Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Wl Wn535k2 Firmware CRITICAL 9.8
CVE-2022-2488EPSS 33%

A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/…

No fix yet
Fix from $2,300 2022-07-20
Megapix Firmware HIGH 8.8
CVE-2022-34538

Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/ad…

Mitigation only
Fix from $1,950 2022-07-19
Megapix Firmware HIGH 8.8
CVE-2022-34539

Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/curltest.c…

Mitigation only
Fix from $1,950 2022-07-19
Megapix Firmware HIGH 8.8
CVE-2022-34540

Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/licens…

Mitigation only
Fix from $1,950 2022-07-19
Fir303b Firmware HIGH 8.8
CVE-2022-27373

Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerability via…

No fix yet
Fix from $1,950 2022-07-19
Fortianalyzer HIGH 7.2
CVE-2022-27483

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.…

Fix: after 7.0.3
Fix from $1,950 2022-07-19
Spark HIGH 8.8
CVE-2022-33891 KEVEPSS 93%

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks …

Fix: after 3.2.1
Fix from $1,950 2022-07-18
Studio X30 Firmware HIGH 8.8
CVE-2022-26481

An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) actio…

Fix: 3.7.0+
Fix from $1,950 2022-07-17
Eagleeye Director Ii Firmware HIGH 7.2
CVE-2022-26482EPSS 23%

An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.

Fix: 2.2.2.1+
Fix from $1,950 2022-07-17
Node.js HIGH 8.1
CVE-2022-32212EPSS 6%

A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easil…

Fix: 1.0 / 14.20.1+
Fix from $1,950 2022-07-14
Lvskihp Indoorunit Firmware CRITICAL 9.8
CVE-2022-28373

Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition function of th…

No fix yet
Fix from $2,300 2022-07-14
Lvskihp Outdoorunit Firmware HIGH 8.8
CVE-2022-28374

Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settings page…

No fix yet
Fix from $1,950 2022-07-14
Lvskihp Outdoorunit Firmware CRITICAL 9.8
CVE-2022-28375

Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function o…

No fix yet
Fix from $2,300 2022-07-14
Spacelogic C Bus Home Controller Firmware HIGH 8.8
CVE-2022-34753EPSS 71%

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote roo…

Fix: after 1.31.460
Fix from $1,950 2022-07-13
Cloud Commerce CRITICAL 9.8
CVE-2022-28888

Spryker Commerce OS 1.4.2 allows Remote Command Execution.

Fix: 1.7.0+
Fix from $2,300 2022-07-13
My Cloud Home Duo Firmware CRITICAL 9.8
CVE-2022-22997

Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed …

Fix: 8.5.1-102+
Fix from $2,300 2022-07-12
Insync Client HIGH 7.8
CVE-2021-36667

Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP…

Fix: 7.0.0+
Fix from $1,950 2022-07-12
Mailcow\ HIGH 8.8
CVE-2022-31138

mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the…

Fix: 2022-06a+
Fix from $1,950 2022-07-11
Roxy Wi CRITICAL 9.8
CVE-2022-31137EPSS 90%

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code executi…

Fix: 6.1.1.0+
Fix from $2,300 2022-07-08
Ac10 Firmware CRITICAL 9.8
CVE-2022-32054EPSS 32%

Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter.

Patch available
Fix from $2,300 2022-07-07
Webpanel HIGH 8.8
CVE-2022-25048EPSS 19%

Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.

No fix yet
Fix from $1,950 2022-07-07
Ax1803 Firmware CRITICAL 9.8
CVE-2022-34595

Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status.

No fix yet
Fix from $2,300 2022-07-06
Ax1803 Firmware CRITICAL 9.8
CVE-2022-34596

Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSetting.

No fix yet
Fix from $2,300 2022-07-06
Ax1806 Firmware CRITICAL 9.8
CVE-2022-34597

Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting.

No fix yet
Fix from $2,300 2022-07-06
Home Spot Cube 2 Firmware HIGH 8.8
CVE-2022-33948

HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHCP server. An adjacent attacke…

Mitigation only
Fix from $1,950 2022-07-04
GitLab HIGH 8.8
CVE-2022-2185EPSS 77%

A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15…

Fix: 14.10.5 / 15.0.4+
Fix from $1,950 2022-07-01
Webhmi Firmware CRITICAL 9.1
CVE-2022-2253

A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 may send OS commands to execute on the host server.

Fix: after 4.1.1.7662
Fix from $2,300 2022-07-01
Awesomespawn CRITICAL 9.8
CVE-2014-0156

Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If unt…

Fix: 1.5.0+
Fix from $2,300 2022-06-30
R1510 Firmware CRITICAL 9.8
CVE-2022-33312

Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted netw…

No fix yet
Fix from $2,300 2022-06-30
R1510 Firmware CRITICAL 9.8
CVE-2022-33313

Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted netw…

No fix yet
Fix from $2,300 2022-06-30