Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
MEDIUM 6.8 CVE-2023-24046 An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in the ping ut… Ac21000 G6 Firmware No fix yet Fix from $1,6002023-12-04 CRITICAL 9.8 CVE-2023-48800 In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the … X6000r Firmware No fix yet Fix from $2,3002023-12-04 HIGH 8.8 CVE-2023-44304 Dell DM5500 contains a privilege escalation vulnerability in the appliance. A remote attacker with low privileges could potentially exploit this vuln… Dm5500 Firmware after 5.14.0.0 Fix from $1,9502023-12-04 HIGH 7.2 CVE-2023-44291 Dell DM5500 5.14.0.0 contains an OS command injection vulnerability in the appliance. A remote attacker with high privileges could potentially exploi… Powerprotect Data Manager Dm5500 Firmware after 5.14.0.0 Fix from $1,9502023-12-04 CRITICAL 9.8 CVE-2023-48842 D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi. Go Rt Ac750 Firmware No fix yet Fix from $2,3002023-12-01 CRITICAL 9.8 CVE-2023-48808 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48810 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48811 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48812 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function t… X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48802 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48803 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48804 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48805 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48806 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48807 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30 HIGH 8.8 CVE-2023-37928EPSS 60% A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware ve… Nas326 Firmware after 5.21 Fix from $1,9502023-11-30 CRITICAL 9.8 CVE-2023-4473EPSS 41% A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C… Nas326 Firmware after 5.21 Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-4474EPSS 30% The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version … Nas326 Firmware after 5.21 Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-35138EPSS 40% A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firm… Nas326 Firmware after 5.21 Fix from $2,3002023-11-30 HIGH 8.8 CVE-2023-37927 The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version … Nas326 Firmware after 5.21 Fix from $1,9502023-11-30 CRITICAL 9.8 CVE-2023-3741 An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on the device. Itk 6dgs 1\(bk\)tel Firmware Mitigation only Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-23325 Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the NetHostname parameter. Netlink Ccd Firmware Mitigation only Fix from $2,3002023-11-29 HIGH 8.8 CVE-2023-6201 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Univera Computer System Panorama allows C… Panorama 8.0+ Fix from $1,9502023-11-28 HIGH 8.8 CVE-2023-4222 Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtai… Chamilo Lms after 1.11.24 Fix from $1,9502023-11-28 HIGH 8.8 CVE-2023-4221 Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain… Chamilo Lms after 1.11.24 Fix from $1,9502023-11-28 CRITICAL 9.8 CVE-2023-3368EPSS 69% Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code… Chamilo 1.11.20+ Fix from $2,3002023-11-28 CRITICAL 9.8 CVE-2023-6309 A vulnerability, which was classified as critical, was found in moses-smt mosesdecoder up to 4.0. This affects an unknown part of the file contrib/iS… Mosesdecoder 4.0+ Fix from $2,3002023-11-27 HIGH 8.0 CVE-2023-6304EPSS 10% A vulnerability was found in Tecno 4G Portable WiFi TR118 TR118-M30E-RR-D-EnFrArSwHaPo-OP-V008-20220830. It has been declared as critical. This vulne… Tr118 Firmware No fix yet Fix from $1,9502023-11-27 CRITICAL 9.8 CVE-2023-4149 A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system contro… 0852 0602 Firmware 1.0.6.s0 / 1.2.5.s0+ Fix from $2,3002023-11-21 CRITICAL 9.8 CVE-2023-35762 Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could allow remote code execution. Me Rtu Firmware 3.37+ Fix from $2,3002023-11-20