Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-27000

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_b…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-27001

Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-27002EPSS 5%

Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26995

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pptp_fix_m…

No fix yet
Fix from $2,300 2022-03-15
A3100r Firmware CRITICAL 9.8
CVE-2021-44620

A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.

Fix: after 4.1.2cu.5050_b20200504
Fix from $2,300 2022-03-11
Tapo C200 Firmware CRITICAL 9.8
CVE-2021-4045EPSS 72%

TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd bin…

Fix: after 1.1.15
Fix from $2,300 2022-03-10
Arubaos Cx HIGH 8.8
CVE-2021-41000

Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Ar…

Fix: after 10.07.0020
Fix from $1,950 2022-03-02
Arubaos Cx HIGH 8.8
CVE-2021-41001

An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch Series, Aru…

Fix: after 10.09.0002
Fix from $1,950 2022-03-02
C Data Onu4ferw Firmware HIGH 7.8
CVE-2021-44132

A command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers to execute arbitrary commands …

Fix: after 2.1.13_x139
Fix from $1,950 2022-02-25
Ais Bw80h 00 Firmware HIGH 7.8
CVE-2021-40043

The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00). The devices cannot effectiv…

Fix: 9.0.3.4+
Fix from $1,950 2022-02-25
Hdzp252di Firmware CRITICAL 9.8
CVE-2021-39363

Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.

Mitigation only
Fix from $2,300 2022-02-24
Fedora HIGH 7.8
CVE-2021-45082

An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Pyth…

Fix: 3.3.1+
Fix from $1,950 2022-02-19
T6 Firmware CRITICAL 9.8
CVE-2022-25130

A command injection vulnerability in the function updateWifiInfo of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V…

Mitigation only
Fix from $2,300 2022-02-19
T6 Firmware CRITICAL 9.8
CVE-2022-25131

A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B2021101…

Mitigation only
Fix from $2,300 2022-02-19
T6 Firmware CRITICAL 9.8
CVE-2022-25132

A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows atta…

Mitigation only
Fix from $2,300 2022-02-19
T6 Firmware CRITICAL 9.8
CVE-2022-25133

A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows a…

Mitigation only
Fix from $2,300 2022-02-19
T6 Firmware CRITICAL 9.8
CVE-2022-25134

A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attac…

Mitigation only
Fix from $2,300 2022-02-19
T6 Firmware CRITICAL 9.8
CVE-2022-25135

A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allow…

Mitigation only
Fix from $2,300 2022-02-19
T6 Firmware CRITICAL 9.8
CVE-2022-25136

A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 …

Mitigation only
Fix from $2,300 2022-02-19
T6 Firmware CRITICAL 9.8
CVE-2022-25137

A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T…

Mitigation only
Fix from $2,300 2022-02-19
Ac10u Firmware CRITICAL 9.8
CVE-2021-45401

A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via the setUsbU…

No fix yet
Fix from $2,300 2022-02-18
Enterprise Server HIGH 8.8
CVE-2021-41599

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. To exploi…

Fix: 3.0.21 / 3.1.13+
Fix from $1,950 2022-02-18
Arris Surfboard Sbg6950ac2 Firmware HIGH 8.8
CVE-2021-41552

CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection.

Mitigation only
Fix from $1,950 2022-02-15
Completeftp Server HIGH 8.8
CVE-2019-16864EPSS 8%

CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that…

Fix: 12.1.4+
Fix from $1,950 2022-02-14
G1 Firmware CRITICAL 9.8
CVE-2022-24168

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpGroup. This vulner…

No fix yet
Fix from $2,300 2022-02-04
G1 Firmware CRITICAL 9.8
CVE-2022-24170

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpSecTunnel. This vu…

No fix yet
Fix from $2,300 2022-02-04
G1 Firmware CRITICAL 9.8
CVE-2022-24171

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vu…

No fix yet
Fix from $2,300 2022-02-04
Ax3 Firmware CRITICAL 9.8
CVE-2022-24148

Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function mDMZSetCfg. This vulnerability allows attackers…

No fix yet
Fix from $2,300 2022-02-04
Ax3 Firmware CRITICAL 9.8
CVE-2022-24150

Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function formSetSafeWanWebMan. This vulnerability allows…

No fix yet
Fix from $2,300 2022-02-04
G1 Firmware CRITICAL 9.8
CVE-2022-24165

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetQvlanList. This vuln…

No fix yet
Fix from $2,300 2022-02-04