… Network Functions Manager For Transport No fix yet Fix from $1,9502023-12-25 HIGH 7.8 CVE-2023-7093 A vulnerability classified as critical has been found in KylinSoft kylin-system-updater up to 2.0.5.16-0k2.33. Affected is an unknown function of the… Kylin System Updater after 2.0.5.16-0k2.33 Fix from $1,9502023-12-25 HIGH 7.2 CVE-2023-7002EPSS 46% The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter.… Backup Migration 1.4.0+ Fix from $1,9502023-12-23 CRITICAL 9.8 CVE-2023-51033 TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi setOpModeCfg interface. Ex1200l Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51035 TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost interface. Ex1200l Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-50147 There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its… A3700r Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51028 TOTOLINK EX1800T 9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the apcliChannel parameter of the setWiFiExtende… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-50993 Ruijie WS6008 v1.x v2.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 and WS6108 v1.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 was discovered to contain a command i… Rg Ws6008 Firmware Mitigation only Fix from $2,3002023-12-20 CRITICAL 9.8 CVE-2023-35895 IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a cert… Informix Jdbc Mitigation only Fix from $2,3002023-12-20 MEDIUM 6.8 CVE-2023-0011 A flaw in the input validation in TOBY-L2 allows a user to execute arbitrary operating system commands using specifically crafted AT commands. This v… Toby L200 Firmware Mitigation only Fix from $1,6002023-12-20 HIGH 8.8 CVE-2023-50466 An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary c… Cmt2078x Firmware Mitigation only Fix from $1,9502023-12-19 CRITICAL 9.8 CVE-2019-25158 A vulnerability has been found in pedroetb tts-api up to 2.1.4 and classified as critical. This vulnerability affects the function onSpeechDone of th… Tts Api 2.2.0+ Fix from $2,3002023-12-19 MEDIUM 6.5 CVE-2023-51385EPSS 20% In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by a… Debian Linux 9.6+ Fix from $1,6002023-12-18