Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Secure Firewall Management Center HIGH 7.2
CVE-2022-20925

A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker…

Mitigation only
Fix from $1,950 2022-11-15
Secure Firewall Management Center HIGH 8.8
CVE-2022-20926

A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker…

Mitigation only
Fix from $1,950 2022-11-15
W15e Firmware HIGH 7.8
CVE-2022-41396

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunne…

No fix yet
Fix from $1,950 2022-11-15
W15e Firmware HIGH 7.8
CVE-2022-42053

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in…

No fix yet
Fix from $1,950 2022-11-15
W15e Firmware HIGH 7.8
CVE-2022-41395

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDM…

No fix yet
Fix from $1,950 2022-11-15
W15e Firmware HIGH 7.8
CVE-2022-40847

In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. This vulnerabi…

No fix yet
Fix from $1,950 2022-11-15
Cloud Pak For Security HIGH 8.8
CVE-2022-38387

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on the system b…

Fix: after 1.10.2.0
Fix from $1,950 2022-11-11
Infosphere Information Server HIGH 7.8
CVE-2022-35717

"IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a special…

Patch available
Fix from $1,950 2022-11-03
Infosphere Information Server MEDIUM 5.4
CVE-2022-35642

"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Patch available
Fix from $1,600 2022-11-03
Fortitester HIGH 7.8
CVE-2022-33870

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 3.0.0 thro…

Patch available
Fix from $1,950 2022-11-02
Mail Sqr Expert CRITICAL 9.8
CVE-2022-40741

Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerabil…

Mitigation only
Fix from $2,300 2022-10-31
Total.js HIGH 8.8
CVE-2022-44019

In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.

Fix: 2022-09-26+
Fix from $1,950 2022-10-30
Aruba Edgeconnect Enterprise Orchestrator CRITICAL 9.8
CVE-2022-37915

A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to …

Fix: 9.1.3.40197+
Fix from $2,300 2022-10-28
Goodcloud MEDIUM 6.5
CVE-2022-42055

Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools…

No fix yet
Fix from $1,600 2022-10-27
Gl Mt300n V2 Firmware MEDIUM 6.8
CVE-2022-31898EPSS 16%

gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr …

No fix yet
Fix from $1,600 2022-10-27
Dir 816 Firmware HIGH 7.5
CVE-2022-42999

D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/set…

No fix yet
Fix from $1,950 2022-10-26
Azure Command Line Interface CRITICAL 9.8
CVE-2022-39327

Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code in…

Fix: 2.40.0+
Fix from $2,300 2022-10-25
Runner CRITICAL 9.9
CVE-2022-39321

GitHub Actions Runner is the application that runs a job from a GitHub Actions workflow. The actions runner invokes the docker cli directly in order …

Fix: 2.283.4 / 2.285.2+
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 10.0
CVE-2022-33194

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9…

Mitigation only
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 10.0
CVE-2022-33195

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9…

Mitigation only
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 9.9
CVE-2022-33204

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Se…

No fix yet
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 9.9
CVE-2022-33205

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Se…

No fix yet
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 9.9
CVE-2022-33206

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Se…

No fix yet
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 9.9
CVE-2022-33207

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Se…

No fix yet
Fix from $2,300 2022-10-25
R1510 Firmware HIGH 7.2
CVE-2022-34850

An OS command injection vulnerability exists in the web_server /action/import_authorized_keys/ functionality of Robustel R1510 3.1.16 and 3.3.0. A sp…

No fix yet
Fix from $1,950 2022-10-25
Usermin HIGH 8.8
CVE-2022-35132

Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module.

Fix: after 1.850
Fix from $1,950 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 9.8
CVE-2022-30541

An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A s…

No fix yet
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware HIGH 8.8
CVE-2022-30603EPSS 6%

An OS command injection vulnerability exists in the web interface /action/iperf functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9…

No fix yet
Fix from $1,950 2022-10-25
Iota All In One Security Kit Firmware HIGH 8.8
CVE-2022-32586

An OS command injection vulnerability exists in the web interface /action/ipcamRecordPost functionality of Abode Systems, Inc. iota All-In-One Securi…

No fix yet
Fix from $1,950 2022-10-25
R1510 Firmware CRITICAL 9.8
CVE-2022-32765

An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafte…

No fix yet
Fix from $2,300 2022-10-25