Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2023-23550 An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5. A specially crafted network… Ur32l Firmware No fix yet Fix from $1,9502023-07-06 HIGH 8.8 CVE-2023-22299 An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. A specially crafted network r… Ur32l Firmware No fix yet Fix from $1,9502023-07-06 HIGH 7.2 CVE-2023-22365 An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32.3.0.5. A specially crafted s… Ur32l Firmware Mitigation only Fix from $1,9502023-07-06 MEDIUM 6.8 CVE-2023-27198 PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the exec service and including a s… Pax A930 Firmware Mitigation only Fix from $1,6002023-07-05 HIGH 7.2 CVE-2023-36622 The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary… Miniserver Go Gen 2 Firmware 14.1.5.9+ Fix from $1,9502023-07-05 HIGH 8.8 CVE-2023-3314 A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands u… Enterprise Security Manager 11.6.7+ Fix from $1,9502023-07-03 HIGH 7.8 CVE-2023-3313 An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthor… Enterprise Security Manager 11.6.7+ Fix from $1,9502023-07-03 MEDIUM 6.7 CVE-2023-22815 Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in t… My Cloud Os 5.26.300+ Fix from $1,6002023-06-30 HIGH 8.8 CVE-2023-22816 A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to b… My Cloud Os 5.26.300+ Fix from $1,9502023-06-30 HIGH 7.2 CVE-2023-32622 Improper neutralization of special elements in WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to … Wl Wn531ax2 Firmware 2023526+ Fix from $1,9502023-06-30 HIGH 8.8 CVE-2023-36143 Maxprint Maxlink 1200G v3.4.11E has an OS command injection vulnerability in the "Diagnostic tool" functionality of the device. Maxlink 1200g Firmware Mitigation only Fix from $1,9502023-06-30 CRITICAL 9.8 CVE-2022-44720 An issue was discovered in Weblib Ucopia before 6.0.13. OS Command Injection injection can occur, related to chroot. Wireless Appliance Firmware 6.0.13+ Fix from $2,3002023-06-29 CRITICAL 9.8 CVE-2023-26613EPSS 31% An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system… Dir 823g Firmware No fix yet Fix from $2,3002023-06-29 HIGH 7.2 CVE-2023-3450EPSS 50% A vulnerability was found in Ruijie RG-BCR860 2.5.13 and classified as critical. This issue affects some unknown processing of the component Network … Rg Bcr860 Firmware No fix yet Fix from $1,9502023-06-28 HIGH 8.0 CVE-2023-2625 A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, having any le… Txpert Hub Coretec 4 Firmware 3.0.1+ Fix from $1,9502023-06-28 CRITICAL 9.8 CVE-2023-26134 Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails… Git Commit Info 2.0.2+ Fix from $2,3002023-06-28 HIGH 7.2 CVE-2023-3333 Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG… Aterm Wf300hp Firmware Mitigation only Fix from $1,9502023-06-28 HIGH 7.2 CVE-2023-34420 A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API. Xclarity Administrator 4.0.0+ Fix from $1,9502023-06-26 CRITICAL 9.8 CVE-2023-30261EPSS 32% Command Injection vulnerability in OpenWB 1.6 and 1.7 allows remote attackers to run arbitrary commands via crafted GET request. Openwb Patch available Fix from $2,3002023-06-26 HIGH 7.2 CVE-2023-34254 The GLPI Agent is a generic management agent. Prior to version 1.5, if glpi-agent is running remoteinventory task against an Unix platform with ssh c… Glpi Agent 1.5+ Fix from $1,9502023-06-23 CRITICAL 9.8 CVE-2023-30258EPSS 94% Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTT… Magnusbilling after 7.3.0 Fix from $2,3002023-06-23 CRITICAL 9.8 CVE-2023-35174 Livebook is a web application for writing interactive and collaborative code notebooks. On Windows, it is possible to open a `livebook://` link from … Livebook 0.8.2 / 0.9.3+ Fix from $2,3002023-06-22 HIGH 7.2 CVE-2023-24261EPSS 19% A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request. Gl E750 Firmware 3.216+ Fix from $1,9502023-06-21 CRITICAL 9.8 CVE-2023-33869 Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands. Envoy Firmware Mitigation only Fix from $2,3002023-06-20 CRITICAL 9.8 CVE-2023-27992 KEVEPSS 84% The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prio… Nas326 Firmware 5.21+ Fix from $2,3002023-06-19 HIGH 7.8 CVE-2023-34642 KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issue can all… Kioware after 8.33 Fix from $1,9502023-06-19 CRITICAL 9.8 CVE-2022-48472 A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected product versions… Bisheng Wnm Firmware Mitigation only Fix from $2,3002023-06-16 CRITICAL 9.8 CVE-2023-34800EPSS 29% D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main. Go Rt Ac750 Firmware No fix yet Fix from $2,3002023-06-15 HIGH 8.8 CVE-2022-32752 IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a remote authenticated attacker to execute arbitrary commands on the system by sen… Security Directory Suite Va after 8.0.1.19 Fix from $1,9502023-06-15 CRITICAL 9.8 CVE-2023-30764 OS command injection vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be exe… Kb Ahr04d Firmware 91110.1.101106.78 / 91210.1.101106.78+ Fix from $2,3002023-06-13