Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Cacti CRITICAL 9.8
CVE-2022-46169 KEVEPSS 100%

Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected …

Fix: 1.2.23+
Fix from $2,300 2022-12-05
Nadesiko3 CRITICAL 9.8
CVE-2022-42496

OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain ap…

Fix: after 3.3.74
Fix from $2,300 2022-12-05
Nadesiko3 CRITICAL 9.8
CVE-2022-41642

OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.61 and earlier allows a remote attacker to execute an arbitrary OS command when pro…

Fix: after 3.3.68
Fix from $2,300 2022-12-05
Dhp W310av Firmware CRITICAL 9.8
CVE-2022-44930

D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.

No fix yet
Fix from $2,300 2022-12-02
Omnia Mpx Node Firmware CRITICAL 9.8
CVE-2022-43325

An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows a…

No fix yet
Fix from $2,300 2022-12-02
Dvg G5402sp Firmware CRITICAL 9.8
CVE-2022-44928

D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

No fix yet
Fix from $2,300 2022-12-02
Xg Firewall Firmware HIGH 7.2
CVE-2022-3226

An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version …

Fix: after 19.0
Fix from $1,950 2022-12-01
C Data Web Management System CRITICAL 9.8
CVE-2022-4257EPSS 44%

A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknown processing of the file cgi-…

No fix yet
Fix from $2,300 2022-12-01
Nas M25 Firmware CRITICAL 9.8
CVE-2022-4221

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated at…

Fix: after 1.0.1.7
Fix from $2,300 2022-12-01
Mbd6304t HIGH 8.8
CVE-2022-45045

Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow …

No fix yet
Fix from $1,950 2022-12-01
Br270n Firmware HIGH 8.8
CVE-2021-4242

A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical. Affected by this issue is some unknown functionality…

No fix yet
Fix from $1,950 2022-11-30
Snyk Cli MEDIUM 6.3
CVE-2022-22984

The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-coc…

Fix: 1.1.6 / 1.24.2+
Fix from $1,600 2022-11-30
Snyk Cli HIGH 8.8
CVE-2022-24441

The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious p…

Fix: 1.1064.0+
Fix from $1,950 2022-11-30
Orion Platform HIGH 7.2
CVE-2022-36962EPSS 9%

SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds data…

Fix: 2020.2.6+
Fix from $1,950 2022-11-29
Debian Linux HIGH 7.8
CVE-2022-45939

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses …

Fix: after 28.2
Fix from $1,950 2022-11-28
A7100ru Firmware CRITICAL 9.8
CVE-2022-44843

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnCl…

No fix yet
Fix from $2,300 2022-11-25
A7100ru Firmware CRITICAL 9.8
CVE-2022-44844

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCf…

No fix yet
Fix from $2,300 2022-11-25
Lr350 Firmware CRITICAL 9.8
CVE-2022-44249

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.

No fix yet
Fix from $2,300 2022-11-23
Lr350 Firmware CRITICAL 9.8
CVE-2022-44250

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.

No fix yet
Fix from $2,300 2022-11-23
Lr350 Firmware CRITICAL 9.8
CVE-2022-44251

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.

No fix yet
Fix from $2,300 2022-11-23
Lr350 Firmware CRITICAL 9.8
CVE-2022-44252

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.

No fix yet
Fix from $2,300 2022-11-23
Sourcegraph HIGH 7.8
CVE-2022-41942

Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present i…

Fix: 4.1.0+
Fix from $1,950 2022-11-22
Dir 823g Firmware CRITICAL 9.8
CVE-2022-44808

A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrar…

No fix yet
Fix from $2,300 2022-11-22
Dir 823g Firmware CRITICAL 9.8
CVE-2022-44201

D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

No fix yet
Fix from $2,300 2022-11-22
Airflow CRITICAL 9.8
CVE-2022-40189

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airfl…

Fix: 2.3.0 / 4.0.0+
Fix from $2,300 2022-11-22
Airflow MEDIUM 5.5
CVE-2022-40954

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Air…

Fix: 2.3.0 / 4.0.0+
Fix from $1,600 2022-11-22
Airflow HIGH 7.8
CVE-2022-41131

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airf…

Fix: 2.3.0 / 4.1.0+
Fix from $1,950 2022-11-22
Airflow CRITICAL 9.8
CVE-2022-38649

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Air…

Fix: 2.3.0 / 4.0.0+
Fix from $2,300 2022-11-22
Netbackup HIGH 8.8
CVE-2022-45461

The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that hav…

Fix: after 10.1
Fix from $1,950 2022-11-17
Secure Firewall Threat Defense MEDIUM 6.7
CVE-2022-20934

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to e…

Fix: after 7.0.4
Fix from $1,600 2022-11-15