Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
N350rt Firmware HIGH 7.8
CVE-2022-36481

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the ip parameter in the function setDiagnosisC…

No fix yet
Fix from $1,950 2022-08-25
N350rt Firmware HIGH 7.8
CVE-2022-36485

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpMo…

No fix yet
Fix from $1,950 2022-08-25
N350rt Firmware HIGH 7.8
CVE-2022-36486

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadF…

No fix yet
Fix from $1,950 2022-08-25
N350rt Firmware HIGH 7.8
CVE-2022-36487

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the command parameter in the function setTrace…

No fix yet
Fix from $1,950 2022-08-25
A720r Firmware HIGH 7.8
CVE-2022-36456

TOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.

No fix yet
Fix from $1,950 2022-08-25
A3700r Firmware HIGH 7.8
CVE-2022-36458

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the command parameter in the function setTrace…

No fix yet
Fix from $1,950 2022-08-25
A3700r Firmware HIGH 7.8
CVE-2022-36459

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyn…

No fix yet
Fix from $1,950 2022-08-25
A3700r Firmware HIGH 7.8
CVE-2022-36460

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadF…

No fix yet
Fix from $1,950 2022-08-25
A3700r Firmware HIGH 7.8
CVE-2022-36461

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpMo…

No fix yet
Fix from $1,950 2022-08-25
Bitbucket HIGH 8.8
CVE-2022-36804 KEVEPSS 99%

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from ver…

Fix: 7.6.17 / 7.17.10+
Fix from $1,950 2022-08-25
Mypro HIGH 8.8
CVE-2022-2234EPSS 42%

An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.

Fix: after 8.26.0
Fix from $1,950 2022-08-24
Teleport HIGH 8.8
CVE-2022-36633EPSS 49%

Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by …

Fix: 10.1.2+
Fix from $1,950 2022-08-24
Mr8300 Firmware HIGH 8.8
CVE-2022-38132

Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connect…

Mitigation only
Fix from $1,950 2022-08-24
Pcmanager HIGH 8.8
CVE-2022-1513

A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a specially craft…

Fix: 5.0.10.4191+
Fix from $1,950 2022-08-23
Archer A7 Firmware CRITICAL 9.8
CVE-2021-42232

TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the progr…

Mitigation only
Fix from $2,300 2022-08-23
Avideo HIGH 8.8
CVE-2022-32572EPSS 24%

An os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-…

No fix yet
Fix from $1,950 2022-08-22
Avideo HIGH 8.8
CVE-2022-30534EPSS 74%

An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A speci…

Mitigation only
Fix from $1,950 2022-08-22
Gitops Tools CRITICAL 9.8
CVE-2022-35976

The GitOps Tools Extension for VSCode relies on kubeconfigs in order to communicate with Kubernetes clusters. A specially crafted kubeconfig leads to…

Fix: after 0.20.9
Fix from $2,300 2022-08-18
Gitops Tools CRITICAL 9.8
CVE-2022-35975

The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution …

Fix: after 0.20.2
Fix from $2,300 2022-08-18
Flir Ax8 Firmware CRITICAL 9.8
CVE-2022-37061EPSS 100%

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject a…

Fix: after 1.46.16
Fix from $2,300 2022-08-18
Cmdb HIGH 8.8
CVE-2022-1410

OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authenticated attacker to execute re…

Fix: 18.01.00+
Fix from $1,950 2022-08-17
Ac9 Firmware CRITICAL 9.8
CVE-2022-36273

Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.

No fix yet
Fix from $2,300 2022-08-16
Wi Fi Network Adaptor Wap 001 Firmware HIGH 7.2
CVE-2022-36381

OS command injection vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to exec…

Mitigation only
Fix from $1,950 2022-08-16
Airvelocity 1500 Firmware HIGH 8.8
CVE-2022-36309EPSS 24%

Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the reco…

Fix: after 15.18.00.2511
Fix from $1,950 2022-08-16
Vr Calendar CRITICAL 9.8
CVE-2022-2314EPSS 17%

The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.

Fix: after 2.3.2
Fix from $2,300 2022-08-15
W6 Firmware CRITICAL 9.8
CVE-2022-35555EPSS 25%

A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters fo…

No fix yet
Fix from $2,300 2022-08-12
Rv160 Firmware CRITICAL 10.0
CVE-2022-20827

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to exe…

Fix: 1.0.01.05 / 1.0.03.26+
Fix from $2,300 2022-08-10
Linkhub Mesh Wifi Ac1200 CRITICAL 9.8
CVE-2022-21178

An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-…

No fix yet
Fix from $2,300 2022-08-05
Linkhub Mesh Wifi Ac1200 CRITICAL 9.8
CVE-2022-22140

An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-cra…

No fix yet
Fix from $2,300 2022-08-05
Michlol MEDIUM 5.5
CVE-2022-34769

Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. After he performs log into the sy…

Fix: 187.4392+
Fix from $1,600 2022-08-05