Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Xenmobile Server HIGH 8.8
CVE-2021-44520EPSS 6%

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root p…

Mitigation only
Fix from $1,950 2022-04-13
Xenmobile Server HIGH 7.2
CVE-2022-26151EPSS 8%

Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.

Mitigation only
Fix from $1,950 2022-04-13
Mypro HIGH 8.8
CVE-2022-0999

An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.

Fix: after 8.25.0
Fix from $1,950 2022-04-11
Dir 823g Firmware CRITICAL 9.8
CVE-2021-43474

An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function

No fix yet
Fix from $2,300 2022-04-07
Staros MEDIUM 6.7
CVE-2022-20665

A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerabili…

Fix: 21.22.n6 / 21.23.n7+
Fix from $1,600 2022-04-06
Autosave CRITICAL 9.8
CVE-2021-32933

An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave version…

Fix: 4.01 / 6.02.06+
Fix from $2,300 2022-04-01
Quick App CRITICAL 9.8
CVE-2021-23247

A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary cod…

No fix yet
Fix from $2,300 2022-04-01
Ex300 V2 Firmware HIGH 7.5
CVE-2021-43663

totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cloudupdate_check.

No fix yet
Fix from $1,950 2022-03-31
Ex300 V2 Firmware HIGH 8.1
CVE-2021-43664

totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo.

No fix yet
Fix from $1,950 2022-03-30
Sambabox MEDIUM 6.7
CVE-2022-25619

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profelis IT Consultancy SambaBox al…

Fix: after 4.0
Fix from $1,600 2022-03-30
Vigor2960 Firmware CRITICAL 9.8
CVE-2021-43118EPSS 35%

A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a craft…

No fix yet
Fix from $2,300 2022-03-29
Diskstation Manager HIGH 8.8
CVE-2022-22688

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStati…

Fix: 6.2.4-25556-2 / 7.0.1-42214+
Fix from $1,950 2022-03-25
M3 Firmware CRITICAL 9.8
CVE-2022-26536

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setFixTools.

No fix yet
Fix from $2,300 2022-03-24
M3 Firmware CRITICAL 9.8
CVE-2022-27076

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/delAd.

No fix yet
Fix from $2,300 2022-03-24
M3 Firmware CRITICAL 9.8
CVE-2022-27077

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic.

No fix yet
Fix from $2,300 2022-03-24
M3 Firmware CRITICAL 9.8
CVE-2022-27078

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setAdInfoDetail.

No fix yet
Fix from $2,300 2022-03-24
M3 Firmware CRITICAL 9.8
CVE-2022-27079

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem.

No fix yet
Fix from $2,300 2022-03-24
M3 Firmware CRITICAL 9.8
CVE-2022-27080

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode.

No fix yet
Fix from $2,300 2022-03-24
M3 Firmware CRITICAL 9.8
CVE-2022-27081

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetLanInfo.

No fix yet
Fix from $2,300 2022-03-24
M3 Firmware CRITICAL 9.8
CVE-2022-27082

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo.

No fix yet
Fix from $2,300 2022-03-24
M3 Firmware CRITICAL 9.8
CVE-2022-27083

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic.

No fix yet
Fix from $2,300 2022-03-24
N600r Firmware CRITICAL 9.8
CVE-2022-26186

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.

No fix yet
Fix from $2,300 2022-03-22
N600r Firmware CRITICAL 9.8
CVE-2022-26187EPSS 20%

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function.

No fix yet
Fix from $2,300 2022-03-22
N600r Firmware CRITICAL 9.8
CVE-2022-26188

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost.

No fix yet
Fix from $2,300 2022-03-22
N600r Firmware CRITICAL 9.8
CVE-2022-26189

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.

No fix yet
Fix from $2,300 2022-03-22
Wallbox Gtb Firmware CRITICAL 9.8
CVE-2021-45876

Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAnd…

Fix: after 185
Fix from $2,300 2022-03-21
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26996

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppo…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26997

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter. This vulnerability …

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26998

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This …

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26999

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_sta…

No fix yet
Fix from $2,300 2022-03-15