Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2023-6901 A vulnerability, which was classified as critical, was found in codelyfe Stupid Simple CMS up to 1.2.3. This affects an unknown part of the file /ter… Stupid Simple Cms after 1.2.3 Fix from $2,3002023-12-17 CRITICAL 9.8 CVE-2023-6895EPSS 89% A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability… Intercom Broadcast System 4.1.0+ Fix from $2,3002023-12-17 CRITICAL 9.8 CVE-2021-42796 An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitra… Edge 2020+ Fix from $2,3002023-12-16 HIGH 8.0 CVE-2023-48380 Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a spcific function. A remote a… Mail Sqr Expert 230330+ Fix from $1,9502023-12-15 HIGH 7.2 CVE-2023-48667 Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administra… Apex Protection Storage 2.7.6 / 6.2.1.110+ Fix from $1,9502023-12-14 MEDIUM 6.7 CVE-2023-48668 Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 on DDMC contain an OS command injection vulnerability in an… Powerprotect Data Domain Management Center 6.2.1.110 / 7.7.5.25+ Fix from $1,6002023-12-14 HIGH 7.2 CVE-2023-48662 Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentiall… Solutions Enabler Virtual Appliance 9.2.4.5 / 9.2.4.7+ Fix from $1,9502023-12-14 HIGH 7.2 CVE-2023-48663 Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentiall… Solutions Enabler Virtual Appliance 9.2.4.5 / 9.2.4.7+ Fix from $1,9502023-12-14 HIGH 7.2 CVE-2023-48664 Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentiall… Solutions Enabler Virtual Appliance 9.2.4.5 / 9.2.4.7+ Fix from $1,9502023-12-14 HIGH 7.2 CVE-2023-48665 Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentiall… Solutions Enabler Virtual Appliance 9.2.4.5 / 9.2.4.7+ Fix from $1,9502023-12-14 MEDIUM 6.7 CVE-2023-44279 Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administ… Powerprotect Data Protection 2.7.6 / 6.2.1.110+ Fix from $1,6002023-12-14 HIGH 7.8 CVE-2023-44277 Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A… Powerprotect Data Protection 2.7.6 / 6.2.1.110+ Fix from $1,9502023-12-14 MEDIUM 6.3 CVE-2023-6792 An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system proces… Pan Os 8.1.24 / 9.0.17+ Fix from $1,6002023-12-13 CRITICAL 9.8 CVE-2023-42495 Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') W Web after 1.27 Fix from $2,3002023-12-13 HIGH 8.8 CVE-2023-48782 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows … Fortiwlm after 8.6.5 Fix from $1,9502023-12-13 HIGH 7.8 CVE-2023-40716 An improper neutralization of special elements used in an OS command vulnerability [CWE-78]  in the command line interpreter of FortiTester 2.3.0 thr… Fortitester Mitigation only Fix from $1,9502023-12-13 CRITICAL 9.8 CVE-2023-46454EPSS 23% In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package in… Gl Ar300m Firmware Mitigation only Fix from $2,3002023-12-12 MEDIUM 6.7 CVE-2023-49692 A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK610… 6gk6108 4am00 2ba2 Firmware 7.2.2+ Fix from $1,6002023-12-12 MEDIUM 6.7 CVE-2023-49691 A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-… 6gk6108 4am00 2ba2 Firmware 8.0+ Fix from $1,6002023-12-12 HIGH 7.2 CVE-2023-48428 A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not… Sinec Ins 1.0+ Fix from $1,9502023-12-12 MEDIUM 6.8 CVE-2023-49695 OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adj… Wrc X3000gsn Firmware after 1.0.24 Fix from $1,6002023-12-12 HIGH 7.5 CVE-2022-48616 A Huawei data communication product has a command injection vulnerability. Successful exploitation of this vulnerability may allow attackers to gain … Ar617vw Firmware No fix yet Fix from $1,9502023-12-12 CRITICAL 9.8 CVE-2023-47254 An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and esca… Vigor167 Firmware No fix yet Fix from $2,3002023-12-09 CRITICAL 9.8 CVE-2023-6612EPSS 31% A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. This issue affects the function setDdnsCfg/setDyn… X5000r Firmware No fix yet Fix from $2,3002023-12-08 HIGH 8.8 CVE-2023-47565 KEVEPSS 73% An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerabili… Qvr Firmware 5.0.0+ Fix from $1,9502023-12-08 HIGH 8.8 CVE-2023-46157 File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and ch… Cloudpanel after 2.3.2 Fix from $1,9502023-12-08 HIGH 7.2 CVE-2023-43744 An OS command injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 1716… Mx Se Firmware 16.0.4 / 17.0.10+ Fix from $1,9502023-12-08 HIGH 8.8 CVE-2023-49897 KEVEPSS 51% An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vu… Ae1021 Firmware 2.0.10+ Fix from $1,9502023-12-06 HIGH 7.2 CVE-2023-44221 KEVEPSS 75% Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative pri… Sma 200 Firmware after 10.2.1.9-57sv Fix from $1,9502023-12-05 HIGH 8.8 CVE-2023-6357 A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the… Control For Beaglebone Sl 4.11.0.0+ Fix from $1,9502023-12-05