Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2025-20016 OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporation. A user with an administra… Mitigation only Fix from $1,9502025-01-14 CRITICAL 9.8 CVE-2025-20055 OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340 provided by Y'S corporation. An attacker who can access the… Mitigation only Fix from $2,3002025-01-14 CRITICAL 9.8 CVE-2025-0107EPSS 79% An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-da… Expedition 1.2.101+ Fix from $2,3002025-01-11 CRITICAL 9.8 CVE-2024-12847EPSS 30% NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary… Dgn1000 Firmware 1.1.00.48+ Fix from $2,3002025-01-10 CRITICAL 9.8 CVE-2024-57687 An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote atta… Land Record System No fix yet Fix from $2,3002025-01-10 HIGH 8.8 CVE-2024-43654 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware for AC models allows OS Comm… Mitigation only Fix from $1,9502025-01-09 CRITICAL 9.3 CVE-2024-43655 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue aff… Mitigation only Fix from $2,3002025-01-09 HIGH 8.8 CVE-2024-43656 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue aff… Mitigation only Fix from $1,9502025-01-09 HIGH 8.8 CVE-2024-43657 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue aff… Mitigation only Fix from $1,9502025-01-09 HIGH 8.8 CVE-2024-43649 Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root user. This issue affects Ioch… Mitigation only Fix from $1,9502025-01-09 CRITICAL 9.3 CVE-2024-43650 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware for AC models allows OS Comma… Mitigation only Fix from $2,3002025-01-09 CRITICAL 9.3 CVE-2024-43651 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affe… Mitigation only Fix from $2,3002025-01-09 HIGH 8.8 CVE-2024-43652 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affe… Mitigation only Fix from $1,9502025-01-09 HIGH 8.8 CVE-2024-43653 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability  allows OS Command Injection as root This issue aff… Mitigation only Fix from $1,9502025-01-09 HIGH 8.8 CVE-2024-43648 Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root user. This issue affects Iochar… Mitigation only Fix from $1,9502025-01-09 CRITICAL 9.8 CVE-2024-50603 KEVEPSS 99% An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used… Controller 7.1.4191 / 7.2.4996+ Fix from $2,3002025-01-08 MEDIUM 6.8 CVE-2024-11681 A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running port selfupdate against the mirr… Macports 2.10.5+ Fix from $1,6002025-01-07 HIGH 8.8 CVE-2024-13129EPSS 18% A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of … Patch available Fix from $1,9502025-01-03 CRITICAL 9.8 CVE-2024-9140 Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability … Mitigation only Fix from $2,3002025-01-03 HIGH 7.2 CVE-2024-56137 MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large language model and retrieval-… Maxkb 1.9.0+ Fix from $1,9502025-01-02 HIGH 8.8 CVE-2024-12828EPSS 33% Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in… Webmin Patch available Fix from $1,9502024-12-30 HIGH 7.2 CVE-2024-54181 IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using sp… Websphere Automation Mitigation only Fix from $1,9502024-12-30 MEDIUM 6.1 CVE-2024-47918 Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Mitigation only Fix from $1,6002024-12-30 CRITICAL 9.8 CVE-2024-47919 Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') No fix yet Fix from $2,3002024-12-30 CRITICAL 9.8 CVE-2024-12987 KEVEPSS 98% A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file … Vigor300b Firmware Mitigation only Fix from $2,3002024-12-27 HIGH 7.2 CVE-2024-12856EPSS 82% The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 … F3x36 Firmware No fix yet Fix from $1,9502024-12-27 CRITICAL 9.8 CVE-2024-12986EPSS 33% A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown… Vigor300b Firmware 1.5.1.5+ Fix from $2,3002024-12-27 MEDIUM 6.3 CVE-2024-12985 A vulnerability classified as critical was found in Overtek OT-E801G OTE801G65.1.1.0. This vulnerability affects unknown code of the file /diag_ping.… Mitigation only Fix from $1,6002024-12-27 HIGH 7.8 CVE-2024-53256 Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code which suffered a command inje… Patch available Fix from $1,9502024-12-23 HIGH 7.2 CVE-2024-45721 home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST name configuration screen. An … Mitigation only Fix from $1,9502024-12-23