Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Debian Linux CRITICAL 9.8
CVE-2022-48337

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses …

Fix: after 28.2
Fix from $2,300 2023-02-20
Checkmk HIGH 7.5
CVE-2022-46303

Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Mana…

Mitigation only
Fix from $1,950 2023-02-20
Fortiweb HIGH 8.8
CVE-2023-23779

Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb version 7.0.…

Fix: after 6.3.19
Fix from $1,950 2023-02-16
Fortiadc HIGH 7.8
CVE-2022-27482

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.1, 6.2.0 …

Fix: 6.2.4+
Fix from $1,950 2023-02-16
Fortiextender Firmware HIGH 7.2
CVE-2022-27489

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.0.0 through 7.0.3, 5.3.2, 4.…

Fix: 3.2.4 / 3.3.3+
Fix from $1,950 2023-02-16
Fortiweb HIGH 8.8
CVE-2022-30303

An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through…

Fix: 6.3.20+
Fix from $1,950 2023-02-16
Fortiwan HIGH 8.8
CVE-2022-33869

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5…

Fix: 4.5.10+
Fix from $1,950 2023-02-16
Netmodule Router Software HIGH 8.8
CVE-2023-0861EPSS 29%

NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authe…

Fix: 4.3.0.119 / 4.4.0.118+
Fix from $1,950 2023-02-16
Easynas HIGH 8.8
CVE-2023-0830EPSS 21%

A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation lead…

No fix yet
Fix from $1,950 2023-02-14
Ic3000 Industrial Compute Gateway HIGH 8.8
CVE-2023-20076

A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root …

Fix: 1.4.2 / 1.10.0.1+
Fix from $1,950 2023-02-12
Evasa Provider Virtual Appliance HIGH 8.8
CVE-2022-45104

Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low priv…

Fix: 9.2.3.6 / 9.2.4.15+
Fix from $1,950 2023-02-11
Powerpath Management Appliance HIGH 7.2
CVE-2022-34447

PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains OS Command Injection vulnerability. An authenticated remote attacker wit…

Mitigation only
Fix from $1,950 2023-02-11
Ipython HIGH 7.0
CVE-2023-24816

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python prog…

Fix: 8.10.0+
Fix from $1,950 2023-02-10
Aleos HIGH 8.8
CVE-2022-46649

Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell comman…

Fix: after 4.16.0
Fix from $1,950 2023-02-10
Ecu R Firmware CRITICAL 9.8
CVE-2022-45699EPSS 77%

Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary comma…

No fix yet
Fix from $2,300 2023-02-10
Jitsi CRITICAL 9.8
CVE-2022-43550

A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which cou…

Fix: 2022-09-14+
Fix from $2,300 2023-02-09
Br 6428ns Firmware HIGH 8.8
CVE-2022-45768EPSS 29%

Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute arbitrary code via…

No fix yet
Fix from $1,950 2023-02-07
Wrangler CRITICAL 9.8
CVE-2022-31249

A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in wrangler of SUSE Rancher allows remote …

Fix: 0.7.4 / 0.8.5+
Fix from $2,300 2023-02-07
Rancher MEDIUM 6.8
CVE-2022-43758

A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for …

Fix: 2.5.17 / 2.6.10+
Fix from $1,600 2023-02-07
Libzypp Plugin Appdata HIGH 7.8
CVE-2023-22643

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in libzypp-plugin-appdata of SUSE Linux E…

Fix: 1.0.1+
Fix from $1,950 2023-02-07
Atp100 Firmware HIGH 7.2
CVE-2022-38547

A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPN series f…

Fix: after 5.32
Fix from $1,950 2023-02-07
Create Choo App3 HIGH 7.8
CVE-2022-25855

All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.

No fix yet
Fix from $1,950 2023-02-06
Semver Tags HIGH 7.8
CVE-2022-25853

All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization.

No fix yet
Fix from $1,950 2023-02-06
Dir 846 Firmware HIGH 8.8
CVE-2022-46552EPSS 11%

D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist paramete…

No fix yet
Fix from $1,950 2023-02-02
Manageengine Supportcenter Plus CRITICAL 9.8
CVE-2023-23076EPSS 74%

OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.

Mitigation only
Fix from $2,300 2023-02-01
Emc Data Domain Os HIGH 8.8
CVE-2023-23692

Dell EMC prior to version DDOS 7.9 contain(s) an OS command injection Vulnerability. An authenticated non admin attacker could potentially exploit th…

Fix: 6.2.1.90 / 7.7.3+
Fix from $1,950 2023-02-01
Mt7688 Wiscan HIGH 7.8
CVE-2022-25916

Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' functi…

Fix: 0.8.3+
Fix from $1,950 2023-02-01
Is Http2 HIGH 7.8
CVE-2022-25906

All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being emplo…

No fix yet
Fix from $1,950 2023-02-01
Nemo Appium CRITICAL 9.8
CVE-2022-21129

Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup'…

Fix: 0.0.9+
Fix from $2,300 2023-01-31
Freshtomato CRITICAL 9.8
CVE-2022-42484EPSS 6%

An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lea…

No fix yet
Fix from $2,300 2023-01-30