Vulnerability index

Browse CVEs

3,669 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2020-28453 This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js. Npos Tesseract No fix yet Fix from $2,3002022-08-02 CRITICAL 9.8 CVE-2020-7795 The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js. Get Npm Package Version 1.0.7+ Fix from $2,3002022-08-02 HIGH 8.8 CVE-2022-2323EPSS 6% Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remote code execution in the host … Sws12 10fpoe Firmware 1.2.0.0-3+ Fix from $1,9502022-07-29 HIGH 8.8 CVE-2022-29558 Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface. Rtl819x Software Development Kit 3.6.1+ Fix from $1,9502022-07-28 CRITICAL 9.8 CVE-2016-4991 Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not prope… Nodepdf No fix yet Fix from $2,3002022-07-28 CRITICAL 9.8 CVE-2020-28435 This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js. Ffmpeg Sdk No fix yet Fix from $2,3002022-07-25 CRITICAL 9.8 CVE-2020-28436 This affects all versions of package google-cloudstorage-commands. Google Cloudstorage Commands No fix yet Fix from $2,3002022-07-25 CRITICAL 9.8 CVE-2020-28438 This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js Deferred Exec No fix yet Fix from $2,3002022-07-25 CRITICAL 9.8 CVE-2020-28443 This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js. Sonar Wrapper No fix yet Fix from $2,3002022-07-25 CRITICAL 9.8 CVE-2020-28445 This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function. Npm Help No fix yet Fix from $2,3002022-07-25 CRITICAL 9.8 CVE-2020-28446 The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js. Ntesseract 0.2.9+ Fix from $2,3002022-07-25 CRITICAL 9.8 CVE-2020-28447 This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath) Xopen No fix yet Fix from $2,3002022-07-25 HIGH 7.8 CVE-2020-28422 All versions of package git-archive are vulnerable to Command Injection via the exports function. Git Archive No fix yet Fix from $1,9502022-07-25 CRITICAL 9.8 CVE-2022-2143EPSS 59% The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code. Iview 5.7.04.6469+ Fix from $2,3002022-07-22 CRITICAL 9.8 CVE-2022-0902EPSS 17% Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Comma… Rmc 100 Firmware 2105298-024 / 2105457-037+ Fix from $2,3002022-07-21 CRITICAL 9.8 CVE-2022-31161EPSS 27% Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via t… Roxy Wi 6.1.1.0+ Fix from $2,3002022-07-15 HIGH 8.4 CVE-2022-34820 A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 L… Simatic Cp 1242 7 V2 Firmware 2.2.28 / 3.0.22+ Fix from $1,9502022-07-12 HIGH 7.2 CVE-2022-29560 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < 2.15.1), RUGGEDCOM ROX MX5000RE (All versions < 2.15.1), RUGGEDCOM ROX RX… Ruggedcom Rox Rx1500 Firmware 2.15.1+ Fix from $1,9502022-07-12 CRITICAL 9.8 CVE-2022-32449EPSS 19% TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function.… Ex300 V2 Firmware No fix yet Fix from $2,3002022-07-07 CRITICAL 9.8 CVE-2022-34592 Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obtw. This vulnerability allows … Wl Wn575a3 Firmware No fix yet Fix from $2,3002022-07-07 HIGH 7.2 CVE-2022-28935 Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, Totolink A800R V4.1.2cu.5137_B… A830r Firmware No fix yet Fix from $1,9502022-07-06 CRITICAL 9.8 CVE-2022-28171EPSS 50% The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validat… Ds A71024 Firmware after 2.3.8-6 Fix from $2,3002022-06-27 CRITICAL 9.8 CVE-2022-31874EPSS 19% ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface. Rt N53 Firmware No fix yet Fix from $2,3002022-06-17 HIGH 8.1 CVE-2022-32154 Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a … Splunk 8.2.2106 / 9.0+ Fix from $1,9502022-06-15 CRITICAL 9.8 CVE-2022-32262 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a file upload server tha… Sinema Remote Connect Server 3.1+ Fix from $2,3002022-06-14 HIGH 8.8 CVE-2019-9972 PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the … Debian Linux No fix yet Fix from $1,9502022-06-07 HIGH 8.8 CVE-2020-36529 A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the… Sevone Network Performance Management after 5.7.2.22 Fix from $1,9502022-06-07 CRITICAL 9.8 CVE-2022-29712 LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters. Librenms Patch available Fix from $2,3002022-06-02 MEDIUM 6.7 CVE-2022-29256 sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm in… Sharp 0.30.5+ Fix from $1,6002022-05-25 HIGH 8.6 CVE-2022-30321 go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed i… Go Getter after 1.5.11 Fix from $1,9502022-05-25