Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2023-28400EPSS 25% mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. Mypro after 8.26.0 Fix from $1,9502023-04-27 HIGH 8.8 CVE-2023-28716 mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. Mypro after 8.26.0 Fix from $1,9502023-04-27 CRITICAL 9.8 CVE-2023-25313 OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link … Avideo 12.4+ Fix from $2,3002023-04-25 CRITICAL 9.8 CVE-2023-28771 KEVEPSS 99% Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG F… Atp100 Firmware 5.35 / 5.36+ Fix from $2,3002023-04-25 HIGH 8.8 CVE-2023-30628 Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and prior, the `changelog.yml` wor… Kiwi Tcms after 12.2 Fix from $1,9502023-04-24 HIGH 8.8 CVE-2023-27991 The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series f… Atp200 Firmware 5.36+ Fix from $1,9502023-04-24 HIGH 8.8 CVE-2023-25507 NVIDIA DGX-1 BMC contains a vulnerability in the SPX REST API, where an attacker with the appropriate level of authorization can inject arbitrary she… Bmc 3.39.30+ Fix from $1,9502023-04-22 CRITICAL 9.8 CVE-2023-30621 Gipsy is a multi-purpose discord bot which aim to be as modular and user-friendly as possible. In versions prior to 1.3 users can run command on the … Gipsy after 1.3 Fix from $2,3002023-04-21 CRITICAL 9.8 CVE-2023-2131 Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary co… Me Rtu Firmware 3.36+ Fix from $2,3002023-04-20 MEDIUM 5.4 CVE-2023-25759 OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to run unprivil… Tripleplay Mitigation only Fix from $1,6002023-04-19 CRITICAL 9.8 CVE-2023-29412 CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code … Apc Easy Ups Online Monitoring Software after 2.5-gs-01-22320 Fix from $2,3002023-04-18 HIGH 7.8 CVE-2023-25554 A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privile… Struxureware Data Center Expert after 7.9.2 Fix from $1,9502023-04-18 HIGH 8.1 CVE-2023-25555 A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user tha… Struxureware Data Center Expert after 7.9.2 Fix from $1,9502023-04-18 HIGH 8.8 CVE-2023-28983 An OS Command Injection vulnerability in gRPC Network Operations Interface (gNOI) server module of Juniper Networks Junos OS Evolved allows an authen… Junos Os Evolved Mitigation only Fix from $1,9502023-04-17 CRITICAL 9.8 CVE-2021-33990EPSS 12% Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue b… Liferay Portal No fix yet Fix from $2,3002023-04-16 HIGH 8.8 CVE-2022-38841EPSS 11% Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page. E8450 Firmware No fix yet Fix from $1,9502023-04-16 HIGH 7.8 CVE-2023-2091 A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerability is the function adjust_cpuf… Youker Assistant 3.1.4.13+ Fix from $1,9502023-04-15 HIGH 8.8 CVE-2023-29804EPSS 17% WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function. Wfs Sr03w Firmware No fix yet Fix from $1,9502023-04-14 CRITICAL 9.8 CVE-2023-29805 WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function. Wfs Sr03w Firmware No fix yet Fix from $2,3002023-04-14 HIGH 8.8 CVE-2023-27216 An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page. Dsl 3782 Firmware Mitigation only Fix from $1,9502023-04-12 HIGH 8.8 CVE-2023-27826EPSS 12% SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attacker… Swc 5100w Firmware No fix yet Fix from $1,9502023-04-12 HIGH 7.8 CVE-2022-40679 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all v… Fortiadc 5.7.0 / 6.1.5+ Fix from $1,9502023-04-11 HIGH 7.8 CVE-2022-43948 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.3, FortiA… Fortiadc 6.2.6 / 7.0.4+ Fix from $1,9502023-04-11 HIGH 8.8 CVE-2023-27917 OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenance page t… Cps Mg341 Adsc1 111 Firmware after 3.7.10 Fix from $1,9502023-04-11 CRITICAL 9.8 CVE-2023-27076EPSS 23% Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter. G103 Firmware No fix yet Fix from $2,3002023-04-10 MEDIUM 6.7 CVE-2023-20153 Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform comman… Identity Services Engine Mitigation only Fix from $1,6002023-04-05 MEDIUM 6.7 CVE-2023-20121 Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisc… Evolved Programmable Network Manager 3.10.4 / 7.0.1+ Fix from $1,6002023-04-05 HIGH 7.8 CVE-2023-20122 Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisc… Identity Services Engine Mitigation only Fix from $1,9502023-04-05 HIGH 7.2 CVE-2023-20117EPSS 28% Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an au… Rv320 Firmware Mitigation only Fix from $1,9502023-04-05 MEDIUM 6.7 CVE-2023-20152 Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform comman… Identity Services Engine Mitigation only Fix from $1,6002023-04-05