Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Dir 878 Firmware CRITICAL 9.8
CVE-2022-48107

D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerabil…

No fix yet
Fix from $2,300 2023-01-27
Dir 878 Firmware CRITICAL 9.8
CVE-2022-48108

D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerabi…

No fix yet
Fix from $2,300 2023-01-27
K2 Firmware HIGH 7.8
CVE-2022-48070

Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.

No fix yet
Fix from $1,950 2023-01-27
K2 Firmware HIGH 7.8
CVE-2022-48072

Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.

No fix yet
Fix from $1,950 2023-01-27
A830r Firmware HIGH 7.5
CVE-2022-48069

Totolink A830R V4.1.2cu.5182 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter.

No fix yet
Fix from $1,950 2023-01-27
Quartz Gold Firmware CRITICAL 9.8
CVE-2022-42493

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network reque…

Mitigation only
Fix from $2,300 2023-01-26
Quartz Gold Firmware CRITICAL 9.8
CVE-2022-42490

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network reque…

Mitigation only
Fix from $2,300 2023-01-26
Quartz Gold Firmware CRITICAL 9.8
CVE-2022-42491

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network reque…

Mitigation only
Fix from $2,300 2023-01-26
Quartz Gold Firmware CRITICAL 9.8
CVE-2022-42492

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network reque…

Mitigation only
Fix from $2,300 2023-01-26
Quartz Gold Firmware HIGH 8.8
CVE-2022-40969EPSS 6%

An os command injection vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafte…

No fix yet
Fix from $1,950 2023-01-26
Quartz Gold Firmware HIGH 8.8
CVE-2022-40220

An OS command injection vulnerability exists in the httpd txt/restore.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-cr…

No fix yet
Fix from $1,950 2023-01-26
Quartz Gold Firmware CRITICAL 9.8
CVE-2022-40222

An OS command injection vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-craf…

No fix yet
Fix from $2,300 2023-01-26
Quartz Gold Firmware HIGH 8.8
CVE-2022-38066EPSS 7%

An OS command injection vulnerability exists in the httpd SNMP functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP …

No fix yet
Fix from $1,950 2023-01-26
Script Security HIGH 8.8
CVE-2023-24422

A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with pe…

Fix: 1229.v4880b_b_e905a_6+
Fix from $1,950 2023-01-26
My Cloud Pr2100 Firmware CRITICAL 9.8
CVE-2022-29843

A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.…

Fix: 5.26.119+
Fix from $2,300 2023-01-26
Vagrant.js CRITICAL 9.8
CVE-2022-25962

All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.

Mitigation only
Fix from $2,300 2023-01-26
Simple Git CRITICAL 9.8
CVE-2022-25860

Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() metho…

Fix: 3.16.0+
Fix from $2,300 2023-01-26
Create Choo Electron CRITICAL 9.8
CVE-2022-25908

All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitiza…

No fix yet
Fix from $2,300 2023-01-26
Puppet Facter HIGH 7.8
CVE-2022-25350

All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.

No fix yet
Fix from $1,950 2023-01-26
Smartctl HIGH 7.8
CVE-2022-21810

All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization.

No fix yet
Fix from $1,950 2023-01-26
Dir 2150 Firmware HIGH 8.8
CVE-2022-40719

This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers. Authen…

Fix: after 4.0.1
Fix from $1,950 2023-01-26
Dir 2150 Firmware HIGH 8.8
CVE-2022-40720

This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers. Authen…

Fix: after 4.0.1
Fix from $1,950 2023-01-26
The Sleuth Kit HIGH 7.8
CVE-2022-45639

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter…

No fix yet
Fix from $1,950 2023-01-24
Application Delivery Controller HIGH 8.8
CVE-2022-37718

The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allow…

No fix yet
Fix from $1,950 2023-01-23
A7100ru Firmware CRITICAL 9.8
CVE-2022-48126

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username parameter in the setting/setOpenV…

No fix yet
Fix from $2,300 2023-01-20
A7100ru Firmware CRITICAL 9.8
CVE-2022-48124

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName parameter in the setting/setOpenV…

No fix yet
Fix from $2,300 2023-01-20
A7100ru Firmware CRITICAL 9.8
CVE-2022-48125

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the password parameter in the setting/setOpenV…

No fix yet
Fix from $2,300 2023-01-20
A7100ru Firmware CRITICAL 9.8
CVE-2022-48121

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits parameter in the setting/delStatic…

No fix yet
Fix from $2,300 2023-01-20
A7100ru Firmware CRITICAL 9.8
CVE-2022-48122

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid parameter in the setting/delStati…

No fix yet
Fix from $2,300 2023-01-20
A7100ru Firmware CRITICAL 9.8
CVE-2022-48123

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the setting/delSta…

No fix yet
Fix from $2,300 2023-01-20