Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Inrouter 900 Firmware CRITICAL 9.8
CVE-2022-27275

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the …

Fix: 1.0.0.r11700+
Fix from $2,300 2022-04-10
Inrouter 900 Firmware CRITICAL 9.8
CVE-2022-27276

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the …

Fix: 1.0.0.r11700+
Fix from $2,300 2022-04-10
Emc Unity Operating Environment CRITICAL 9.8
CVE-2021-36287

Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated user…

Fix: after 8.1.21.266
Fix from $2,300 2022-04-08
Emc Unity Operating Environment MEDIUM 6.7
CVE-2021-36293

Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vuln…

Fix: after 8.1.21.266
Fix from $1,600 2022-04-08
Rt Ac86u Firmware HIGH 8.8
CVE-2022-25597

ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to pe…

Mitigation only
Fix from $1,950 2022-04-07
Dir 878 Firmware HIGH 8.8
CVE-2022-26670

D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attacker can perform command inject…

Fix: after 1.20b05
Fix from $1,950 2022-04-07
Wl Wn531p3 Firmware CRITICAL 9.8
CVE-2022-23900

A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized…

No fix yet
Fix from $2,300 2022-04-07
Icheck Connect Bp Monitor Bp Testing 118 Firmware HIGH 8.8
CVE-2020-27373

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE.

Mitigation only
Fix from $1,950 2022-04-07
Forticlient HIGH 8.0
CVE-2021-22127

An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x before 6.2.9 may allow an unauthe…

Fix: 6.2.9 / 6.4.3+
Fix from $1,950 2022-04-06
Fortianalyzer HIGH 7.8
CVE-2021-26104

Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all version…

Fix: 5.2.6 / 5.3.6+
Fix from $1,950 2022-04-06
Fortiauthenticator HIGH 8.8
CVE-2021-26116

An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1…

Fix: 6.3.1+
Fix from $1,950 2022-04-06
Fortiwan HIGH 8.8
CVE-2021-24009

Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow…

Fix: after 4.5.8
Fix from $1,950 2022-04-06
S4600 10p Si Firmware HIGH 7.4
CVE-2021-42324

An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console i…

No fix yet
Fix from $1,950 2022-04-05
Nport Iaw5150a 6i\/o Firmware CRITICAL 9.8
CVE-2021-32974

Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to…

Fix: after 2.2
Fix from $2,300 2022-04-01
Autosave CRITICAL 9.8
CVE-2021-32933

An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave version…

Fix: 4.01 / 6.02.06+
Fix from $2,300 2022-04-01
Chita Firmware HIGH 8.8
CVE-2022-25017EPSS 29%

Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field.

No fix yet
Fix from $1,950 2022-04-01
Asciidoctor Include Ext CRITICAL 9.8
CVE-2022-24803

Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4.0, when used to render user-…

Fix: 0.4.0+
Fix from $2,300 2022-04-01
Raspberrymatic CRITICAL 9.8
CVE-2022-24796

RaspberryMatic is a free and open-source operating system for running a cloud-free smart-home using the homematicIP / HomeMatic hardware line of IoT …

Fix: 3.63.8.20220330+
Fix from $2,300 2022-03-31
Og410xa Firmware HIGH 8.8
CVE-2022-22986

Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier) allow an attacker on the ad…

Fix: after 2.28
Fix from $1,950 2022-03-31
Ar3100r Firmware CRITICAL 9.8
CVE-2021-46007

totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not…

Mitigation only
Fix from $2,300 2022-03-30
Dir 820l Firmware CRITICAL 9.8
CVE-2022-26258 KEVEPSS 80%

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

Mitigation only
Fix from $2,300 2022-03-28
R8500 Firmware HIGH 8.8
CVE-2022-27945

NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysN…

Patch available
Fix from $1,950 2022-03-26
R8500 Firmware HIGH 8.8
CVE-2022-27946

NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysN…

Patch available
Fix from $1,950 2022-03-26
R8500 Firmware HIGH 8.8
CVE-2022-27947

NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the ipv6…

Patch available
Fix from $1,950 2022-03-26
Ocrfeeder CRITICAL 9.8
CVE-2022-27811

GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.

Fix: 0.8.4+
Fix from $2,300 2022-03-24
M3 Firmware CRITICAL 9.8
CVE-2022-26289

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeCommand.

No fix yet
Fix from $2,300 2022-03-24
M3 Firmware CRITICAL 9.8
CVE-2022-26290

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac.

No fix yet
Fix from $2,300 2022-03-24
Advanced Server Access HIGH 8.8
CVE-2022-1030

Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafte…

Fix: 1.58.0+
Fix from $1,950 2022-03-23
Carbon Black App Control CRITICAL 9.1
CVE-2022-22951EPSS 20%

VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command i…

Fix: 8.5.14 / 8.6.6+
Fix from $2,300 2022-03-23
Factorytalk Assetcentre CRITICAL 9.8
CVE-2021-27476

A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allo…

Fix: after 10.00
Fix from $2,300 2022-03-23