Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Nginx Proxy Manager HIGH 8.8
CVE-2023-23596EPSS 15%

jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted u…

Fix: after 2.9.19
Fix from $1,950 2023-01-20
Rv340 Firmware HIGH 7.2
CVE-2023-20007

A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could all…

Fix: 1.0.03.29+
Fix from $1,950 2023-01-20
Identity Services Engine HIGH 8.8
CVE-2022-20964EPSS 31%

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbit…

Fix: 2.6.0+
Fix from $1,950 2023-01-20
Dir 859 A1 Firmware CRITICAL 9.8
CVE-2022-46476EPSS 41%

D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function.

No fix yet
Fix from $2,300 2023-01-19
Orangescrum HIGH 8.8
CVE-2023-0164

OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the applic…

No fix yet
Fix from $1,950 2023-01-18
Real Time Location System Studio HIGH 7.2
CVE-2022-47911

Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly validate the input module name to t…

Fix: after 2.6.2
Fix from $1,950 2023-01-18
Real Time Location System Studio HIGH 7.2
CVE-2022-43483

Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly validate the input module name to t…

Fix: after 2.6.2
Fix from $1,950 2023-01-18
Runner HIGH 8.0
CVE-2022-2251

Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows …

Fix: 15.3.5 / 15.4.4+
Fix from $1,950 2023-01-17
A7100ru Firmware CRITICAL 9.8
CVE-2022-47853

TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a stable root sh…

No fix yet
Fix from $2,300 2023-01-17
Maho Pbx Netdevancer Firmware CRITICAL 9.8
CVE-2023-22279

MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer Mobile…

Fix: 1.11.00+
Fix from $2,300 2023-01-17
Maho Pbx Netdevancer Firmware HIGH 7.2
CVE-2023-22280

MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer Mobile…

Fix: 1.11.00+
Fix from $1,950 2023-01-17
Pix Rt100 Firmware HIGH 8.0
CVE-2023-22304

OS command injection vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker who can a…

Mitigation only
Fix from $1,950 2023-01-17
Autolab HIGH 8.8
CVE-2022-41955

Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer au…

Fix: 2.10.0+
Fix from $1,950 2023-01-14
Global Modules Path CRITICAL 9.8
CVE-2022-21191

Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sa…

Fix: 3.0.0+
Fix from $2,300 2023-01-13
Dgx A100 Firmware HIGH 8.8
CVE-2022-42289

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code executi…

Fix: 00.19.07+
Fix from $1,950 2023-01-13
Dgx A100 Firmware HIGH 8.8
CVE-2022-42290

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code executi…

Fix: 00.19.07+
Fix from $1,950 2023-01-13
Dgx A100 Firmware HIGH 8.8
CVE-2022-42279

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code executi…

Fix: 00.19.07+
Fix from $1,950 2023-01-13
Inrouter302 Firmware HIGH 7.2
CVE-2023-22598

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CW…

Fix: 2.3.0.r5542 / 3.5.56+
Fix from $1,950 2023-01-12
Lte7480 M804 Firmware HIGH 8.8
CVE-2022-43390

A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker t…

Fix: 1.00 / 1.15+
Fix from $1,950 2023-01-11
Pi.alert CRITICAL 9.8
CVE-2022-48252

The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter) OS Command Injection.

No fix yet
Fix from $2,300 2023-01-11
Wumc710 Firmware HIGH 7.2
CVE-2022-43971

An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <= 1.0.02 (build3). The do_set…

Fix: 1.0.02+
Fix from $1,950 2023-01-09
Wrt54gl Firmware HIGH 7.2
CVE-2022-43973

An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI functio…

Fix: after 4.30.18.006
Fix from $1,950 2023-01-09
Rooms HIGH 7.8
CVE-2022-36926

Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this…

Fix: 5.11.3+
Fix from $1,950 2023-01-09
Wifey CRITICAL 9.8
CVE-2022-25890

All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.

No fix yet
Fix from $2,300 2023-01-09
Amp300 Firmware HIGH 8.8
CVE-2022-44149EPSS 64%

The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON…

No fix yet
Fix from $1,950 2023-01-06
Exec Local Bin CRITICAL 9.8
CVE-2022-25923

Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input…

Fix: 1.2.0+
Fix from $2,300 2023-01-06
Webpanel CRITICAL 9.8
CVE-2022-44877 KEVEPSS 100%

login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via s…

Fix: 0.9.8.1147+
Fix from $2,300 2023-01-05
Clearpass Policy Manager HIGH 8.8
CVE-2022-43536

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.12 / 6.10.7+
Fix from $1,950 2023-01-05
Clearpass Policy Manager HIGH 7.2
CVE-2022-43537

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.12 / 6.10.7+
Fix from $1,950 2023-01-05
Clearpass Policy Manager HIGH 7.2
CVE-2022-43538

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.12 / 6.10.7+
Fix from $1,950 2023-01-05