Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Window Control HIGH 7.8
CVE-2022-25926

Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.

Fix: 1.4.5+
Fix from $1,950 2023-01-04
Fortitester HIGH 8.8
CVE-2022-35845

Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.…

Fix: after 3.9.1
Fix from $1,950 2023-01-03
Fortiadc HIGH 8.8
CVE-2022-39947

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiA…

Fix: after 6.2.3
Fix from $1,950 2023-01-03
Servisign HIGH 8.8
CVE-2022-46304

ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. An unauthenticated remote att…

Mitigation only
Fix from $1,950 2023-01-03
Usdk HIGH 7.2
CVE-2022-40740

Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrator can exploit this vulnerabi…

Mitigation only
Fix from $1,950 2023-01-03
Tew 755ap Firmware CRITICAL 9.8
CVE-2022-46597

TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydlink (sub_…

No fix yet
Fix from $2,300 2022-12-30
Tew 755ap Firmware CRITICAL 9.8
CVE-2022-46598

TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action set_sta_en…

No fix yet
Fix from $2,300 2022-12-30
For The Badge CRITICAL 9.8
CVE-2021-4281

A vulnerability was found in Brave UX for-the-badge and classified as critical. Affected by this issue is some unknown functionality of the file .git…

Fix: 1.2.0+
Fix from $2,300 2022-12-26
Wifiber 120ac Inmesh Firmware HIGH 8.8
CVE-2022-40005EPSS 35%

Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaf…

Fix: 1.1-220826+
Fix from $1,950 2022-12-25
M50 Firmware CRITICAL 9.8
CVE-2022-45717

IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartiti…

Mitigation only
Fix from $2,300 2022-12-23
M50 Firmware CRITICAL 9.8
CVE-2022-45709

IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule parameters in…

Mitigation only
Fix from $2,300 2022-12-23
M50 Firmware CRITICAL 9.8
CVE-2022-45711EPSS 20%

IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools func…

No fix yet
Fix from $2,300 2022-12-23
Rocket.chat CRITICAL 9.8
CVE-2022-44567

A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalVideoChat…

Fix: 3.8.14+
Fix from $2,300 2022-12-23
Activitywatch CRITICAL 9.6
CVE-2021-32692

Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macO…

Fix: 0.11.0+
Fix from $2,300 2022-12-23
Iboot Pdu4 N20 Firmware CRITICAL 9.8
CVE-2022-3183

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the …

Fix: 1.42.06162022+
Fix from $2,300 2022-12-21
Docconv CRITICAL 9.8
CVE-2022-4643

A vulnerability was found in docconv up to 1.2.0. It has been declared as critical. This vulnerability affects the function ConvertPDFImages of the f…

Fix: 1.2.1+
Fix from $2,300 2022-12-21
Abacus Ext Cmdline CRITICAL 9.8
CVE-2022-24431

All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper user-input sanitization.

No fix yet
Fix from $2,300 2022-12-21
Debian Linux HIGH 7.8
CVE-2022-4515

A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified i…

No fix yet
Fix from $1,950 2022-12-20
F1203 Firmware CRITICAL 9.8
CVE-2022-46538

Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.

No fix yet
Fix from $2,300 2022-12-20
Pfblockerng CRITICAL 9.8
CVE-2022-40624EPSS 17%

pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerabi…

Fix: 2.1.4_27+
Fix from $2,300 2022-12-20
Baijiacms HIGH 8.8
CVE-2022-45942EPSS 22%

A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.

No fix yet
Fix from $1,950 2022-12-20
P4 CRITICAL 9.8
CVE-2022-25171

The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization

Fix: 0.0.7+
Fix from $2,300 2022-12-20
Wsr 3200ax4s Firmware HIGH 8.8
CVE-2022-43443

OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a specially c…

Fix: after 1.26
Fix from $1,950 2022-12-19
Wsr 3200ax4s Firmware MEDIUM 6.8
CVE-2022-43466

OS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbit…

Fix: after 1.26
Fix from $1,600 2022-12-19
Conprosys Hmi System CRITICAL 9.8
CVE-2022-44456EPSS 70%

CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the …

Fix: after 3.4.4
Fix from $2,300 2022-12-19
Paydroid MEDIUM 6.8
CVE-2022-26580

PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries in the ADB …

Mitigation only
Fix from $1,600 2022-12-16
Paydroid HIGH 7.8
CVE-2022-26582

PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systool client. …

Mitigation only
Fix from $1,950 2022-12-16
Rax30 Firmware HIGH 7.8
CVE-2022-47210

The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, ap…

Fix: 1.0.9.90+
Fix from $1,950 2022-12-16
Nighthawk Ax1800 Firmware HIGH 8.8
CVE-2022-47208

The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated atta…

Fix: 1.0.9.90+
Fix from $1,950 2022-12-16
A7100ru Firmware CRITICAL 9.8
CVE-2022-46631

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWi…

No fix yet
Fix from $2,300 2022-12-15