Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Aos Cx HIGH 7.8
CVE-2022-23681

Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. A successful exploit could al…

Fix: 10.06.0220 / 10.08.1080+
Fix from $1,950 2022-09-06
Raid Manager Storage Replication Adapter HIGH 8.8
CVE-2022-34883

OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to execute arbitrary OS comm…

Fix: 02.03.02+
Fix from $1,950 2022-09-06
Geonetwork HIGH 7.2
CVE-2021-28398

A privileged attacker in GeoNetwork before 3.12.0 and 4.x before 4.0.4 can use the directory harvester before-script to execute arbitrary OS commands…

Fix: 3.12.0 / 4.0.4+
Fix from $1,950 2022-09-05
Pfblockerng CRITICAL 9.8
CVE-2022-31814EPSS 88%

pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host heade…

Fix: after 2.1.4_26
Fix from $2,300 2022-09-05
Debian Linux HIGH 8.8
CVE-2022-3008

The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. T…

Fix: 2.6.0+
Fix from $1,950 2022-09-05
Dir 816 Firmware HIGH 8.8
CVE-2022-37123

D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.

No fix yet
Fix from $1,950 2022-08-31
Dir 816 Firmware HIGH 8.8
CVE-2022-37129EPSS 8%

D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it wil…

No fix yet
Fix from $1,950 2022-08-31
Dir 816 Firmware CRITICAL 9.8
CVE-2022-37130EPSS 26%

In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is …

No fix yet
Fix from $2,300 2022-08-31
Edge Gateway 5200 Firmware HIGH 8.2
CVE-2022-34383

Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A local malicious user may potentia…

Fix: 1.03.10+
Fix from $1,950 2022-08-31
Rengine CRITICAL 9.8
CVE-2022-36566

Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.

No fix yet
Fix from $2,300 2022-08-31
Rpi Jukebox Rfid CRITICAL 9.8
CVE-2022-36749

RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is …

Patch available
Fix from $2,300 2022-08-30
Smartfabric Storage Software CRITICAL 9.8
CVE-2022-31232

SmartFabric storage software version 1.0.0 contains a Command-Injection vulnerability. A remote unauthenticated attacker may potentially exploit this…

Mitigation only
Fix from $2,300 2022-08-30
Container Storage Modules HIGH 8.8
CVE-2022-34374

Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authenticated malicious user with low …

Fix: 1.3.0+
Fix from $1,950 2022-08-30
Wl Wn575a3 Firmware CRITICAL 9.8
CVE-2022-37149

WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerabili…

No fix yet
Fix from $2,300 2022-08-30
A810r Firmware HIGH 7.8
CVE-2022-38511

TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi.

No fix yet
Fix from $1,950 2022-08-29
Go Rt Ac750 Firmware CRITICAL 9.8
CVE-2022-37056EPSS 10%

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main,

Patch available
Fix from $2,300 2022-08-28
Go Rt Ac750 Firmware CRITICAL 9.8
CVE-2022-37057EPSS 25%

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main.

Patch available
Fix from $2,300 2022-08-28
Emerge E3 Firmware CRITICAL 9.8
CVE-2022-31499EPSS 65%

Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists …

Fix: after 0.32-09c
Fix from $2,300 2022-08-25
Firepower 4110 Firmware MEDIUM 6.7
CVE-2022-20865

A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro…

Mitigation only
Fix from $1,600 2022-08-25
Ac1206 Firmware CRITICAL 9.8
CVE-2022-37810

Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.

No fix yet
Fix from $2,300 2022-08-25
A7000r Firmware HIGH 7.8
CVE-2022-37083

TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the ip parameter at the function setDiagnosisC…

No fix yet
Fix from $1,950 2022-08-25
A3600r Firmware HIGH 7.8
CVE-2022-36455

TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.

No fix yet
Fix from $1,950 2022-08-25
A7000r Firmware HIGH 7.8
CVE-2022-37079

TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpMo…

No fix yet
Fix from $1,950 2022-08-25
A7000r Firmware HIGH 7.8
CVE-2022-37081

TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the command parameter at setting/setTraceroute…

No fix yet
Fix from $1,950 2022-08-25
A7000r Firmware HIGH 7.8
CVE-2022-37082

TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the host_time parameter at the function NTPSyn…

No fix yet
Fix from $1,950 2022-08-25
Gr 1200w Firmware CRITICAL 9.8
CVE-2022-37070EPSS 11%

H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.

No fix yet
Fix from $2,300 2022-08-25
A7000r Firmware HIGH 7.8
CVE-2022-37076

TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadF…

No fix yet
Fix from $1,950 2022-08-25
Gr3200 Firmware HIGH 7.8
CVE-2022-36509EPSS 12%

H3C GR3200 MiniGR1B0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.

No fix yet
Fix from $1,950 2022-08-25
Gr2200 Firmware HIGH 7.8
CVE-2022-36510EPSS 12%

H3C GR2200 MiniGR1A0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.

No fix yet
Fix from $1,950 2022-08-25
N350rt Firmware HIGH 7.8
CVE-2022-36479

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyn…

No fix yet
Fix from $1,950 2022-08-25