Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
R1510 Firmware CRITICAL 9.8
CVE-2022-33314

Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted netw…

No fix yet
Fix from $2,300 2022-06-30
R1510 Firmware CRITICAL 9.8
CVE-2022-33325

Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted networ…

No fix yet
Fix from $2,300 2022-06-30
R1510 Firmware CRITICAL 9.8
CVE-2022-33326

Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted networ…

No fix yet
Fix from $2,300 2022-06-30
R1510 Firmware CRITICAL 9.8
CVE-2022-33327

Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted networ…

No fix yet
Fix from $2,300 2022-06-30
R1510 Firmware CRITICAL 9.8
CVE-2022-33328

Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted networ…

No fix yet
Fix from $2,300 2022-06-30
R1510 Firmware CRITICAL 9.8
CVE-2022-33329

Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted networ…

No fix yet
Fix from $2,300 2022-06-30
Marval Msm CRITICAL 9.8
CVE-2022-31885EPSS 32%

Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.

No fix yet
Fix from $2,300 2022-06-28
Dir 645 Firmware CRITICAL 9.8
CVE-2022-32092EPSS 6%

D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __ajax_explorer.sgi.

Fix: after 1.03
Fix from $2,300 2022-06-27
Ds A71024 Firmware CRITICAL 9.8
CVE-2022-28171EPSS 52%

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validat…

Fix: after 2.3.8-6
Fix from $2,300 2022-06-27
Cics Tx CRITICAL 9.8
CVE-2022-31767EPSS 5%

IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted reque…

Fix: 11.1+
Fix from $2,300 2022-06-24
Pra Es8p2s Firmware CRITICAL 9.8
CVE-2022-32534

The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostic…

Fix: after 1.01.05
Fix from $2,300 2022-06-23
OpenSSL HIGH 7.3
CVE-2022-2068EPSS 96%

In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sa…

Fix: 1.0 / 1.0.2zf+
Fix from $1,950 2022-06-21
Rg502q Ea Firmware CRITICAL 9.8
CVE-2022-26147

The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.

Fix: 2022-02-23+
Fix from $2,300 2022-06-21
Eternus Cs8000 Firmware CRITICAL 9.8
CVE-2022-31794

An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the request…

Fix: 8.1+
Fix from $2,300 2022-06-20
Eternus Cs8000 Firmware CRITICAL 9.8
CVE-2022-31795

An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_fi…

Fix: 8.1+
Fix from $2,300 2022-06-20
Tew 831dr Firmware CRITICAL 9.8
CVE-2022-30329

An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. An OS injection vulnerability exists within the web interface, allowing an attac…

Mitigation only
Fix from $2,300 2022-06-16
Hg9 Firmware HIGH 8.8
CVE-2022-30023EPSS 39%

Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

Mitigation only
Fix from $1,950 2022-06-16
Nifi HIGH 8.8
CVE-2022-33140

The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group …

Fix: after 1.16.2
Fix from $1,950 2022-06-15
Aerial X 1200m Firmware CRITICAL 9.8
CVE-2022-31311

An issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to execute arbitrary commands via a crafted POST request.

No fix yet
Fix from $2,300 2022-06-14
Ac18 Firmware CRITICAL 9.8
CVE-2022-31446EPSS 34%

Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/gof…

No fix yet
Fix from $2,300 2022-06-14
Controller Cecc X M1 Firmware CRITICAL 9.8
CVE-2022-30308

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for po…

Fix: after 3.8.14
Fix from $2,300 2022-06-13
Controller Cecc X M1 Firmware CRITICAL 9.8
CVE-2022-30309

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for p…

Fix: after 3.8.14
Fix from $2,300 2022-06-13
Controller Cecc X M1 Firmware CRITICAL 9.8
CVE-2022-30310

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syn…

Fix: after 3.8.14
Fix from $2,300 2022-06-13
Controller Cecc X M1 Firmware CRITICAL 9.8
CVE-2022-30311

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syn…

Fix: after 3.8.14
Fix from $2,300 2022-06-13
Zeroshell HIGH 8.8
CVE-2021-41738

ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system …

Mitigation only
Fix from $1,950 2022-06-11
Opennetadmin CRITICAL 9.8
CVE-2019-25065EPSS 7%

A vulnerability was found in OpenNetAdmin 18.1.1. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulati…

No fix yet
Fix from $2,300 2022-06-09
Ajenti HIGH 8.8
CVE-2019-25066EPSS 5%

A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipul…

Patch available
Fix from $1,950 2022-06-09
Gogs CRITICAL 9.8
CVE-2022-1986

OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.

Fix: 0.12.9+
Fix from $2,300 2022-06-09
Sila Firmware CRITICAL 9.8
CVE-2022-29013EPSS 77%

A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a cr…

No fix yet
Fix from $2,300 2022-06-09
Sma 210 Firmware HIGH 8.8
CVE-2022-1703EPSS 12%

Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inj…

Fix: after 10.2.1.4-31sv
Fix from $1,950 2022-06-08