Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2024-54082 home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore function. An arbitrary OS command ma… Mitigation only Fix from $1,9502024-12-23 HIGH 7.8 CVE-2020-13712 A command injection is possible through the user interface, allowing arbitrary command execution as the root user. oMG2000 running MGOS 3.15.1 or ea… Mitigation only Fix from $1,9502024-12-20 HIGH 8.8 CVE-2024-28767 IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary c… Security Directory Integrator after 10.0.3 Fix from $1,9502024-12-20 HIGH 8.8 CVE-2024-12829 Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit… Ng Firewall Mitigation only Fix from $1,9502024-12-20 HIGH 7.8 CVE-2021-26115 An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unpriv… Fortiwan 4.5.8+ Fix from $1,9502024-12-19 HIGH 7.2 CVE-2023-23356 A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow rem… Qufirewall 2.3.3+ Fix from $1,9502024-12-19 HIGH 7.2 CVE-2024-12686 KEVEPSS 14% A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrativ… Privileged Remote Access after 24.3.1 Fix from $1,9502024-12-18 HIGH 7.2 CVE-2024-48889 An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, v… Fortimanager 6.4.15 / 7.0.13+ Fix from $1,9502024-12-18 HIGH 7.2 CVE-2024-53688 Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in AE1021 firmware versions 2.0.10 and earlie… Mitigation only Fix from $1,9502024-12-18 CRITICAL 9.1 CVE-2024-31668 rizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set function in librz/analysis/meta. Rizin 0.6.3+ Fix from $2,3002024-12-17 HIGH 8.8 CVE-2024-53376EPSS 11% CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the web… Cyberpanel 2.3.8+ Fix from $1,9502024-12-16 HIGH 7.8 CVE-2024-11858 A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Applicatio… Radare2 after 5.9.8 Fix from $1,9502024-12-15 MEDIUM 6.5 CVE-2024-48008 Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially explo… Recoverpoint For Virtual Machines Mitigation only Fix from $1,6002024-12-13 HIGH 8.8 CVE-2024-22461 Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially explo… Recoverpoint For Virtual Machines Mitigation only Fix from $1,9502024-12-13 HIGH 7.8 CVE-2024-52058 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in RTI Connext Professional (System Designer… Connext Professional 6.1.2.19 / 7.3.0.2+ Fix from $1,9502024-12-13 HIGH 7.2 CVE-2024-54008 An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a rem… Mitigation only Fix from $1,9502024-12-10 HIGH 7.3 CVE-2024-28138 An unauthenticated attacker with network access to the affected device's web interface can execute any system command via the "msg_events.php" script… Mitigation only Fix from $1,9502024-12-10 HIGH 8.8 CVE-2024-12358 A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. … Datax Web No fix yet Fix from $1,9502024-12-09 HIGH 7.8 CVE-2024-47115 IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input. Vios Mitigation only Fix from $1,9502024-12-07 CRITICAL 9.8 CVE-2024-52320 The affected product is vulnerable to a command injection. An unauthenticated attacker could send commands through a malicious HTTP request which cou… Mitigation only Fix from $2,3002024-12-06 CRITICAL 9.8 CVE-2024-50388 An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attack… Hybrid Backup Sync Mitigation only Fix from $2,3002024-12-06 CRITICAL 9.8 CVE-2024-50393 A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow rem… Qts Mitigation only Fix from $2,3002024-12-06 CRITICAL 9.8 CVE-2024-48863 A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute… License Center 1.9.43+ Fix from $2,3002024-12-06 HIGH 7.2 CVE-2024-47133 UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administrative accou… Mitigation only Fix from $1,9502024-12-05 HIGH 8.8 CVE-2024-51465 IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authenticated attacker to execute ar… App Connect Enterprise Certified Container 12.4+ Fix from $1,9502024-12-04 HIGH 7.2 CVE-2024-9200 A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions thro… Emg6726 B10a Firmware 5.13 / 5.15+ Fix from $1,9502024-12-03 HIGH 8.0 CVE-2024-53375EPSS 41% An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exists in the "tmp_get_sites" fu… Mitigation only Fix from $1,9502024-12-02 HIGH 8.8 CVE-2024-53939 An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq… Mitigation only Fix from $1,9502024-12-02 HIGH 8.8 CVE-2024-53940 An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /cgi-bin/luci/admin endpoints … Mitigation only Fix from $1,9502024-12-02 HIGH 8.8 CVE-2024-53992 unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malicious commands that are execut… Patch available Fix from $1,9502024-12-02