Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2024-48895 Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware version V1.3.18 … Mitigation only Fix from $1,9502024-11-20 HIGH 8.8 CVE-2024-51503 A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges… Deep Security Agent Mitigation only Fix from $1,9502024-11-19 HIGH 7.8 CVE-2024-10224EPSS 9% Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute … Debian Linux 1.36+ Fix from $1,9502024-11-19 HIGH 7.8 CVE-2024-11003EPSS 11% Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input. This could… Needrestart 3.8+ Fix from $1,9502024-11-19 HIGH 8.8 CVE-2024-52587 StepSecurity's Harden-Runner provides network egress filtering and runtime security for GitHub-hosted and self-hosted runners. Versions of step-secur… Patch available Fix from $1,9502024-11-18 HIGH 7.2 CVE-2024-9474 KEVEPSS 95% A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface … Pan Os 10.1.14 / 10.2.12+ Fix from $1,9502024-11-18 HIGH 7.5 CVE-2024-44759 An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arb… Nus M9 Erp Mitigation only Fix from $1,9502024-11-15 HIGH 7.5 CVE-2024-24426 Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cau… Mitigation only Fix from $1,9502024-11-15 HIGH 7.5 CVE-2024-24431 A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS pack… Open5gs No fix yet Fix from $1,9502024-11-15 CRITICAL 9.9 CVE-2023-20036EPSS 13% A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges… Industrial Network Director 1.11.3+ Fix from $2,3002024-11-15 HIGH 8.8 CVE-2022-20871 A vulnerability in the web management interface of Cisco&nbsp;AsyncOS for Cisco&nbsp;Secure Web Appliance, formerly Cisco&nbsp;Web Security Appliance… Asyncos Mitigation only Fix from $1,9502024-11-15 MEDIUM 6.5 CVE-2022-20652 A vulnerability in the web-based management interface and in the API subsystem of Cisco&nbsp;Tetration could allow an authenticated, remote attacker … Mitigation only Fix from $1,6002024-11-15 HIGH 8.8 CVE-2022-20655 A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command … Mitigation only Fix from $1,9502024-11-15 CRITICAL 9.8 CVE-2024-10443EPSS 28% Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePho… Photos 1.0.2-10026 / 1.1.0-10053+ Fix from $2,3002024-11-15 CRITICAL 9.8 CVE-2022-1884 A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to imp… Gogs after 0.12.7 Fix from $2,3002024-11-15 CRITICAL 9.8 CVE-2024-11120 KEVEPSS 29% Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject a… Gv Vs12 Firmware Mitigation only Fix from $2,3002024-11-15 CRITICAL 9.8 CVE-2024-4343 A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/components/llm/custom/sagemak… Privategpt 0.6.0+ Fix from $2,3002024-11-14 HIGH 8.8 CVE-2024-50852 Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function. G3 Firmware No fix yet Fix from $1,9502024-11-13 HIGH 8.8 CVE-2024-50853 Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function. G3 Firmware No fix yet Fix from $1,9502024-11-13 MEDIUM 6.7 CVE-2024-32118 Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager… Fortianalyzer 7.2.6 / 7.2.8+ Fix from $1,6002024-11-12 HIGH 8.6 CVE-2024-52010 Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. A command injection vulnerability in the Web SSH feature allows an authenticated … Patch available Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-11005 Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap… Connect Secure 9.1 / 22.7+ Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-11006 Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap… Connect Secure 9.1 / 22.7+ Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-11007 Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap… Connect Secure 22.7+ Fix from $1,9502024-11-12 CRITICAL 9.1 CVE-2024-46890 A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent t… Sinec Ins 1.0+ Fix from $2,3002024-11-12 HIGH 8.0 CVE-2024-45827 Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Mesh Wi-Fi router RP562B firmware version … Mitigation only Fix from $1,9502024-11-12 MEDIUM 6.8 CVE-2024-8881 A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier c… Gs1900 8 Firmware 2.90+ Fix from $1,6002024-11-12 CRITICAL 9.8 CVE-2024-36061 EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metac… Ews356 Fit Firmware after 1.1.30 Fix from $2,3002024-11-11 HIGH 7.2 CVE-2024-11065 The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute ar… Dsl6740c Firmware Mitigation only Fix from $1,9502024-11-11 HIGH 7.2 CVE-2024-11066 The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute ar… Dsl6740c Firmware Mitigation only Fix from $1,9502024-11-11