Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 7.2 CVE-2022-39265 MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, i… Mybb 1.8.31+ Fix from $1,9502022-10-06 HIGH 7.2 CVE-2022-20851 A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against a… Ios Xe Mitigation only Fix from $1,9502022-09-30 HIGH 7.2 CVE-2022-41870 AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload. Innovaphone Firmware 13r2+ Fix from $1,9502022-09-30 CRITICAL 9.8 CVE-2022-39243 NuProcess is an external process execution implementation for Java. In all the versions of NuProcess where it forks processes by using the JVM's Java… Nuprocess 2.0.5+ Fix from $2,3002022-09-26 CRITICAL 9.8 CVE-2022-40100 Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function. I9 Firmware Mitigation only Fix from $2,3002022-09-23 HIGH 7.2 CVE-2022-37879 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.12 / 6.10.7+ Fix from $1,9502022-09-20 HIGH 7.2 CVE-2022-37881 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.12 / 6.10.7+ Fix from $1,9502022-09-20 HIGH 7.2 CVE-2022-37883 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.12 / 6.10.7+ Fix from $1,9502022-09-20 HIGH 7.5 CVE-2022-28220 Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, … James after 3.6.2 Fix from $1,9502022-09-08 HIGH 8.8 CVE-2022-3008 The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. T… Debian Linux 2.6.0+ Fix from $1,9502022-09-05 CRITICAL 9.8 CVE-2022-37125 D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost. Dir 816 Firmware No fix yet Fix from $2,3002022-08-31 HIGH 8.2 CVE-2022-34383 Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A local malicious user may potentia… Edge Gateway 5200 Firmware 1.03.10+ Fix from $1,9502022-08-31 CRITICAL 9.8 CVE-2022-21941 All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to… Istar Ultra Firmware 6.8.9.cu01+ Fix from $2,3002022-08-31 CRITICAL 9.8 CVE-2022-36553EPSS 91% Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi. Hwl 2511 Ss Firmware after 1.05 Fix from $2,3002022-08-29 CRITICAL 9.8 CVE-2022-36554 A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to e… Hwl 2511 Ss Firmware after 1.05 Fix from $2,3002022-08-29 CRITICAL 9.8 CVE-2022-36556 Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08ex… Skybridge Mb A100 Firmware after 4.2.0 Fix from $2,3002022-08-29 CRITICAL 9.8 CVE-2022-36559 Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi. Skybridge Mb A200 Firmware after 01.00.04 Fix from $2,3002022-08-29 HIGH 8.8 CVE-2022-2234EPSS 41% An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system. Mypro after 8.26.0 Fix from $1,9502022-08-24 CRITICAL 9.8 CVE-2022-36523 D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/upnpinc/gena.php. Go Rt Ac750 Firmware Mitigation only Fix from $2,3002022-08-15 MEDIUM 5.0 CVE-2022-35954 The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter… Toolkit 1.9.1+ Fix from $1,6002022-08-15 CRITICAL 9.8 CVE-2022-35518 WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to command injection … Wn572hp3 Firmware No fix yet Fix from $2,3002022-08-10 HIGH 8.8 CVE-2022-20345 In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execut… Android Mitigation only Fix from $1,9502022-08-10 CRITICAL 9.8 CVE-2022-34660 A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (… Teamcenter 12.4.0.15 / 13.0.0.10+ Fix from $2,3002022-08-10 CRITICAL 9.8 CVE-2022-34974EPSS 23% D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function. Dir 810l Firmware No fix yet Fix from $2,3002022-08-03 CRITICAL 9.8 CVE-2020-28423 This affects all versions of package monorepo-build. Monorepo Build No fix yet Fix from $2,3002022-08-02 CRITICAL 9.8 CVE-2020-28425 This affects all versions of package curljs. Curljs No fix yet Fix from $2,3002022-08-02 CRITICAL 9.8 CVE-2020-28433 This affects all versions of package node-latex-pdf. Node Latex Pdf No fix yet Fix from $2,3002022-08-02 CRITICAL 9.8 CVE-2020-28434 This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js. Gitblame No fix yet Fix from $2,3002022-08-02 CRITICAL 9.8 CVE-2020-28437 This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js. Heroku Env No fix yet Fix from $2,3002022-08-02 CRITICAL 9.8 CVE-2020-28451 This affects the package image-tiler before 2.0.2. Image Tiler 2.0.2+ Fix from $2,3002022-08-02