Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Usg Flex 100w Firmware CRITICAL 9.8
CVE-2022-30525 KEVEPSS 100%

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware v…

Fix: 5.30+
Fix from $2,300 2022-05-12
Gaia Portal MEDIUM 6.7
CVE-2021-30361

The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that …

Fix: 2022-04-13+
Fix from $1,600 2022-05-11
Infosphere Information Server On Cloud HIGH 7.8
CVE-2022-22454

IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a speciall…

Patch available
Fix from $1,950 2022-05-10
N600r Firmware CRITICAL 9.8
CVE-2022-28910

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicename parameter in /setting/setDeviceNam…

No fix yet
Fix from $2,300 2022-05-10
N600r Firmware CRITICAL 9.8
CVE-2022-28911

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/CloudACMunualU…

No fix yet
Fix from $2,300 2022-05-10
N600r Firmware CRITICAL 9.8
CVE-2022-28912

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUpgradeFW.

No fix yet
Fix from $2,300 2022-05-10
N600r Firmware CRITICAL 9.8
CVE-2022-28913

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUploadSetti…

No fix yet
Fix from $2,300 2022-05-10
Dir 816 Firmware CRITICAL 9.8
CVE-2022-28915EPSS 7%

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.

No fix yet
Fix from $2,300 2022-05-10
Dir 882 Firmware CRITICAL 9.8
CVE-2022-28895

A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate priv…

No fix yet
Fix from $2,300 2022-05-10
Dir 882 Firmware CRITICAL 9.8
CVE-2022-28896

A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate pri…

No fix yet
Fix from $2,300 2022-05-10
Dir 882 Firmware CRITICAL 9.8
CVE-2022-28901

A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileg…

No fix yet
Fix from $2,300 2022-05-10
N600r Firmware CRITICAL 9.8
CVE-2022-28905

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicemac parameter in /setting/setDeviceName.

No fix yet
Fix from $2,300 2022-05-10
N600r Firmware CRITICAL 9.8
CVE-2022-28906

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.

No fix yet
Fix from $2,300 2022-05-10
N600r Firmware CRITICAL 9.8
CVE-2022-28907

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime function in /setting/NTPSyncWithHost.

No fix yet
Fix from $2,300 2022-05-10
N600r Firmware CRITICAL 9.8
CVE-2022-28908

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin parameter in /setting/setDiagnosisCf…

No fix yet
Fix from $2,300 2022-05-10
N600r Firmware CRITICAL 9.8
CVE-2022-28909

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the webwlanidx parameter in /setting/setWebWlanId…

No fix yet
Fix from $2,300 2022-05-10
Nts 6002 Gps Firmware HIGH 7.2
CVE-2022-27224

An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via …

No fix yet
Fix from $1,950 2022-05-09
A7100ru Firmware CRITICAL 9.8
CVE-2022-28575

It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, …

No fix yet
Fix from $2,300 2022-05-05
A7100ru Firmware CRITICAL 9.8
CVE-2022-28577

It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, whi…

No fix yet
Fix from $2,300 2022-05-05
A7100ru Firmware CRITICAL 9.8
CVE-2022-28578

It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which …

No fix yet
Fix from $2,300 2022-05-05
A7100ru Firmware CRITICAL 9.8
CVE-2022-28579

It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, whi…

No fix yet
Fix from $2,300 2022-05-05
A7100ru Firmware CRITICAL 9.8
CVE-2022-28580

It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, whi…

No fix yet
Fix from $2,300 2022-05-05
A7100ru Firmware CRITICAL 9.8
CVE-2022-28581

It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, w…

No fix yet
Fix from $2,300 2022-05-05
A7100ru Firmware CRITICAL 9.8
CVE-2022-28582

It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, whi…

No fix yet
Fix from $2,300 2022-05-05
A7100ru Firmware CRITICAL 9.8
CVE-2022-28583

It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which …

No fix yet
Fix from $2,300 2022-05-05
A7100ru Firmware CRITICAL 9.8
CVE-2022-28584

It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, whic…

No fix yet
Fix from $2,300 2022-05-05
Tx9 Pro Firmware CRITICAL 9.8
CVE-2022-29592EPSS 20%

Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).

No fix yet
Fix from $2,300 2022-05-05
Artica Proxy CRITICAL 9.8
CVE-2021-41739

A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param…

Mitigation only
Fix from $2,300 2022-05-05
Rv340 Firmware HIGH 7.2
CVE-2022-20799

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote a…

Fix: 1.0.03.27+
Fix from $1,950 2022-05-04
Rv340 Firmware HIGH 7.2
CVE-2022-20801

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote a…

Fix: 1.0.03.27+
Fix from $1,950 2022-05-04