Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
A7100ru Firmware CRITICAL 9.8
CVE-2022-46634

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWi…

No fix yet
Fix from $2,300 2022-12-15
Cycle Import Check CRITICAL 9.8
CVE-2022-24377

The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-inpu…

Fix: 1.3.2+
Fix from $2,300 2022-12-14
Dvw W02w2 E2 Firmware HIGH 8.8
CVE-2022-42139EPSS 18%

Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.

No fix yet
Fix from $1,950 2022-12-14
Dx 2100 L1 Cn Firmware HIGH 7.2
CVE-2022-42140

Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.

No fix yet
Fix from $1,950 2022-12-14
Ew9 Firmware CRITICAL 9.8
CVE-2022-45005EPSS 5%

IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function.

No fix yet
Fix from $2,300 2022-12-13
W20e Firmware HIGH 7.2
CVE-2022-45996

Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.

No fix yet
Fix from $1,950 2022-12-12
Ax12 Firmware HIGH 8.8
CVE-2022-45043

Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set.

No fix yet
Fix from $1,950 2022-12-12
Ax12 Firmware HIGH 8.8
CVE-2022-45977

Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.

No fix yet
Fix from $1,950 2022-12-12
Sd Wan HIGH 8.8
CVE-2022-37912

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results…

Fix: 6.5.4.22 / 8.6.0.17+
Fix from $1,950 2022-12-12
Edgeconnect Enterprise HIGH 7.2
CVE-2022-37924

Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlyi…

Fix: after 9.2.1.0
Fix from $1,950 2022-12-12
Sd Wan CRITICAL 9.8
CVE-2022-37897

There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to …

Fix: 6.5.4.22 / 8.6.0.17+
Fix from $2,300 2022-12-12
Sd Wan HIGH 7.2
CVE-2022-37898

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results…

Fix: 6.5.4.23 / 8.6.0.18+
Fix from $1,950 2022-12-12
Sd Wan HIGH 7.2
CVE-2022-37899

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results…

Fix: 6.5.4.23 / 8.6.0.18+
Fix from $1,950 2022-12-12
Sd Wan HIGH 7.2
CVE-2022-37900

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results…

Fix: 6.5.4.23 / 8.6.0.18+
Fix from $1,950 2022-12-12
Sd Wan HIGH 7.2
CVE-2022-37901

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results…

Fix: 6.5.4.23 / 8.6.0.18+
Fix from $1,950 2022-12-12
Sd Wan HIGH 7.2
CVE-2022-37902

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results…

Fix: 6.5.4.23 / 8.6.0.18+
Fix from $1,950 2022-12-12
Chicken CRITICAL 9.8
CVE-2022-45145

egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.

Fix: 5.3.1+
Fix from $2,300 2022-12-10
Fabric Operating System CRITICAL 9.8
CVE-2022-33186

A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker t…

Mitigation only
Fix from $2,300 2022-12-08
W6 S Firmware CRITICAL 9.8
CVE-2022-45497

Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommand.

No fix yet
Fix from $2,300 2022-12-08
W30e Firmware CRITICAL 9.8
CVE-2022-45506

Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.

No fix yet
Fix from $2,300 2022-12-08
Flir Ax8 Firmware CRITICAL 9.8
CVE-2022-4364

A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of th…

Fix: 1.46.16+
Fix from $2,300 2022-12-08
Udr Ja1604 Firmware HIGH 8.8
CVE-2022-44606

OS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated…

Fix: 71x10.1.107114.43a+
Fix from $1,950 2022-12-07
Udr Ja1604 Firmware HIGH 8.8
CVE-2022-43464

Hidden functionality vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated…

Fix: 71x10.1.107114.43a+
Fix from $1,950 2022-12-07
Markdown Preview Enhanced CRITICAL 9.8
CVE-2022-45025EPSS 35%

Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import …

No fix yet
Fix from $2,300 2022-12-07
Markdown Preview Enhanced CRITICAL 9.8
CVE-2022-45026

An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GFM export pro…

No fix yet
Fix from $2,300 2022-12-07
Ilias HIGH 8.8
CVE-2022-45915

ILIAS before 7.16 allows OS Command Injection.

Fix: 7.16+
Fix from $1,950 2022-12-07
Spectrum Scale Container Native Storage Access HIGH 7.8
CVE-2022-43867

IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437.

Fix: after 5.1.4.1
Fix from $1,950 2022-12-06
Stcg2000300 Firmware CRITICAL 9.8
CVE-2020-6627EPSS 12%

The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_la…

Patch available
Fix from $2,300 2022-12-06
Simple Git CRITICAL 9.8
CVE-2022-25912

The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitab…

Fix: 3.15.0+
Fix from $2,300 2022-12-06
Node.js HIGH 8.1
CVE-2022-43548EPSS 14%

A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that…

Fix: 14.21.1 / 16.18.1+
Fix from $1,950 2022-12-05