Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Fedora CRITICAL 9.8
CVE-2022-24065

The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Pyth…

Fix: 2.1.1+
Fix from $2,300 2022-06-08
Txpert Hub Coretec 4 Firmware MEDIUM 6.7
CVE-2021-35531

Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product, allows an attacke…

Mitigation only
Fix from $1,600 2022-06-07
Lp1501 Firmware HIGH 8.8
CVE-2022-31486

An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell commands. This vulnerability im…

Fix: 1.297 / 1.303+
Fix from $1,950 2022-06-06
Lp1501 Firmware CRITICAL 9.8
CVE-2022-31479

An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core c…

Fix: 1.296 / 1.302+
Fix from $2,300 2022-06-06
Ex1200t Firmware CRITICAL 9.8
CVE-2021-42890

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control …

No fix yet
Fix from $2,300 2022-06-03
Ex1200t Firmware CRITICAL 9.8
CVE-2021-42888

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which can control l…

No fix yet
Fix from $2,300 2022-06-03
Ex1200t Firmware CRITICAL 9.8
CVE-2021-42884

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file global.so which can control th…

No fix yet
Fix from $2,300 2022-06-03
Ex1200t Firmware CRITICAL 9.8
CVE-2021-42885

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file global.so which can control dev…

No fix yet
Fix from $2,300 2022-06-03
Powerstoreos HIGH 7.8
CVE-2022-26868

Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially ex…

Fix: 2.1.1.0+
Fix from $1,950 2022-06-02
Ex1200t Firmware CRITICAL 9.8
CVE-2021-42875

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.…

Mitigation only
Fix from $2,300 2022-06-02
Hg6 Firmware HIGH 8.8
CVE-2022-30425EPSS 20%

Tenda Technology Co.,Ltd HG6 3.3.0-210926 was discovered to contain a command injection vulnerability via the pingAddr and traceAddr parameters. This…

No fix yet
Fix from $1,950 2022-06-02
H500s Firmware HIGH 7.2
CVE-2021-44080EPSS 25%

A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitra…

No fix yet
Fix from $1,950 2022-06-02
Ex1200t Firmware CRITICAL 9.8
CVE-2021-42872EPSS 7%

TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.

Mitigation only
Fix from $2,300 2022-06-02
S3 Uploader CRITICAL 9.8
CVE-2021-34084

OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via …

Fix: after 2.0.3
Fix from $2,300 2022-06-02
Lifion Verifiy Dependencies HIGH 8.8
CVE-2021-34078

lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json fi…

Fix: 1.2.0+
Fix from $1,950 2022-06-02
Docker Tester CRITICAL 9.8
CVE-2021-34079

OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands via shell metacharacters in t…

Fix: after 1.2.1
Fix from $2,300 2022-06-02
Ssl Utils CRITICAL 9.8
CVE-2021-34080

OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metachar…

Fix: after 1.0.0
Fix from $2,300 2022-06-02
Gitsome HIGH 8.8
CVE-2021-34081

OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via a crafted tag name of the tar…

Fix: after 0.2.3
Fix from $1,950 2022-06-02
Proctree CRITICAL 9.8
CVE-2021-34082EPSS 5%

OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7593 for Node.js, allows attac…

Fix: after 0.1.1
Fix from $2,300 2022-06-02
Google It HIGH 8.1
CVE-2021-34083

Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open…

Fix: after 1.6.2
Fix from $1,950 2022-06-02
Secure Network Analytics CRITICAL 9.1
CVE-2022-20797

A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Cisco Stealthwatch Enterprise, could allow an authe…

Fix: 7.4.1+
Fix from $2,300 2022-05-27
Sharp MEDIUM 6.7
CVE-2022-29256

sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm in…

Fix: 0.30.5+
Fix from $1,600 2022-05-25
Fd702xw X R430 Firmware CRITICAL 9.8
CVE-2022-29337EPSS 35%

C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerab…

No fix yet
Fix from $2,300 2022-05-24
Vpn100 Firmware HIGH 7.8
CVE-2022-26532

A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series …

Fix: after 5.21
Fix from $1,950 2022-05-24
Rengine CRITICAL 9.8
CVE-2022-1813

OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.

Fix: 1.2.0+
Fix from $2,300 2022-05-22
Mailcow\ HIGH 8.8
CVE-2022-31245EPSS 5%

mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in co…

Fix: 2022-05d+
Fix from $1,950 2022-05-20
N4800eco Firmware CRITICAL 9.8
CVE-2021-34111

Thecus 4800Eco was discovered to contain a command injection vulnerability via the username parameter in /adm/setmain.php.

No fix yet
Fix from $2,300 2022-05-20
A1 Firmware HIGH 8.0
CVE-2021-42852

A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operat…

Fix: 5.3.6.t1 / 5.3.6.a1+
Fix from $1,950 2022-05-18
N300 Firmware CRITICAL 9.8
CVE-2022-30105

In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits mul…

No fix yet
Fix from $2,300 2022-05-18
Ipcom Ex2 Nw 1100 Firmware CRITICAL 9.8
CVE-2022-29516

The web console of FUJITSU Network IPCOM series (IPCOM EX2 IN(3200, 3500), IPCOM EX2 LB(1100, 3200, 3500), IPCOM EX2 SC(1100, 3200, 3500), IPCOM EX2 …

Mitigation only
Fix from $2,300 2022-05-18