Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Iota All In One Security Kit Firmware CRITICAL 9.8
CVE-2022-32773

An OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A s…

No fix yet
Fix from $2,300 2022-10-25
R1510 Firmware CRITICAL 9.8
CVE-2022-33150

An OS command injection vulnerability exists in the js_package install functionality of Robustel R1510 3.1.16. A specially-crafted network request ca…

No fix yet
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 9.8
CVE-2022-33189

An OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially…

No fix yet
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 10.0
CVE-2022-33192

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9…

Mitigation only
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 10.0
CVE-2022-33193

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9…

Mitigation only
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 9.8
CVE-2022-27804

An os command injection vulnerability exists in the web interface util_set_abode_code functionality of Abode Systems, Inc. iota All-In-One Security K…

No fix yet
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 9.8
CVE-2022-29472

An OS command injection vulnerability exists in the web interface util_set_serial_mac functionality of Abode Systems, Inc. iota All-In-One Security K…

No fix yet
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 9.8
CVE-2022-29520

An OS command injection vulnerability exists in the console_main_loop :sys functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A …

No fix yet
Fix from $2,300 2022-10-25
Ox App Suite CRITICAL 9.8
CVE-2022-29851

documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversio…

Fix: after 7.10.6
Fix from $2,300 2022-10-25
Emc Powerscale Onefs MEDIUM 6.7
CVE-2022-34437

Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious user could potentially explo…

Fix: after 9.3.0.7
Fix from $1,600 2022-10-21
Dir 878 Firmware CRITICAL 9.8
CVE-2022-43184

D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.

Mitigation only
Fix from $2,300 2022-10-19
Tv 7104he Firmware CRITICAL 9.8
CVE-2016-20016EPSS 87%

MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthent…

No fix yet
Fix from $2,300 2022-10-19
Fortitester CRITICAL 9.8
CVE-2022-33872

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of …

Fix: 3.9.2 / 4.2.1+
Fix from $2,300 2022-10-18
Fortitester CRITICAL 9.8
CVE-2022-33873

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of…

Fix: 3.9.2 / 4.2.1+
Fix from $2,300 2022-10-18
Fortitester CRITICAL 9.8
CVE-2022-33874

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of For…

Fix: 3.9.2 / 4.2.1+
Fix from $2,300 2022-10-18
Fortitester HIGH 7.2
CVE-2022-35844

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 2.3.0 through …

Fix: 3.9.2 / 4.2.1+
Fix from $1,950 2022-10-18
Rava Certificate Validation System HIGH 7.2
CVE-2022-39057

RAVA certificate validation system has insufficient filtering for special parameter of the web page input field. A remote attacker with administrator…

Mitigation only
Fix from $1,950 2022-10-18
Fedora HIGH 7.8
CVE-2022-41751

Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.

Patch available
Fix from $1,950 2022-10-17
GitLab CRITICAL 9.9
CVE-2022-2884EPSS 76%

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated…

Fix: 15.1.5 / 15.2.3+
Fix from $2,300 2022-10-17
Human Resource Management System HIGH 8.8
CVE-2022-3492

A vulnerability classified as critical was found in SourceCodester Human Resource Management System 1.0. This vulnerability affects unknown code of t…

Mitigation only
Fix from $1,950 2022-10-13
Kylin CRITICAL 9.8
CVE-2022-24697EPSS 85%

Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can…

Fix: 2.6.6+
Fix from $2,300 2022-10-13
Container Storage Modules HIGH 8.8
CVE-2022-34427

Dell Container Storage Modules 1.2 contains an OS Command Injection in goiscsi and gobrick libraries. A remote unauthenticated attacker could exploit…

Fix: 2.0.0+
Fix from $1,950 2022-10-11
Desigo Pxm30 1 Firmware HIGH 8.0
CVE-2022-40176

A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM…

Fix: 02.20.126.11-37 / 02.20.126.11-41+
Fix from $1,950 2022-10-11
Fortios HIGH 8.0
CVE-2021-44171

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiO…

Fix: after 7.0.3
Fix from $1,950 2022-10-10
Puppetlabs Mysql HIGH 8.8
CVE-2022-3276

Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if…

Fix: 13.0.0+
Fix from $1,950 2022-10-07
Fedora CRITICAL 9.8
CVE-2022-3275

Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if th…

Fix: 9.0.0+
Fix from $2,300 2022-10-07
Arubaos HIGH 7.8
CVE-2022-37893

An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this…

Fix: 6.4.4.8-4.2.4.21 / 6.5.4.24+
Fix from $1,950 2022-10-07
Nr1800x Firmware CRITICAL 9.8
CVE-2022-41525

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cg…

No fix yet
Fix from $2,300 2022-10-06
Nr1800x Firmware CRITICAL 9.8
CVE-2022-41518

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/c…

No fix yet
Fix from $2,300 2022-10-06
Cli HIGH 7.8
CVE-2022-40764

Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the c…

Fix: 1.19.1 / 1.996.0+
Fix from $1,950 2022-10-03