Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2023-5002 A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a user selects to external PostgreSQL utilities su… Pgadmin 4 7.7+ Fix from $1,9502023-09-22 CRITICAL 9.1 CVE-2022-3874 A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile comm… Satellite Mitigation only Fix from $2,3002023-09-22 HIGH 8.8 CVE-2023-23362 An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated… Qts 4.5.4.2374 / 5.0.1.2376+ Fix from $1,9502023-09-22 CRITICAL 9.1 CVE-2023-0118 An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on … Satellite 6.13.3+ Fix from $2,3002023-09-20 HIGH 7.2 CVE-2023-38886EPSS 29% An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script. Dolibarr Erp\/crm after 17.0.1 Fix from $1,9502023-09-20 HIGH 8.8 CVE-2022-47555 Operating system command injection in ekorCCP and ekorRCI, which could allow an authenticated attacker to execute commands, create new users with ele… Ekorrci Firmware Mitigation only Fix from $1,9502023-09-19 HIGH 7.2 CVE-2023-35850 SUNNET WMPro portal's file management function has a vulnerability of insufficient filtering for user input. A remote attacker with administrator pri… Wmpro Mitigation only Fix from $1,9502023-09-18 CRITICAL 9.8 CVE-2023-28614 Freewill iFIS (aka SMART Trade) 20.01.01.04 allows OS Command Injection via shell metacharacters to a report page. Smart Trade Mitigation only Fix from $2,3002023-09-15 HIGH 7.8 CVE-2023-36642 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through … Fortitester after 7.2.3 Fix from $1,9502023-09-13 HIGH 8.8 CVE-2022-35849 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 through 7.1… Fortiadc 6.2.6 / 7.0.4+ Fix from $1,9502023-09-13 HIGH 8.8 CVE-2023-39780 KEVEPSS 34% On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist paramete… Rt Ax55 Firmware Mitigation only Fix from $1,9502023-09-11 CRITICAL 9.8 CVE-2023-4873EPSS 75% A vulnerability, which was classified as critical, was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to … Smart S45f Firmware after 20230906 Fix from $2,3002023-09-10 MEDIUM 6.7 CVE-2023-20193 A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary fi… Identity Services Engine after 3.3 Fix from $1,6002023-09-07 HIGH 8.8 CVE-2023-38032 ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege … Rt Ac86u Firmware Mitigation only Fix from $1,9502023-09-07 HIGH 8.8 CVE-2023-38033 ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user … Rt Ac86u Firmware Mitigation only Fix from $1,9502023-09-07 HIGH 8.8 CVE-2023-39236 ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege ca… Rt Ac86u Firmware Mitigation only Fix from $1,9502023-09-07 HIGH 8.8 CVE-2023-39237 ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privileg… Rt Ac86u Firmware Mitigation only Fix from $1,9502023-09-07 HIGH 8.8 CVE-2023-38031 ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can … Rt Ac86u Firmware Mitigation only Fix from $1,9502023-09-07 HIGH 7.2 CVE-2021-36023 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the W… Magento 2.3.7 / 2.4.2+ Fix from $1,9502023-09-06 CRITICAL 9.8 CVE-2023-41149 F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can acces… F Revocrm Mitigation only Fix from $2,3002023-09-06 HIGH 8.0 CVE-2023-40531 Archer AX6000 firmware versions prior to 'Archer AX6000(JP)_V1_1.3.0 Build 20221208' allows a network-adjacent authenticated attacker to execute arbi… Archer Ax6000 Firmware 1.3.0+ Fix from $1,9502023-09-06 HIGH 8.8 CVE-2023-38563 Archer C1200 firmware versions prior to 'Archer C1200(JP)_V2_230508' and Archer C9 firmware versions prior to 'Archer C9(JP)_V3_230508' allow a netwo… Archer C1200 Firmware 230508+ Fix from $1,9502023-09-06 HIGH 8.8 CVE-2023-38568 Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504' allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Archer A10 Firmware 230504+ Fix from $1,9502023-09-06 HIGH 8.0 CVE-2023-38588 Archer C3150 firmware versions prior to 'Archer C3150(JP)_V2_230511' allows a network-adjacent authenticated attacker to execute arbitrary OS command… Archer C3150 Firmware 230511+ Fix from $1,9502023-09-06 HIGH 8.0 CVE-2023-39224 Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to… Archer C7 Firmware 230602+ Fix from $1,9502023-09-06 HIGH 8.0 CVE-2023-39935 Archer C5400 firmware versions prior to 'Archer C5400(JP)_V2_230506' allows a network-adjacent authenticated attacker to execute arbitrary OS command… Archer C5400 Firmware 230506+ Fix from $1,9502023-09-06 HIGH 8.0 CVE-2023-40193 Deco M4 firmware versions prior to 'Deco M4(JP)_V2_1.5.8 Build 20230619' allows a network-adjacent authenticated attacker to execute arbitrary OS com… Deco M4 Firmware 1.5.8+ Fix from $1,9502023-09-06 HIGH 8.0 CVE-2023-40357 Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows… Archer Ax50 Firmware 230508 / 230523+ Fix from $1,9502023-09-06 HIGH 8.0 CVE-2023-31188 Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows… Archer C55 Firmware 230505 / 230506+ Fix from $1,9502023-09-06 HIGH 8.8 CVE-2023-36489 Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follo… Tl Wr902ac Firmware 221008 / 230506+ Fix from $1,9502023-09-06