Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Nimbleos CRITICAL 9.8
CVE-2022-28618

A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE…

Fix: 5.0.10.100 / 5.2.1.500+
Fix from $2,300 2022-05-20
Gocd HIGH 8.8
CVE-2022-29184

GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users who have permissions to edit …

Fix: 22.1.0+
Fix from $1,950 2022-05-20
Deception HIGH 8.8
CVE-2022-24388

Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deceptio…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24389

Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and De…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24390

Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network …

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24392

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “feed_comm_tes…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24393

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24394

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkf…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Ir302 Firmware HIGH 7.2
CVE-2022-26007EPSS 6%

An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network …

No fix yet
Fix from $1,950 2022-05-12
Ir302 Firmware HIGH 8.8
CVE-2022-26042EPSS 9%

An OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network…

No fix yet
Fix from $1,950 2022-05-12
Ir302 Firmware HIGH 8.8
CVE-2022-26085EPSS 13%

An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP re…

No fix yet
Fix from $1,950 2022-05-12
Big Ip Access Policy Manager HIGH 7.2
CVE-2022-27806

On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC…

Fix: 9.0+
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2022-26415

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5…

Fix: 13.1.5 / 14.1.4.6+
Fix from $2,300 2022-05-05
Qvr CRITICAL 9.8
CVE-2022-27588

We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later

Fix: after 5.1.6
Fix from $2,300 2022-05-05
Qts HIGH 8.8
CVE-2021-44051

A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows …

Fix: 4.3.3.1945 / 4.3.4.1976+
Fix from $1,950 2022-05-05
Rv340 Firmware HIGH 7.2
CVE-2022-20799

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote a…

Fix: 1.0.03.27+
Fix from $1,950 2022-05-04
Rv340 Firmware HIGH 7.2
CVE-2022-20801

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote a…

Fix: 1.0.03.27+
Fix from $1,950 2022-05-04
Reyeeos HIGH 8.8
CVE-2021-43159

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the s…

Fix: after 1.55.1915_ew_3.0
Fix from $1,950 2022-05-04
Reyeeos HIGH 8.8
CVE-2021-43160

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the s…

Fix: after 1.55.1915_ew_3.0
Fix from $1,950 2022-05-04
Reyeeos HIGH 8.8
CVE-2021-43161

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the d…

Fix: after 1.55.1915_ew_3.0
Fix from $1,950 2022-05-04
Reyeeos HIGH 8.8
CVE-2021-43162

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the r…

Fix: after 1.55.1915_ew_3.0
Fix from $1,950 2022-05-04
Reyeeos CRITICAL 9.8
CVE-2021-43163

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the c…

Fix: after 1.55.1915_ew_3.0
Fix from $2,300 2022-05-04
Control Panel HIGH 8.8
CVE-2022-1509

Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can exec…

Fix: 1.5.12+
Fix from $1,950 2022-04-28
Cc612 Firmware HIGH 8.8
CVE-2021-34592

In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell …

Fix: 5.11.2 / 5.12.5+
Fix from $1,950 2022-04-27
Windows 10 HIGH 7.2
CVE-2022-26826

Windows DNS Server Remote Code Execution Vulnerability

No fix yet
Fix from $1,950 2022-04-15
Gocd HIGH 8.8
CVE-2021-43286

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command…

Fix: 21.3.0+
Fix from $1,950 2022-04-14
Python HIGH 7.6
CVE-2015-20107EPSS 7%

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may…

Fix: 3.10.8+
Fix from $1,950 2022-04-13
Xenmobile Server HIGH 8.8
CVE-2021-44520EPSS 6%

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root p…

Mitigation only
Fix from $1,950 2022-04-13
Xenmobile Server HIGH 7.2
CVE-2022-26151EPSS 8%

Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.

Mitigation only
Fix from $1,950 2022-04-13
Mypro HIGH 8.8
CVE-2022-0999

An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.

Fix: after 8.25.0
Fix from $1,950 2022-04-11