Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2021-44520EPSS 6% In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root p… Xenmobile Server Mitigation only Fix from $1,9502022-04-13 HIGH 7.2 CVE-2022-26151EPSS 8% Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection. Xenmobile Server Mitigation only Fix from $1,9502022-04-13 HIGH 8.8 CVE-2022-0999 An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior. Mypro after 8.25.0 Fix from $1,9502022-04-11 CRITICAL 9.8 CVE-2021-43474 An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function Dir 823g Firmware No fix yet Fix from $2,3002022-04-07 MEDIUM 6.7 CVE-2022-20665 A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerabili… Staros 21.22.n6 / 21.23.n7+ Fix from $1,6002022-04-06 CRITICAL 9.8 CVE-2021-32933 An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave version… Autosave 4.01 / 6.02.06+ Fix from $2,3002022-04-01 CRITICAL 9.8 CVE-2021-23247 A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary cod… Quick App No fix yet Fix from $2,3002022-04-01 HIGH 7.5 CVE-2021-43663 totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cloudupdate_check. Ex300 V2 Firmware No fix yet Fix from $1,9502022-03-31 HIGH 8.1 CVE-2021-43664 totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo. Ex300 V2 Firmware No fix yet Fix from $1,9502022-03-30 MEDIUM 6.7 CVE-2022-25619 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profelis IT Consultancy SambaBox al… Sambabox after 4.0 Fix from $1,6002022-03-30 CRITICAL 9.8 CVE-2021-43118EPSS 35% A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a craft… Vigor2960 Firmware No fix yet Fix from $2,3002022-03-29 HIGH 8.8 CVE-2022-22688 Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStati… Diskstation Manager 6.2.4-25556-2 / 7.0.1-42214+ Fix from $1,9502022-03-25 CRITICAL 9.8 CVE-2022-26536 Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setFixTools. M3 Firmware No fix yet Fix from $2,3002022-03-24 CRITICAL 9.8 CVE-2022-27076 Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/delAd. M3 Firmware No fix yet Fix from $2,3002022-03-24 CRITICAL 9.8 CVE-2022-27077 Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic. M3 Firmware No fix yet Fix from $2,3002022-03-24 CRITICAL 9.8 CVE-2022-27078 Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setAdInfoDetail. M3 Firmware No fix yet Fix from $2,3002022-03-24 CRITICAL 9.8 CVE-2022-27079 Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem. M3 Firmware No fix yet Fix from $2,3002022-03-24 CRITICAL 9.8 CVE-2022-27080 Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode. M3 Firmware No fix yet Fix from $2,3002022-03-24 CRITICAL 9.8 CVE-2022-27081 Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetLanInfo. M3 Firmware No fix yet Fix from $2,3002022-03-24 CRITICAL 9.8 CVE-2022-27082 Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo. M3 Firmware No fix yet Fix from $2,3002022-03-24 CRITICAL 9.8 CVE-2022-27083 Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic. M3 Firmware No fix yet Fix from $2,3002022-03-24 CRITICAL 9.8 CVE-2022-26186 TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi. N600r Firmware No fix yet Fix from $2,3002022-03-22 CRITICAL 9.8 CVE-2022-26187EPSS 20% TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function. N600r Firmware No fix yet Fix from $2,3002022-03-22 CRITICAL 9.8 CVE-2022-26188 TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost. N600r Firmware No fix yet Fix from $2,3002022-03-22 CRITICAL 9.8 CVE-2022-26189 TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface. N600r Firmware No fix yet Fix from $2,3002022-03-22 CRITICAL 9.8 CVE-2021-45876 Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAnd… Wallbox Gtb Firmware after 185 Fix from $2,3002022-03-21 CRITICAL 9.8 CVE-2022-26996 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppo… Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-26997 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter. This vulnerability … Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-26998 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This … Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-26999 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_sta… Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15