Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
MEDIUM 6.7 CVE-2022-45095 Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privile… Emc Powerscale Onefs 9.1.0.25 / 9.2.1.18+ Fix from $1,6002023-02-01 CRITICAL 9.8 CVE-2022-21129 Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup'… Nemo Appium 0.0.9+ Fix from $2,3002023-01-31 CRITICAL 9.8 CVE-2023-24612 The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an option. Pdfbook after 2.0.5 Fix from $2,3002023-01-30 HIGH 7.2 CVE-2021-41231 OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and… Magento 19.4.22 / 20.0.19+ Fix from $1,9502023-01-27 HIGH 7.2 CVE-2021-41143 OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute co… Magento 19.4.22 / 20.0.19+ Fix from $1,9502023-01-27 HIGH 8.8 CVE-2021-41144 OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the block blacklist to execute remot… Magento 19.4.22 / 20.0.19+ Fix from $1,9502023-01-27 HIGH 7.2 CVE-2021-39217 OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via bl… Magento 19.4.22 / 20.0.19+ Fix from $1,9502023-01-27 CRITICAL 9.8 CVE-2022-25962 All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization. Vagrant.js Mitigation only Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2022-25908 All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitiza… Create Choo Electron No fix yet Fix from $2,3002023-01-26 HIGH 7.8 CVE-2022-25350 All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization. Puppet Facter No fix yet Fix from $1,9502023-01-26 HIGH 7.8 CVE-2022-21810 All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization. Smartctl No fix yet Fix from $1,9502023-01-26 CRITICAL 9.8 CVE-2023-22884EPSS 11% Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach… Airflow 2.5.1 / 4.0.0+ Fix from $2,3002023-01-21 HIGH 7.5 CVE-2020-22662 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10… R310 Firmware 3.6.2.0.795+ Fix from $1,9502023-01-20 HIGH 7.2 CVE-2023-20045 A vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticated, remote… Rv160 Vpn Router Firmware 1.0.01.04+ Fix from $1,9502023-01-20 HIGH 7.2 CVE-2023-20026 A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320 and RV325 Routers could allow an aut… Rv016 Firmware Mitigation only Fix from $1,9502023-01-20 HIGH 8.8 CVE-2023-0315EPSS 98% Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8. Froxlor 2.0.8+ Fix from $1,9502023-01-16 CRITICAL 9.8 CVE-2023-22496EPSS 36% Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the ability to establish a streaming c… Netdata 1.37.0+ Fix from $2,3002023-01-14 HIGH 8.8 CVE-2022-41955 Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer au… Autolab 2.10.0+ Fix from $1,9502023-01-14 CRITICAL 9.8 CVE-2022-21191 Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sa… Global Modules Path 3.0.0+ Fix from $2,3002023-01-13 CRITICAL 9.1 CVE-2022-4616 The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This vulnerability cou… Dx 3021l9 Firmware 1.24+ Fix from $2,3002023-01-13 HIGH 8.0 CVE-2020-36650 A vulnerability, which was classified as critical, was found in IonicaBizau node-gry up to 5.x. This affects an unknown part. The manipulation leads … Gry 6.0.0+ Fix from $1,9502023-01-11 HIGH 8.8 CVE-2022-45094 A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Ma… Sinec Ins 1.0+ Fix from $1,9502023-01-10 CRITICAL 9.8 CVE-2022-39073 There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerabi… Mf286r Firmware Mitigation only Fix from $2,3002023-01-06 CRITICAL 9.8 CVE-2020-36642 A vulnerability was found in trampgeek jobe up to 1.6.x and classified as critical. This issue affects the function run_in_sandbox of the file applic… Jobe 1.7.0+ Fix from $2,3002023-01-06 CRITICAL 9.8 CVE-2023-22671 Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when ca… Ghidra after 10.2.2 Fix from $2,3002023-01-06 CRITICAL 9.8 CVE-2022-25923 Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input… Exec Local Bin 1.2.0+ Fix from $2,3002023-01-06 CRITICAL 9.8 CVE-2021-4304 A vulnerability was found in eprintsug ulcc-core. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the… Ulcc Core 2021-02-05+ Fix from $2,3002023-01-05 MEDIUM 6.7 CVE-2022-39086 In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. Android No fix yet Fix from $1,6002023-01-04 MEDIUM 6.7 CVE-2022-39087 In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. Android Mitigation only Fix from $1,6002023-01-04 MEDIUM 6.7 CVE-2022-39088 In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. Android Mitigation only Fix from $1,6002023-01-04