Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2022-27000 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_b… Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-27001 Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability… Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-27002EPSS 5% Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host… Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-26995 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pptp_fix_m… Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2021-44620 A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters. A3100r Firmware after 4.1.2cu.5050_b20200504 Fix from $2,3002022-03-11 CRITICAL 9.8 CVE-2021-4045EPSS 72% TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd bin… Tapo C200 Firmware after 1.1.15 Fix from $2,3002022-03-10 HIGH 8.8 CVE-2021-41000 Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Ar… Arubaos Cx after 10.07.0020 Fix from $1,9502022-03-02 HIGH 8.8 CVE-2021-41001 An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch Series, Aru… Arubaos Cx after 10.09.0002 Fix from $1,9502022-03-02 HIGH 7.8 CVE-2021-44132 A command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers to execute arbitrary commands … C Data Onu4ferw Firmware after 2.1.13_x139 Fix from $1,9502022-02-25 HIGH 7.8 CVE-2021-40043 The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00). The devices cannot effectiv… Ais Bw80h 00 Firmware 9.0.3.4+ Fix from $1,9502022-02-25 CRITICAL 9.8 CVE-2021-39363 Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved. Hdzp252di Firmware Mitigation only Fix from $2,3002022-02-24 HIGH 7.8 CVE-2021-45082 An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Pyth… Fedora 3.3.1+ Fix from $1,9502022-02-19 CRITICAL 9.8 CVE-2022-25130 A command injection vulnerability in the function updateWifiInfo of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V… T6 Firmware Mitigation only Fix from $2,3002022-02-19 CRITICAL 9.8 CVE-2022-25131 A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B2021101… T6 Firmware Mitigation only Fix from $2,3002022-02-19 CRITICAL 9.8 CVE-2022-25132 A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows atta… T6 Firmware Mitigation only Fix from $2,3002022-02-19 CRITICAL 9.8 CVE-2022-25133 A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows a… T6 Firmware Mitigation only Fix from $2,3002022-02-19 CRITICAL 9.8 CVE-2022-25134 A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attac… T6 Firmware Mitigation only Fix from $2,3002022-02-19 CRITICAL 9.8 CVE-2022-25135 A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allow… T6 Firmware Mitigation only Fix from $2,3002022-02-19 CRITICAL 9.8 CVE-2022-25136 A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 … T6 Firmware Mitigation only Fix from $2,3002022-02-19 CRITICAL 9.8 CVE-2022-25137 A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T… T6 Firmware Mitigation only Fix from $2,3002022-02-19 CRITICAL 9.8 CVE-2021-45401 A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via the setUsbU… Ac10u Firmware No fix yet Fix from $2,3002022-02-18 HIGH 8.8 CVE-2021-41599 A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. To exploi… Enterprise Server 3.0.21 / 3.1.13+ Fix from $1,9502022-02-18 HIGH 8.8 CVE-2021-41552 CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection. Arris Surfboard Sbg6950ac2 Firmware Mitigation only Fix from $1,9502022-02-15 HIGH 8.8 CVE-2019-16864EPSS 8% CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that… Completeftp Server 12.1.4+ Fix from $1,9502022-02-14 CRITICAL 9.8 CVE-2022-24168 Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpGroup. This vulner… G1 Firmware No fix yet Fix from $2,3002022-02-04 CRITICAL 9.8 CVE-2022-24170 Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpSecTunnel. This vu… G1 Firmware No fix yet Fix from $2,3002022-02-04 CRITICAL 9.8 CVE-2022-24171 Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vu… G1 Firmware No fix yet Fix from $2,3002022-02-04 CRITICAL 9.8 CVE-2022-24148 Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function mDMZSetCfg. This vulnerability allows attackers… Ax3 Firmware No fix yet Fix from $2,3002022-02-04 CRITICAL 9.8 CVE-2022-24150 Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function formSetSafeWanWebMan. This vulnerability allows… Ax3 Firmware No fix yet Fix from $2,3002022-02-04 CRITICAL 9.8 CVE-2022-24165 Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetQvlanList. This vuln… G1 Firmware No fix yet Fix from $2,3002022-02-04