Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2023-37477EPSS 6% 1Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability exists in 1Panel firewall fun… 1panel 1.4.3+ Fix from $1,9502023-07-18 CRITICAL 9.8 CVE-2020-36762 A vulnerability was found in ONS Digital RAS Collection Instrument up to 2.0.27 and classified as critical. Affected by this issue is the function jo… Ras Collection Instrument 2.0.28+ Fix from $2,3002023-07-18 HIGH 8.8 CVE-2023-33012EPSS 10% A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series fi… Usg 20w Vpn Firmware 5.37+ Fix from $1,9502023-07-17 HIGH 8.0 CVE-2023-34138 A command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USG FLEX ser… Usg 20w Vpn Firmware 5.37+ Fix from $1,9502023-07-17 HIGH 8.8 CVE-2023-34139 A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and … Usg 2200 Vpn Firmware 5.37+ Fix from $1,9502023-07-17 HIGH 8.0 CVE-2023-34141 A command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions 5.00 through 5.36 Patch 2, US… Usg 20w Vpn Firmware 5.37+ Fix from $1,9502023-07-17 HIGH 8.8 CVE-2023-28767 The configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX series firmwar… Usg 2200 Vpn Firmware 5.37+ Fix from $1,9502023-07-17 CRITICAL 9.8 CVE-2023-38378 The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to execute arbitrary code via shell … Mso5000 Firmware No fix yet Fix from $2,3002023-07-16 HIGH 8.0 CVE-2023-37564 OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute an arbitrary OS command… Wrc 1167ghbk S Firmware after 1.24 Fix from $1,9502023-07-13 HIGH 8.8 CVE-2023-34127EPSS 86% Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enable… Analytics 9.3.2+ Fix from $1,9502023-07-13 HIGH 8.8 CVE-2023-34116 Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of priv… Zoom 5.15.0+ Fix from $1,9502023-07-11 HIGH 7.2 CVE-2023-23777 An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0.1 and be… Fortiweb after 6.4.3 Fix from $1,9502023-07-11 HIGH 8.8 CVE-2023-36922 Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arb… Netweaver Mitigation only Fix from $1,9502023-07-11 HIGH 8.8 CVE-2023-3608EPSS 12% A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracer… Bcr810w Firmware No fix yet Fix from $1,9502023-07-10 HIGH 8.8 CVE-2023-3606EPSS 7% A vulnerability was found in TamronOS up to 20230703. It has been classified as critical. This affects an unknown part of the file /api/ping. The man… Tamronos after 20230703 Fix from $1,9502023-07-10 HIGH 8.0 CVE-2023-3607EPSS 6% A vulnerability was found in kodbox 1.26. It has been declared as critical. This vulnerability affects the function Execute of the file webconsole.ph… Kodbox No fix yet Fix from $1,9502023-07-10 HIGH 7.2 CVE-2021-42081 An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC http://<IP_ADDRESS>/qstorapi/storageSystemMo… Quantastor 6.0.0.355+ Fix from $1,9502023-07-10 CRITICAL 9.8 CVE-2023-37170 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the lang parameter… A3300r Firmware No fix yet Fix from $2,3002023-07-07 CRITICAL 9.8 CVE-2023-37171 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg f… A3300r Firmware No fix yet Fix from $2,3002023-07-07 CRITICAL 9.8 CVE-2023-37172 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg funct… A3300r Firmware No fix yet Fix from $2,3002023-07-07 CRITICAL 9.8 CVE-2023-37173 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg… A3300r Firmware No fix yet Fix from $2,3002023-07-07 HIGH 7.2 CVE-2023-25582 Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request… Ur32l Firmware No fix yet Fix from $1,9502023-07-06 HIGH 7.2 CVE-2023-25583 Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request… Ur32l Firmware No fix yet Fix from $1,9502023-07-06 HIGH 8.8 CVE-2023-24519 Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-craf… Ur32l Firmware No fix yet Fix from $1,9502023-07-06 HIGH 8.8 CVE-2023-24520 Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-craf… Ur32l Firmware No fix yet Fix from $1,9502023-07-06 HIGH 8.8 CVE-2023-24582 Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted ne… Ur32l Firmware No fix yet Fix from $1,9502023-07-06 HIGH 7.2 CVE-2023-24595 An OS command injection vulnerability exists in the ys_thirdparty system_user_script functionality of Milesight UR32L v32.3.0.5. A specially crafted … Ur32l Firmware No fix yet Fix from $1,9502023-07-06 HIGH 8.1 CVE-2023-22371 An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2. A specially-crafted network… Milesightvpn No fix yet Fix from $1,9502023-07-06 HIGH 8.8 CVE-2023-22653EPSS 6% An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP … Ur32l Firmware No fix yet Fix from $1,9502023-07-06 HIGH 7.2 CVE-2023-22659 An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted netwo… Ur32l Firmware No fix yet Fix from $1,9502023-07-06