Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Catalyst Sd Wan Manager MEDIUM 6.7
CVE-2022-20930

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt files on an affect…

Fix: 20.6.2+
Fix from $1,600 2022-09-30
Ios Xe HIGH 7.2
CVE-2022-20851

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against a…

Mitigation only
Fix from $1,950 2022-09-30
Ios Xe MEDIUM 6.7
CVE-2022-20855

A vulnerability in the self-healing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst Access Points could allow an…

Mitigation only
Fix from $1,600 2022-09-30
A860r Firmware CRITICAL 9.8
CVE-2022-40475

TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.

No fix yet
Fix from $2,300 2022-09-29
Xxl Job CRITICAL 9.8
CVE-2022-40929

XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended a…

No fix yet
Fix from $2,300 2022-09-28
Cpy Car Park Server CRITICAL 9.8
CVE-2022-28811

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper in…

Fix: 2.8.3 / 8.5.0.3+
Fix from $2,300 2022-09-28
Mipc Camera Firmware HIGH 8.8
CVE-2022-40785

Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3.1.2003161406. This allows an attacker to gain remot…

Mitigation only
Fix from $1,950 2022-09-26
Ruby Arr Pm HIGH 7.8
CVE-2022-39224

Arr-pm is an RPM reader/writer library written in Ruby. Versions prior to 0.0.12 are subject to OS command injection resulting in shell execution if …

Fix: 0.0.12+
Fix from $1,950 2022-09-21
Clearpass Policy Manager HIGH 7.2
CVE-2022-37878

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.12 / 6.10.7+
Fix from $1,950 2022-09-20
Clearpass Policy Manager HIGH 7.2
CVE-2022-37880

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.12 / 6.10.7+
Fix from $1,950 2022-09-20
Clearpass Policy Manager HIGH 7.2
CVE-2022-37882

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…

Fix: 6.9.12 / 6.10.7+
Fix from $1,950 2022-09-20
T6 Firmware CRITICAL 9.8
CVE-2022-38828EPSS 19%

TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi

No fix yet
Fix from $2,300 2022-09-16
T6 Firmware CRITICAL 9.8
CVE-2022-38826

In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.

No fix yet
Fix from $2,300 2022-09-16
A720r Firmware HIGH 7.2
CVE-2022-38534

TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setdiagnosicfg function.

No fix yet
Fix from $1,950 2022-09-15
A720r Firmware HIGH 7.2
CVE-2022-38535

TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg function.

No fix yet
Fix from $1,950 2022-09-15
A7000ru Firmware CRITICAL 9.8
CVE-2022-38308EPSS 20%

TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter in the function cstesystem. …

Patch available
Fix from $2,300 2022-09-14
1350 Optical Management System HIGH 8.8
CVE-2022-39819

In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execute commands on the operating s…

Mitigation only
Fix from $1,950 2022-09-13
1350 Optical Management System CRITICAL 9.8
CVE-2022-39815

In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on …

Mitigation only
Fix from $2,300 2022-09-13
M330 W Firmware CRITICAL 9.8
CVE-2022-36779

PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Proscend M330-w / M33-W5 / M350-…

Fix: 1.02 / 1.11+
Fix from $2,300 2022-09-13
M7350 Firmware CRITICAL 9.8
CVE-2022-37860EPSS 80%

The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerabil…

Patch available
Fix from $2,300 2022-09-12
Drawio HIGH 7.8
CVE-2022-3133

OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0.

Fix: 20.3.0+
Fix from $1,950 2022-09-09
Fortisoar HIGH 7.2
CVE-2022-29061

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2…

Fix: 7.0.3+
Fix from $1,950 2022-09-09
R6200 HIGH 8.8
CVE-2022-30079EPSS 25%

Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acos_service that could allow …

Mitigation only
Fix from $1,950 2022-09-08
Centrecom Ar260s Firmware HIGH 8.8
CVE-2022-35273

OS command injection vulnerability in GUI setting page of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated atta…

Fix: 3.3.7+
Fix from $1,950 2022-09-08
Centrecom Ar260s Firmware HIGH 8.8
CVE-2022-38094

OS command injection vulnerability in the telnet function of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated a…

Fix: 3.3.7+
Fix from $1,950 2022-09-08
Powercms CRITICAL 9.8
CVE-2022-33941

PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted message by POST method to Power…

Fix: after 6.021
Fix from $2,300 2022-09-08
G 97rg6m Firmware HIGH 8.8
CVE-2022-38531

FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function.

No fix yet
Fix from $1,950 2022-09-08
R6200 Firmware HIGH 8.8
CVE-2022-30078

NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0.4.52_10.0.93 allow remote au…

Fix: after 1.0.4.52_10.0.93
Fix from $1,950 2022-09-07
Aos Cx HIGH 7.8
CVE-2022-23682

Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. A successful exploit could al…

Fix: 10.06.0220 / 10.08.1080+
Fix from $1,950 2022-09-06
Aos Cx HIGH 7.2
CVE-2022-23683

Authenticated command injection vulnerabilities exist in the AOS-CX Network Analytics Engine via NAE scripts. Successful exploitation of these vulner…

Fix: 10.06.0220 / 10.08.1080+
Fix from $1,950 2022-09-06