Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Android MEDIUM 6.7
CVE-2022-39081

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39082

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39083

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39084

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39085

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

No fix yet
Fix from $1,600 2023-01-04
Linkit Software Development Kit HIGH 8.8
CVE-2022-32664

In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with Use…

Fix: 7.3.293.0+
Fix from $1,950 2023-01-03
Linkit Software Development Kit CRITICAL 9.8
CVE-2022-32665

In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional …

Mitigation only
Fix from $2,300 2023-01-03
Printer CRITICAL 9.8
CVE-2017-20156

A vulnerability was found in Exciting Printer and classified as critical. This issue affects some unknown processing of the file lib/printer/jobs/pre…

Fix: 2017-07-08+
Fix from $2,300 2022-12-31
Kylin CRITICAL 9.8
CVE-2022-44621

Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.

Fix: 4.0.3+
Fix from $2,300 2022-12-30
Dir 846 Firmware CRITICAL 9.9
CVE-2022-46642

D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the SetAutoUpgradeInfo …

No fix yet
Fix from $2,300 2022-12-23
Dir 846 Firmware CRITICAL 9.9
CVE-2022-46641

D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindS…

No fix yet
Fix from $2,300 2022-12-23
Activitywatch CRITICAL 9.6
CVE-2021-32692

Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macO…

Fix: 0.11.0+
Fix from $2,300 2022-12-23
Thunderbird HIGH 8.8
CVE-2020-15685

During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. T…

Fix: 78.7.0+
Fix from $1,950 2022-12-22
Apache Airflow Providers Apache Hive CRITICAL 9.8
CVE-2022-46421

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive P…

Fix: 5.0.0+
Fix from $2,300 2022-12-20
Bp 30c25 Firmware HIGH 7.2
CVE-2022-45796

Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlie…

Mitigation only
Fix from $1,950 2022-12-16
Vrealize Network Insight CRITICAL 9.8
CVE-2022-31702

vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the…

Patch available
Fix from $2,300 2022-12-14
Dir 3040 Firmware CRITICAL 9.8
CVE-2022-44832

D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.

No fix yet
Fix from $2,300 2022-12-14
Unify Openscape 4000 Assistant CRITICAL 9.8
CVE-2022-46404

A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 …

Mitigation only
Fix from $2,300 2022-12-13
Flir Ax8 Firmware CRITICAL 9.8
CVE-2022-4364

A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of th…

Fix: 1.46.16+
Fix from $2,300 2022-12-08
Big Ip Access Policy Manager HIGH 8.7
CVE-2022-41800EPSS 66%

In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode…

Fix: after 17.0.0
Fix from $1,950 2022-12-07
Uc 8580 T Lx Firmware HIGH 7.6
CVE-2022-3086

Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentia…

Fix: after 1.2
Fix from $1,950 2022-12-02
Orion Platform HIGH 7.2
CVE-2022-36962EPSS 9%

SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds data…

Fix: 2020.2.6+
Fix from $1,950 2022-11-29
Hirschmann Bat C2 Firmware HIGH 8.8
CVE-2022-40282

The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass comma…

Fix: 09.13.00r04+
Fix from $1,950 2022-11-25
Dolphinscheduler CRITICAL 9.8
CVE-2022-45462

Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade…

Fix: 2.0.6+
Fix from $2,300 2022-11-23
Manageengine Servicedesk Plus HIGH 7.2
CVE-2022-40770EPSS 81%

Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileg…

Fix: 10.6 / 11.0+
Fix from $1,950 2022-11-23
Op Xt71000n Firmware CRITICAL 9.8
CVE-2020-23584EPSS 41%

Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDR…

Mitigation only
Fix from $2,300 2022-11-23
Op Xt71000n Firmware CRITICAL 9.8
CVE-2020-23583

OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp…

Mitigation only
Fix from $2,300 2022-11-23
Mivoice Connect MEDIUM 6.8
CVE-2022-40765 KEVEPSS 10%

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with interna…

Fix: after 22.22.6100.0
Fix from $1,600 2022-11-22
I Access Client Solutions MEDIUM 6.7
CVE-2022-40746

IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the syste…

Fix: after 1.1.9.0
Fix from $1,600 2022-11-21
Manageengine Admanager Plus HIGH 7.2
CVE-2022-42904EPSS 83%

Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.

Fix: 7.1+
Fix from $1,950 2022-11-18