Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Cnmaestro HIGH 7.5
CVE-2022-1359

The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside…

Mitigation only
Fix from $1,950 2022-05-17
Cnmaestro CRITICAL 9.8
CVE-2022-1360

The affected On-Premise cnMaestro is vulnerable to execution of code on the cnMaestro hosting server. This could allow a remote attacker to change se…

Mitigation only
Fix from $2,300 2022-05-17
Cnmaestro HIGH 7.3
CVE-2022-1362

The affected On-Premise cnMaestro is vulnerable inside a specific route where a user can upload a crafted package to the system. An attacker could ab…

Mitigation only
Fix from $1,950 2022-05-17
Cnmaestro HIGH 7.8
CVE-2022-1356

cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, w…

Mitigation only
Fix from $1,950 2022-05-17
Cnmaestro CRITICAL 9.8
CVE-2022-1357

The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of t…

Mitigation only
Fix from $2,300 2022-05-17
Deception HIGH 8.8
CVE-2022-24388

Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deceptio…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24389

Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and De…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24390

Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network …

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24392

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “feed_comm_tes…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24393

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24394

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkf…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Clearpass Policy Manager HIGH 7.2
CVE-2022-23672

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below…

Fix: 6.8.9+
Fix from $1,950 2022-05-17
Clearpass Policy Manager HIGH 7.2
CVE-2022-23673

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below…

Fix: 6.8.9+
Fix from $1,950 2022-05-17
Clearpass Policy Manager HIGH 7.2
CVE-2022-23667

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below…

Fix: 6.8.9 / 6.9.10+
Fix from $1,950 2022-05-16
Clearpass Policy Manager CRITICAL 9.1
CVE-2022-23661

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below…

Fix: 6.8.9 / 6.9.10+
Fix from $2,300 2022-05-16
Clearpass Policy Manager CRITICAL 9.1
CVE-2022-23662

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below…

Fix: 6.8.9 / 6.9.10+
Fix from $2,300 2022-05-16
Clearpass Policy Manager CRITICAL 9.1
CVE-2022-23663

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below…

Fix: 6.8.9 / 6.9.10+
Fix from $2,300 2022-05-16
Clearpass Policy Manager CRITICAL 9.1
CVE-2022-23664

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below…

Fix: 6.8.9 / 6.9.10+
Fix from $2,300 2022-05-16
Clearpass Policy Manager CRITICAL 9.1
CVE-2022-23665

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below…

Fix: 6.8.9 / 6.9.10+
Fix from $2,300 2022-05-16
Clearpass Policy Manager CRITICAL 9.1
CVE-2022-23666

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below…

Fix: 6.8.9 / 6.9.10+
Fix from $2,300 2022-05-16
Feminer Wms CRITICAL 9.8
CVE-2021-42897

A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed in…

No fix yet
Fix from $2,300 2022-05-16
Anaconda3 HIGH 8.8
CVE-2021-42969

Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something …

No fix yet
Fix from $1,950 2022-05-13
Ir302 Firmware HIGH 7.2
CVE-2022-26007EPSS 6%

An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network …

No fix yet
Fix from $1,950 2022-05-12
Ir302 Firmware HIGH 8.8
CVE-2022-26042EPSS 9%

An OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network…

No fix yet
Fix from $1,950 2022-05-12
Ir302 Firmware HIGH 8.8
CVE-2022-26075EPSS 6%

An OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted …

No fix yet
Fix from $1,950 2022-05-12
Ir302 Firmware HIGH 8.8
CVE-2022-26085EPSS 13%

An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP re…

No fix yet
Fix from $1,950 2022-05-12
Ir302 Firmware HIGH 8.8
CVE-2022-26420EPSS 6%

An OS command injection vulnerability exists in the console infactory_port functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted …

No fix yet
Fix from $1,950 2022-05-12
Ir302 Firmware HIGH 8.8
CVE-2022-26518

An OS command injection vulnerability exists in the console infactory_net functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted s…

No fix yet
Fix from $1,950 2022-05-12
Sv Cpt Mc310 Firmware CRITICAL 9.8
CVE-2022-29303 KEVEPSS 98%

SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.

Mitigation only
Fix from $2,300 2022-05-12
Gemini Net CRITICAL 9.8
CVE-2022-29539

resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are pr…

Mitigation only
Fix from $2,300 2022-05-12