Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2025-20617 Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlie… Mitigation only Fix from $1,9502025-01-22 MEDIUM 6.6 CVE-2025-23237 Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlie… Mitigation only Fix from $1,6002025-01-22 HIGH 7.5 CVE-2023-37032 A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fe… Magma after 1.8.0 Fix from $1,9502025-01-21 HIGH 8.8 CVE-2024-57542 Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_btn. E8450 Firmware No fix yet Fix from $1,9502025-01-21 HIGH 7.2 CVE-2025-0528EPSS 6% A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown fun… Ac8 Firmware No fix yet Fix from $1,9502025-01-17 CRITICAL 9.3 CVE-2024-13502 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDirect NTC2218, NTC2250, NTC2299 … Mitigation only Fix from $2,3002025-01-17 HIGH 8.8 CVE-2025-0457 The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and exe… Mitigation only Fix from $1,9502025-01-16 HIGH 8.8 CVE-2024-57022 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in setWiFiScheduleC… X5000r Firmware No fix yet Fix from $1,9502025-01-15 MEDIUM 6.8 CVE-2024-57023 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCf… X5000r Firmware No fix yet Fix from $1,6002025-01-15 MEDIUM 6.8 CVE-2024-57024 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiSchedul… X5000r Firmware No fix yet Fix from $1,6002025-01-15 MEDIUM 6.8 CVE-2024-57025 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCf… X5000r Firmware No fix yet Fix from $1,6002025-01-15 HIGH 8.8 CVE-2024-57011 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg. X5000r Firmware No fix yet Fix from $1,9502025-01-15 HIGH 8.8 CVE-2024-57012 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setScheduleCfg. X5000r Firmware No fix yet Fix from $1,9502025-01-15 HIGH 8.8 CVE-2024-57013 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setScheduleCfg. X5000r Firmware No fix yet Fix from $1,9502025-01-15 HIGH 8.8 CVE-2024-57014 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScheduleCfg. X5000r Firmware No fix yet Fix from $1,9502025-01-15 HIGH 8.8 CVE-2024-57015 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg. X5000r Firmware No fix yet Fix from $1,9502025-01-15 HIGH 8.8 CVE-2024-57016 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in setVpnAccountCfg. X5000r Firmware No fix yet Fix from $1,9502025-01-15 HIGH 8.8 CVE-2024-57017 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg. X5000r Firmware No fix yet Fix from $1,9502025-01-15 HIGH 8.8 CVE-2024-57018 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAccountCfg. X5000r Firmware No fix yet Fix from $1,9502025-01-15 HIGH 8.8 CVE-2024-57019 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAccountCfg. X5000r Firmware No fix yet Fix from $1,9502025-01-15 HIGH 8.8 CVE-2024-57020 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute" parameter in setWiFiSchedul… X5000r Firmware No fix yet Fix from $1,9502025-01-15 HIGH 8.8 CVE-2024-57021 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleC… X5000r Firmware No fix yet Fix from $1,9502025-01-15 HIGH 7.2 CVE-2025-0356 NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arbitrary OS commands via the ne… Mitigation only Fix from $1,9502025-01-15 MEDIUM 6.7 CVE-2024-56497 An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and … Fortimail 6.4.5 / 6.4.8+ Fix from $1,6002025-01-14 HIGH 8.8 CVE-2024-48890 An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector vers… Fortisoar Imap Connector 3.5.8+ Fix from $1,9502025-01-14 HIGH 8.8 CVE-2024-50566 A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 throu… Fortimanager 7.2.8 / 7.2.9+ Fix from $1,9502025-01-14 MEDIUM 6.7 CVE-2024-40587 An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7… Fortivoice 6.4.10 / 7.0.5+ Fix from $1,6002025-01-14 HIGH 8.8 CVE-2024-27778 An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.… Fortisandbox 4.0.5 / 4.2.7+ Fix from $1,9502025-01-14 HIGH 7.8 CVE-2024-26012 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 throug… Fortiap 6.4.10 / 7.2.4+ Fix from $1,9502025-01-14 HIGH 7.8 CVE-2023-37937 An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through… Fortiswitch 6.2.8 / 6.4.14+ Fix from $1,9502025-01-14