Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Dsl 224 Firmware CRITICAL 9.9
CVE-2022-36786

DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc AP…

Mitigation only
Fix from $2,300 2022-11-17
Solarview Compact Firmware CRITICAL 9.8
CVE-2022-40881EPSS 29%

SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php

No fix yet
Fix from $2,300 2022-11-17
Bitbucket CRITICAL 9.8
CVE-2022-43781EPSS 98%

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control th…

Fix: 7.6.19 / 7.17.12+
Fix from $2,300 2022-11-17
Infosphere Information Server CRITICAL 9.8
CVE-2022-40752

IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: …

Patch available
Fix from $2,300 2022-11-16
Secure Firewall Threat Defense MEDIUM 6.7
CVE-2022-20934

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to e…

Fix: after 7.0.4
Fix from $1,600 2022-11-15
Secure Firewall Management Center HIGH 7.2
CVE-2022-20925

A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker…

Mitigation only
Fix from $1,950 2022-11-15
Secure Firewall Management Center HIGH 8.8
CVE-2022-20926

A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker…

Mitigation only
Fix from $1,950 2022-11-15
Fedora CRITICAL 9.8
CVE-2022-45063

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within …

Fix: 375+
Fix from $2,300 2022-11-10
Dir 823g Firmware CRITICAL 9.8
CVE-2022-43109

D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows…

No fix yet
Fix from $2,300 2022-11-03
Opennebula CRITICAL 9.8
CVE-2022-37425

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remot…

Fix: 6.4.2+
Fix from $2,300 2022-10-28
Ew9 Firmware CRITICAL 9.8
CVE-2022-43367EPSS 5%

IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.

No fix yet
Fix from $2,300 2022-10-27
R1510 Firmware HIGH 7.5
CVE-2022-35265

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…

No fix yet
Fix from $1,950 2022-10-25
R1510 Firmware HIGH 7.5
CVE-2022-35266

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…

No fix yet
Fix from $1,950 2022-10-25
R1510 Firmware HIGH 7.5
CVE-2022-35267

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…

No fix yet
Fix from $1,950 2022-10-25
R1510 Firmware HIGH 7.5
CVE-2022-35269

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…

No fix yet
Fix from $1,950 2022-10-25
R1510 Firmware HIGH 7.5
CVE-2022-35270

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…

No fix yet
Fix from $1,950 2022-10-25
R1510 Firmware HIGH 7.5
CVE-2022-35271

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…

No fix yet
Fix from $1,950 2022-10-25
R1510 Firmware CRITICAL 9.8
CVE-2022-32765

An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafte…

No fix yet
Fix from $2,300 2022-10-25
Iac Ast2500a Firmware CRITICAL 9.8
CVE-2021-26727

Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker…

Mitigation only
Fix from $2,300 2022-10-24
Iac Ast2500a Firmware CRITICAL 9.8
CVE-2021-26728

Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arb…

Mitigation only
Fix from $2,300 2022-10-24
Iac Ast2500a Firmware CRITICAL 9.8
CVE-2021-26729

Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker t…

Mitigation only
Fix from $2,300 2022-10-24
Iac Ast2500a Firmware CRITICAL 9.8
CVE-2021-26731

Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticate…

Mitigation only
Fix from $2,300 2022-10-24
Big Ip Advanced Web Application Firewall HIGH 7.2
CVE-2022-41617

In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is…

Fix: 13.1.5.1 / 14.1.5.1+
Fix from $1,950 2022-10-19
Dsl 2750b Firmware CRITICAL 9.8
CVE-2016-20017 KEVEPSS 65%

D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016…

Fix: 1.05+
Fix from $2,300 2022-10-19
Covr 1203 Firmware HIGH 8.8
CVE-2022-42156

D-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at function SetNetwo…

No fix yet
Fix from $1,950 2022-10-13
Covr 1203 Firmware HIGH 8.8
CVE-2022-42160

D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the system_time_timezone parameter at function SetNT…

No fix yet
Fix from $1,950 2022-10-13
Covr 1203 Firmware HIGH 8.8
CVE-2022-42161

D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the /SetTriggerWPS/PIN parameter at function SetTrig…

No fix yet
Fix from $1,950 2022-10-13
Debian Linux HIGH 7.8
CVE-2022-42906

powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration…

Fix: 1.3.2+
Fix from $1,950 2022-10-13
Arrayos Ag CRITICAL 9.8
CVE-2022-42897

Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of th…

Fix: after 9.4.0.469
Fix from $2,300 2022-10-13
Hybrid Client HIGH 8.2
CVE-2022-34432

Dell Hybrid Client below 1.8 version contains a gedit vulnerability. A guest attacker could potentially exploit this vulnerability, allowing deletion…

Fix: 1.8+
Fix from $1,950 2022-10-11