Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Mybb HIGH 7.2
CVE-2022-39265

MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, i…

Fix: 1.8.31+
Fix from $1,950 2022-10-06
Ios Xe HIGH 7.2
CVE-2022-20851

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against a…

Mitigation only
Fix from $1,950 2022-09-30
Innovaphone Firmware HIGH 7.2
CVE-2022-41870

AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload.

Fix: 13r2+
Fix from $1,950 2022-09-30
Nuprocess CRITICAL 9.8
CVE-2022-39243

NuProcess is an external process execution implementation for Java. In all the versions of NuProcess where it forks processes by using the JVM's Java…

Fix: 2.0.5+
Fix from $2,300 2022-09-26
I9 Firmware CRITICAL 9.8
CVE-2022-40100

Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function.

Mitigation only
Fix from $2,300 2022-09-23
Clearpass Policy Manager HIGH 7.2
CVE-2022-37879

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.12 / 6.10.7+
Fix from $1,950 2022-09-20
Clearpass Policy Manager HIGH 7.2
CVE-2022-37881

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.12 / 6.10.7+
Fix from $1,950 2022-09-20
Clearpass Policy Manager HIGH 7.2
CVE-2022-37883

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.12 / 6.10.7+
Fix from $1,950 2022-09-20
James HIGH 7.5
CVE-2022-28220

Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, …

Fix: after 3.6.2
Fix from $1,950 2022-09-08
Debian Linux HIGH 8.8
CVE-2022-3008

The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. T…

Fix: 2.6.0+
Fix from $1,950 2022-09-05
Dir 816 Firmware CRITICAL 9.8
CVE-2022-37125

D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.

No fix yet
Fix from $2,300 2022-08-31
Edge Gateway 5200 Firmware HIGH 8.2
CVE-2022-34383

Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A local malicious user may potentia…

Fix: 1.03.10+
Fix from $1,950 2022-08-31
Istar Ultra Firmware CRITICAL 9.8
CVE-2022-21941

All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to…

Fix: 6.8.9.cu01+
Fix from $2,300 2022-08-31
Hwl 2511 Ss Firmware CRITICAL 9.8
CVE-2022-36553EPSS 91%

Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.

Fix: after 1.05
Fix from $2,300 2022-08-29
Hwl 2511 Ss Firmware CRITICAL 9.8
CVE-2022-36554

A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to e…

Fix: after 1.05
Fix from $2,300 2022-08-29
Skybridge Mb A100 Firmware CRITICAL 9.8
CVE-2022-36556

Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08ex…

Fix: after 4.2.0
Fix from $2,300 2022-08-29
Skybridge Mb A200 Firmware CRITICAL 9.8
CVE-2022-36559

Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.

Fix: after 01.00.04
Fix from $2,300 2022-08-29
Mypro HIGH 8.8
CVE-2022-2234EPSS 41%

An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.

Fix: after 8.26.0
Fix from $1,950 2022-08-24
Go Rt Ac750 Firmware CRITICAL 9.8
CVE-2022-36523

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/upnpinc/gena.php.

Mitigation only
Fix from $2,300 2022-08-15
Toolkit MEDIUM 5.0
CVE-2022-35954

The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter…

Fix: 1.9.1+
Fix from $1,600 2022-08-15
Wn572hp3 Firmware CRITICAL 9.8
CVE-2022-35518

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to command injection …

No fix yet
Fix from $2,300 2022-08-10
Android HIGH 8.8
CVE-2022-20345

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execut…

Mitigation only
Fix from $1,950 2022-08-10
Teamcenter CRITICAL 9.8
CVE-2022-34660

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (…

Fix: 12.4.0.15 / 13.0.0.10+
Fix from $2,300 2022-08-10
Dir 810l Firmware CRITICAL 9.8
CVE-2022-34974EPSS 23%

D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function.

No fix yet
Fix from $2,300 2022-08-03
Monorepo Build CRITICAL 9.8
CVE-2020-28423

This affects all versions of package monorepo-build.

No fix yet
Fix from $2,300 2022-08-02
Curljs CRITICAL 9.8
CVE-2020-28425

This affects all versions of package curljs.

No fix yet
Fix from $2,300 2022-08-02
Node Latex Pdf CRITICAL 9.8
CVE-2020-28433

This affects all versions of package node-latex-pdf.

No fix yet
Fix from $2,300 2022-08-02
Gitblame CRITICAL 9.8
CVE-2020-28434

This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.

No fix yet
Fix from $2,300 2022-08-02
Heroku Env CRITICAL 9.8
CVE-2020-28437

This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.

No fix yet
Fix from $2,300 2022-08-02
Image Tiler CRITICAL 9.8
CVE-2020-28451

This affects the package image-tiler before 2.0.2.

Fix: 2.0.2+
Fix from $2,300 2022-08-02