Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2022-39265
MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, i…
Mybb
1.8.31+
HIGH 7.2
CVE-2022-20851
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against a…
Ios Xe
Mitigation only
HIGH 7.2
CVE-2022-41870
AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload.
Innovaphone Firmware
13r2+
CRITICAL 9.8
CVE-2022-39243
NuProcess is an external process execution implementation for Java. In all the versions of NuProcess where it forks processes by using the JVM's Java…
Nuprocess
2.0.5+
CRITICAL 9.8
CVE-2022-40100
Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function.
I9 Firmware
Mitigation only
HIGH 7.2
CVE-2022-37879
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…
Clearpass Policy Manager
6.9.12 / 6.10.7+
HIGH 7.2
CVE-2022-37881
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…
Clearpass Policy Manager
6.9.12 / 6.10.7+
HIGH 7.2
CVE-2022-37883
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…
Clearpass Policy Manager
6.9.12 / 6.10.7+
HIGH 7.5
CVE-2022-28220
Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, …
James
after 3.6.2
HIGH 8.8
CVE-2022-3008
The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. T…
Debian Linux
2.6.0+
CRITICAL 9.8
CVE-2022-37125
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
Dir 816 Firmware
No fix yet
HIGH 8.2
CVE-2022-34383
Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A local malicious user may potentia…
Edge Gateway 5200 Firmware
1.03.10+
CRITICAL 9.8
CVE-2022-21941
All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to…
Istar Ultra Firmware
6.8.9.cu01+
CRITICAL 9.8
CVE-2022-36553EPSS 91%
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.
Hwl 2511 Ss Firmware
after 1.05
CRITICAL 9.8
CVE-2022-36554
A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to e…
Hwl 2511 Ss Firmware
after 1.05
CRITICAL 9.8
CVE-2022-36556
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08ex…
Skybridge Mb A100 Firmware
after 4.2.0
CRITICAL 9.8
CVE-2022-36559
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.
Skybridge Mb A200 Firmware
after 01.00.04
HIGH 8.8
CVE-2022-2234EPSS 41%
An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.
Mypro
after 8.26.0
CRITICAL 9.8
CVE-2022-36523
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/upnpinc/gena.php.
Go Rt Ac750 Firmware
Mitigation only
MEDIUM 5.0
CVE-2022-35954
The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter…
Toolkit
1.9.1+
CRITICAL 9.8
CVE-2022-35518
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to command injection …
Wn572hp3 Firmware
No fix yet
HIGH 8.8
CVE-2022-20345
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execut…
Android
Mitigation only
CRITICAL 9.8
CVE-2022-34660
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (…
Teamcenter
12.4.0.15 / 13.0.0.10+
CRITICAL 9.8
CVE-2022-34974EPSS 23%
D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function.
Dir 810l Firmware
No fix yet
CRITICAL 9.8
CVE-2020-28423
This affects all versions of package monorepo-build.
Monorepo Build
No fix yet
CRITICAL 9.8
CVE-2020-28425
This affects all versions of package curljs.
Curljs
No fix yet
CRITICAL 9.8
CVE-2020-28433
This affects all versions of package node-latex-pdf.
Node Latex Pdf
No fix yet
CRITICAL 9.8
CVE-2020-28434
This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
Gitblame
No fix yet
CRITICAL 9.8
CVE-2020-28437
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
Heroku Env
No fix yet
CRITICAL 9.8
CVE-2020-28451
This affects the package image-tiler before 2.0.2.
Image Tiler
2.0.2+