Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Ac15 Firmware CRITICAL 9.8
CVE-2022-28557EPSS 23%

There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, …

No fix yet
Fix from $2,300 2022-05-04
Eve Ng HIGH 8.8
CVE-2022-27903

An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allo…

Fix: after 4.0.1-65
Fix from $1,950 2022-05-04
Fusionpbx CRITICAL 9.8
CVE-2022-28055

Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.

Fix: after 4.4.0
Fix from $2,300 2022-05-04
Reyeeos HIGH 8.8
CVE-2021-43164EPSS 35%

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the u…

Fix: after 1.55.1915_ew_3.0
Fix from $1,950 2022-05-04
OpenSSL HIGH 7.3
CVE-2022-1292EPSS 83%

The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating system…

Fix: 1.0.2ze / 1.1.1o+
Fix from $1,950 2022-05-03
Gpt 2541gnac N1 Firmware HIGH 8.8
CVE-2021-42165EPSS 14%

MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file …

No fix yet
Fix from $1,950 2022-05-03
Dir 823 Pro Firmware CRITICAL 9.8
CVE-2022-28573EPSS 28%

D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. This vulnerability allows a…

No fix yet
Fix from $2,300 2022-05-02
Dir 882 Firmware CRITICAL 9.8
CVE-2022-28571EPSS 6%

D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli.

No fix yet
Fix from $2,300 2022-05-02
Ax1806 Firmware HIGH 8.8
CVE-2022-28572

Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function

No fix yet
Fix from $1,950 2022-05-02
Oracle Optimization HIGH 8.8
CVE-2022-29937

USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because some common OS commands are bloc…

No fix yet
Fix from $1,950 2022-04-29
Cc612 Firmware HIGH 8.8
CVE-2021-34602

In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell …

Fix: 5.11.2 / 5.12.5+
Fix from $1,950 2022-04-27
Sdt Cs3b1 Firmware CRITICAL 9.8
CVE-2021-46422EPSS 95%

Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any auth…

No fix yet
Fix from $2,300 2022-04-27
Dir 825 Firmware HIGH 8.8
CVE-2021-46441EPSS 33%

In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary s…

No fix yet
Fix from $1,950 2022-04-27
Git Interface CRITICAL 9.8
CVE-2022-1440

Command Injection vulnerability in [email protected] in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input,…

Fix: 2.1.2+
Fix from $2,300 2022-04-22
Manageengine Adselfservice Plus MEDIUM 6.8
CVE-2022-28810 KEVEPSS 71%

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYST…

Fix: 6.1+
Fix from $1,600 2022-04-18
Ios Xe HIGH 7.2
CVE-2022-20718

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary com…

No fix yet
Fix from $1,950 2022-04-15
Ios Xe HIGH 7.2
CVE-2022-20693

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against a…

Mitigation only
Fix from $1,950 2022-04-15
B\/m9000 Vp HIGH 7.8
CVE-2022-27188

OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.…

Mitigation only
Fix from $1,950 2022-04-15
Struxureware Data Center Expert CRITICAL 9.8
CVE-2021-22795

A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code…

Fix: after 7.8.1
Fix from $2,300 2022-04-13
Npm Dependency Versions CRITICAL 9.8
CVE-2022-29080

The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON …

Fix: after 0.3.0
Fix from $2,300 2022-04-12
Dir 1360 Firmware HIGH 7.8
CVE-2022-1262

A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary comm…

No fix yet
Fix from $1,950 2022-04-11
Mypro HIGH 8.8
CVE-2022-0999

An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.

Fix: after 8.25.0
Fix from $1,950 2022-04-11
Vmg3312 T20a Firmware HIGH 8.0
CVE-2022-26413

A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker…

Fix: 5.13 / 5.17+
Fix from $1,950 2022-04-11
Inrouter 900 Firmware CRITICAL 9.8
CVE-2022-27268

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the …

Fix: 1.0.0.r11700+
Fix from $2,300 2022-04-10
Inrouter 900 Firmware CRITICAL 9.8
CVE-2022-27269

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the …

Fix: 1.0.0.r11700+
Fix from $2,300 2022-04-10
Inrouter 900 Firmware CRITICAL 9.8
CVE-2022-27270

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the …

Fix: 1.0.0.r11700+
Fix from $2,300 2022-04-10
Inrouter 900 Firmware CRITICAL 9.8
CVE-2022-27271

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the …

Fix: 1.0.0.r11700+
Fix from $2,300 2022-04-10
Inrouter 900 Firmware CRITICAL 9.8
CVE-2022-27272

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the …

Fix: 1.0.0.r11700+
Fix from $2,300 2022-04-10
Inrouter 900 Firmware CRITICAL 9.8
CVE-2022-27273

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the …

Fix: 1.0.0.r11700+
Fix from $2,300 2022-04-10
Inrouter 900 Firmware CRITICAL 9.8
CVE-2022-27274

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the …

Fix: 1.0.0.r11700+
Fix from $2,300 2022-04-10