Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Npos Tesseract CRITICAL 9.8
CVE-2020-28453

This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.

No fix yet
Fix from $2,300 2022-08-02
Get Npm Package Version CRITICAL 9.8
CVE-2020-7795

The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.

Fix: 1.0.7+
Fix from $2,300 2022-08-02
Sws12 10fpoe Firmware HIGH 8.8
CVE-2022-2323EPSS 6%

Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remote code execution in the host …

Fix: 1.2.0.0-3+
Fix from $1,950 2022-07-29
Rtl819x Software Development Kit HIGH 8.8
CVE-2022-29558

Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.

Fix: 3.6.1+
Fix from $1,950 2022-07-28
Nodepdf CRITICAL 9.8
CVE-2016-4991

Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not prope…

No fix yet
Fix from $2,300 2022-07-28
Ffmpeg Sdk CRITICAL 9.8
CVE-2020-28435

This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.

No fix yet
Fix from $2,300 2022-07-25
Google Cloudstorage Commands CRITICAL 9.8
CVE-2020-28436

This affects all versions of package google-cloudstorage-commands.

No fix yet
Fix from $2,300 2022-07-25
Deferred Exec CRITICAL 9.8
CVE-2020-28438

This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js

No fix yet
Fix from $2,300 2022-07-25
Sonar Wrapper CRITICAL 9.8
CVE-2020-28443

This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.

No fix yet
Fix from $2,300 2022-07-25
Npm Help CRITICAL 9.8
CVE-2020-28445

This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.

No fix yet
Fix from $2,300 2022-07-25
Ntesseract CRITICAL 9.8
CVE-2020-28446

The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.

Fix: 0.2.9+
Fix from $2,300 2022-07-25
Xopen CRITICAL 9.8
CVE-2020-28447

This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)

No fix yet
Fix from $2,300 2022-07-25
Git Archive HIGH 7.8
CVE-2020-28422

All versions of package git-archive are vulnerable to Command Injection via the exports function.

No fix yet
Fix from $1,950 2022-07-25
Iview CRITICAL 9.8
CVE-2022-2143EPSS 59%

The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.

Fix: 5.7.04.6469+
Fix from $2,300 2022-07-22
Rmc 100 Firmware CRITICAL 9.8
CVE-2022-0902EPSS 17%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Comma…

Fix: 2105298-024 / 2105457-037+
Fix from $2,300 2022-07-21
Roxy Wi CRITICAL 9.8
CVE-2022-31161EPSS 27%

Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via t…

Fix: 6.1.1.0+
Fix from $2,300 2022-07-15
Simatic Cp 1242 7 V2 Firmware HIGH 8.4
CVE-2022-34820

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 L…

Fix: 2.2.28 / 3.0.22+
Fix from $1,950 2022-07-12
Ruggedcom Rox Rx1500 Firmware HIGH 7.2
CVE-2022-29560

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < 2.15.1), RUGGEDCOM ROX MX5000RE (All versions < 2.15.1), RUGGEDCOM ROX RX…

Fix: 2.15.1+
Fix from $1,950 2022-07-12
Ex300 V2 Firmware CRITICAL 9.8
CVE-2022-32449EPSS 19%

TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function.…

No fix yet
Fix from $2,300 2022-07-07
Wl Wn575a3 Firmware CRITICAL 9.8
CVE-2022-34592

Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obtw. This vulnerability allows …

No fix yet
Fix from $2,300 2022-07-07
A830r Firmware HIGH 7.2
CVE-2022-28935

Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, Totolink A800R V4.1.2cu.5137_B…

No fix yet
Fix from $1,950 2022-07-06
Ds A71024 Firmware CRITICAL 9.8
CVE-2022-28171EPSS 50%

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validat…

Fix: after 2.3.8-6
Fix from $2,300 2022-06-27
Rt N53 Firmware CRITICAL 9.8
CVE-2022-31874EPSS 19%

ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.

No fix yet
Fix from $2,300 2022-06-17
Splunk HIGH 8.1
CVE-2022-32154

Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a …

Fix: 8.2.2106 / 9.0+
Fix from $1,950 2022-06-15
Sinema Remote Connect Server CRITICAL 9.8
CVE-2022-32262

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a file upload server tha…

Fix: 3.1+
Fix from $2,300 2022-06-14
Debian Linux HIGH 8.8
CVE-2019-9972

PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the …

No fix yet
Fix from $1,950 2022-06-07
Sevone Network Performance Management HIGH 8.8
CVE-2020-36529

A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the…

Fix: after 5.7.2.22
Fix from $1,950 2022-06-07
Librenms CRITICAL 9.8
CVE-2022-29712

LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.

Patch available
Fix from $2,300 2022-06-02
Sharp MEDIUM 6.7
CVE-2022-29256

sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm in…

Fix: 0.30.5+
Fix from $1,600 2022-05-25
Go Getter HIGH 8.6
CVE-2022-30321

go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed i…

Fix: after 1.5.11
Fix from $1,950 2022-05-25