Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
G1 Firmware CRITICAL 9.8
CVE-2022-24167

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetDMZ. This vulnerabil…

No fix yet
Fix from $2,300 2022-02-04
Dir 882 Firmware CRITICAL 9.8
CVE-2021-45998

D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This v…

Fix: after 1.30b06
Fix from $2,300 2022-02-04
Di 7200gv2 Firmware CRITICAL 9.8
CVE-2021-46226

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability…

Fix: after 21.04.09e1
Fix from $2,300 2022-02-04
Di 7200gv2 Firmware CRITICAL 9.8
CVE-2021-46227

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function proxy_client.asp. This vulnerabil…

Fix: after 21.04.09e1
Fix from $2,300 2022-02-04
Di 7200gv2 Firmware CRITICAL 9.8
CVE-2021-46228

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerabili…

Fix: after 21.04.09e1
Fix from $2,300 2022-02-04
Di 7200gv2 Firmware CRITICAL 9.8
CVE-2021-46229

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function usb_paswd.asp. This vulnerability…

Fix: after 21.04.09e1
Fix from $2,300 2022-02-04
Di 7200gv2 Firmware CRITICAL 9.8
CVE-2021-46230

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgrade_filter. This vulnerabilit…

Fix: after 21.04.09e1
Fix from $2,300 2022-02-04
Di 7200gv2 Firmware CRITICAL 9.8
CVE-2021-46231

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrd_opt.asp. This vulnerability…

Fix: after 21.04.09e1
Fix from $2,300 2022-02-04
Di 7200gv2 Firmware CRITICAL 9.8
CVE-2021-46232

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function version_upgrade.asp. This vulnera…

Fix: after 21.04.09e1
Fix from $2,300 2022-02-04
Di 7200gv2 Firmware CRITICAL 9.8
CVE-2021-46233

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function msp_info.htm. This vulnerability …

Fix: after 21.04.09e1
Fix from $2,300 2022-02-04
Dir 823 Pro Firmware CRITICAL 9.8
CVE-2021-46452

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNetworkTomographySettings. Thi…

Fix: after 1.0.2
Fix from $2,300 2022-02-04
Dir 823 Pro Firmware CRITICAL 9.8
CVE-2021-46453

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStaticRouteSettings. This vuln…

Fix: after 1.0.2
Fix from $2,300 2022-02-04
Dir 823 Pro Firmware CRITICAL 9.8
CVE-2021-46454

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanApcliSettings. This vulner…

Fix: after 1.0.2
Fix from $2,300 2022-02-04
Dir 823 Pro Firmware CRITICAL 9.8
CVE-2021-46455

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStationSettings. This vulnerab…

Fix: after 1.0.2
Fix from $2,300 2022-02-04
Dir 823 Pro Firmware CRITICAL 9.8
CVE-2021-46456

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanACLSettings. This vulnerab…

Fix: after 1.0.2
Fix from $2,300 2022-02-04
Dir 823 Pro Firmware CRITICAL 9.8
CVE-2021-46457

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgSambaUserSettings. This vulner…

Fix: after 1.0.2
Fix from $2,300 2022-02-04
Ax3 Firmware CRITICAL 9.8
CVE-2022-24144EPSS 19%

Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function WanParameterSetting. This vulnerability allows …

No fix yet
Fix from $2,300 2022-02-04
Dir 878 Firmware CRITICAL 9.8
CVE-2021-44882

D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability al…

Fix: after 1.20b05
Fix from $2,300 2022-02-04
X5000r Firmware CRITICAL 9.8
CVE-2021-45733

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerabilit…

No fix yet
Fix from $2,300 2022-02-04
X5000r Firmware CRITICAL 9.8
CVE-2021-45738

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerabi…

No fix yet
Fix from $2,300 2022-02-04
A720r Firmware CRITICAL 9.8
CVE-2021-45742

TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows a…

No fix yet
Fix from $2,300 2022-02-04
G1 Firmware CRITICAL 9.8
CVE-2021-45990

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnera…

Mitigation only
Fix from $2,300 2022-02-04
A720r Firmware CRITICAL 9.8
CVE-2021-44247

Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command inje…

No fix yet
Fix from $2,300 2022-02-04
Dir 878 Firmware CRITICAL 9.8
CVE-2021-44880

D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerabili…

Fix: after 1.30b06
Fix from $2,300 2022-02-04
Dir 882 Firmware CRITICAL 9.8
CVE-2021-44881

D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerab…

Fix: after 1.30b06
Fix from $2,300 2022-02-04
Web Stack HIGH 8.1
CVE-2021-42638EPSS 5%

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.

Fix: 19.1.1.13+
Fix from $1,950 2022-02-01
Gerapy HIGH 8.8
CVE-2021-32849EPSS 8%

Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is f…

Fix: 0.9.9+
Fix from $1,950 2022-01-26
Tn 5900 Firmware CRITICAL 9.8
CVE-2021-46560

The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.

Fix: after 3.1
Fix from $2,300 2022-01-26
Emc Unity Operating Environment MEDIUM 6.7
CVE-2021-43589

Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerabil…

Fix: 5.1.2.0.5.007+
Fix from $1,600 2022-01-24
B2236 Firmware CRITICAL 9.8
CVE-2021-44735EPSS 7%

Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.

Mitigation only
Fix from $2,300 2022-01-20