Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Emc Powerscale Onefs MEDIUM 6.7
CVE-2022-45095

Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privile…

Fix: 9.1.0.25 / 9.2.1.18+
Fix from $1,600 2023-02-01
Nemo Appium CRITICAL 9.8
CVE-2022-21129

Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup'…

Fix: 0.0.9+
Fix from $2,300 2023-01-31
Pdfbook CRITICAL 9.8
CVE-2023-24612

The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an option.

Fix: after 2.0.5
Fix from $2,300 2023-01-30
Magento HIGH 7.2
CVE-2021-41231

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and…

Fix: 19.4.22 / 20.0.19+
Fix from $1,950 2023-01-27
Magento HIGH 7.2
CVE-2021-41143

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute co…

Fix: 19.4.22 / 20.0.19+
Fix from $1,950 2023-01-27
Magento HIGH 8.8
CVE-2021-41144

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the block blacklist to execute remot…

Fix: 19.4.22 / 20.0.19+
Fix from $1,950 2023-01-27
Magento HIGH 7.2
CVE-2021-39217

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via bl…

Fix: 19.4.22 / 20.0.19+
Fix from $1,950 2023-01-27
Vagrant.js CRITICAL 9.8
CVE-2022-25962

All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.

Mitigation only
Fix from $2,300 2023-01-26
Create Choo Electron CRITICAL 9.8
CVE-2022-25908

All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitiza…

No fix yet
Fix from $2,300 2023-01-26
Puppet Facter HIGH 7.8
CVE-2022-25350

All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.

No fix yet
Fix from $1,950 2023-01-26
Smartctl HIGH 7.8
CVE-2022-21810

All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization.

No fix yet
Fix from $1,950 2023-01-26
Airflow CRITICAL 9.8
CVE-2023-22884EPSS 11%

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach…

Fix: 2.5.1 / 4.0.0+
Fix from $2,300 2023-01-21
R310 Firmware HIGH 7.5
CVE-2020-22662

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10…

Fix: 3.6.2.0.795+
Fix from $1,950 2023-01-20
Rv160 Vpn Router Firmware HIGH 7.2
CVE-2023-20045

A vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticated, remote…

Fix: 1.0.01.04+
Fix from $1,950 2023-01-20
Rv016 Firmware HIGH 7.2
CVE-2023-20026

A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320 and RV325 Routers could allow an aut…

Mitigation only
Fix from $1,950 2023-01-20
Froxlor HIGH 8.8
CVE-2023-0315EPSS 98%

Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.

Fix: 2.0.8+
Fix from $1,950 2023-01-16
Netdata CRITICAL 9.8
CVE-2023-22496EPSS 36%

Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the ability to establish a streaming c…

Fix: 1.37.0+
Fix from $2,300 2023-01-14
Autolab HIGH 8.8
CVE-2022-41955

Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer au…

Fix: 2.10.0+
Fix from $1,950 2023-01-14
Global Modules Path CRITICAL 9.8
CVE-2022-21191

Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sa…

Fix: 3.0.0+
Fix from $2,300 2023-01-13
Dx 3021l9 Firmware CRITICAL 9.1
CVE-2022-4616

The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This vulnerability cou…

Fix: 1.24+
Fix from $2,300 2023-01-13
Gry HIGH 8.0
CVE-2020-36650

A vulnerability, which was classified as critical, was found in IonicaBizau node-gry up to 5.x. This affects an unknown part. The manipulation leads …

Fix: 6.0.0+
Fix from $1,950 2023-01-11
Sinec Ins HIGH 8.8
CVE-2022-45094

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Ma…

Fix: 1.0+
Fix from $1,950 2023-01-10
Mf286r Firmware CRITICAL 9.8
CVE-2022-39073

There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerabi…

Mitigation only
Fix from $2,300 2023-01-06
Jobe CRITICAL 9.8
CVE-2020-36642

A vulnerability was found in trampgeek jobe up to 1.6.x and classified as critical. This issue affects the function run_in_sandbox of the file applic…

Fix: 1.7.0+
Fix from $2,300 2023-01-06
Ghidra CRITICAL 9.8
CVE-2023-22671

Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when ca…

Fix: after 10.2.2
Fix from $2,300 2023-01-06
Exec Local Bin CRITICAL 9.8
CVE-2022-25923

Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input…

Fix: 1.2.0+
Fix from $2,300 2023-01-06
Ulcc Core CRITICAL 9.8
CVE-2021-4304

A vulnerability was found in eprintsug ulcc-core. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the…

Fix: 2021-02-05+
Fix from $2,300 2023-01-05
Android MEDIUM 6.7
CVE-2022-39086

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39087

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

Mitigation only
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39088

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

Mitigation only
Fix from $1,600 2023-01-04