Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2022-48586 A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it … Sl1 after 11.1.2 Fix from $1,9502023-08-09 HIGH 8.8 CVE-2022-48580 A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and… Sl1 after 11.1.2 Fix from $1,9502023-08-09 HIGH 8.8 CVE-2022-48581 A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes… Sl1 after 11.1.2 Fix from $1,9502023-08-09 HIGH 7.2 CVE-2023-38208 Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Improper Neutralization of Speci… Commerce 2.4.4+ Fix from $1,9502023-08-09 HIGH 8.8 CVE-2023-37861 In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions wit… Wp 6070 Wvps Firmware 4.0.10+ Fix from $1,9502023-08-09 HIGH 7.2 CVE-2023-37863 In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP re… Wp 6070 Wvps Firmware 4.0.10+ Fix from $1,9502023-08-09 HIGH 8.8 CVE-2023-37569EPSS 34% This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated … Emagic Data Center Management after 6.0 Fix from $1,9502023-08-08 HIGH 8.8 CVE-2023-3570 In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE reques… Wp 6070 Wvps Firmware 4.0.10+ Fix from $1,9502023-08-08 HIGH 8.8 CVE-2023-3571 In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP POST releated… Wp 6070 Wvps Firmware 4.0.10+ Fix from $1,9502023-08-08 CRITICAL 10.0 CVE-2023-3572 In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP … Wp 6070 Wvps Firmware 4.0.10+ Fix from $2,3002023-08-08 HIGH 8.8 CVE-2023-3573 In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP… Wp 6070 Wvps Firmware 4.0.10+ Fix from $1,9502023-08-08 CRITICAL 9.8 CVE-2023-38692 CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the… Cloudexplorer Lite 1.3.1+ Fix from $2,3002023-08-04 CRITICAL 9.8 CVE-2023-33374 Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands f… Connected Io after 2.1.0 Fix from $2,3002023-08-04 CRITICAL 9.8 CVE-2023-33377 Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, enabling a… Connected Io after 2.1.0 Fix from $2,3002023-08-04 HIGH 8.8 CVE-2023-33364 An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to execute arbitrary OS commands on… Biostar 2 2.9.1+ Fix from $1,9502023-08-03 HIGH 8.8 CVE-2023-21411 User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution. License Plate Verifier after 2.8.3 Fix from $1,9502023-08-03 HIGH 8.8 CVE-2023-21410 User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution. License Plate Verifier after 2.8.3 Fix from $1,9502023-08-03 CRITICAL 9.8 CVE-2023-26317 Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external… Xiaomi Router Firmware 2023.2+ Fix from $2,3002023-08-02 HIGH 7.8 CVE-2023-31425 A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local a… Fabric Operating System Mitigation only Fix from $1,9502023-08-01 HIGH 7.8 CVE-2023-4033 OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0. Mlflow 2.6.0+ Fix from $1,9502023-08-01 CRITICAL 9.8 CVE-2023-35861 A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to injec… H12dst B Firmware 03.10.35+ Fix from $2,3002023-07-31 HIGH 8.8 CVE-2023-35019 IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by send… Security Verify Governance Mitigation only Fix from $1,9502023-07-31 CRITICAL 9.8 CVE-2023-37213 Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection' Synergy\/a Firmware 3015.1+ Fix from $2,3002023-07-30 CRITICAL 9.8 CVE-2023-3974 OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0. Drawio 21.4.0+ Fix from $2,3002023-07-27 CRITICAL 9.8 CVE-2023-3975 OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0. Drawio 21.5.0+ Fix from $2,3002023-07-27 CRITICAL 9.8 CVE-2023-38673 PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system. Paddlepaddle 2.5.0+ Fix from $2,3002023-07-26 HIGH 7.2 CVE-2023-38056 Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows … Otrs 7.0.45 / 8.0.35+ Fix from $1,9502023-07-24 CRITICAL 10.0 CVE-2023-37903 vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to esc… Vm2 after 3.9.19 Fix from $2,3002023-07-21 CRITICAL 9.8 CVE-2023-37292 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modul… Isherlock 4.5-174 / 5.5-174+ Fix from $2,3002023-07-21 CRITICAL 9.8 CVE-2023-36670 A remotely exploitable command injection vulnerability was found on the Kratos NGC-IDU 9.1.0.4. An attacker can execute arbitrary Linux commands as r… Ngc Indoor Unit Firmware Mitigation only Fix from $2,3002023-07-18