Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Aria HIGH 8.8
CVE-2022-24237EPSS 25%

The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated …

No fix yet
Fix from $1,950 2022-03-21
Otrs HIGH 8.8
CVE-2021-36100

Specially crafted string in OTRS system configuration can allow the execution of any system command.

Fix: 7.0.19 / 7.0.28+
Fix from $1,950 2022-03-21
Contao CRITICAL 9.8
CVE-2022-26265EPSS 30%

Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.

No fix yet
Fix from $2,300 2022-03-18
Ac9 Firmware CRITICAL 9.8
CVE-2022-25438

Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function.

No fix yet
Fix from $2,300 2022-03-18
Ac9 Firmware CRITICAL 9.8
CVE-2022-25441

Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter in the SetIPTVCfg function.

No fix yet
Fix from $2,300 2022-03-18
Cloud Phone System CRITICAL 9.8
CVE-2021-45966EPSS 6%

An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.pl allows remote attackers to …

Fix: after 7.19
Fix from $2,300 2022-03-18
Git CRITICAL 9.8
CVE-2021-23632

All versions of package git are vulnerable to Remote Code Execution (RCE) due to missing sanitization in the Git.git method, which allows execution o…

Fix: after 0.1.5
Fix from $2,300 2022-03-17
Sma 200 Firmware CRITICAL 9.8
CVE-2022-22273

Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products a…

Fix: after 9.0.0.9-26sv
Fix from $2,300 2022-03-17
X5000r Firmware CRITICAL 9.8
CVE-2022-27003

Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in th…

No fix yet
Fix from $2,300 2022-03-15
X5000r Firmware CRITICAL 9.8
CVE-2022-27004

Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in th…

No fix yet
Fix from $2,300 2022-03-15
X5000r Firmware CRITICAL 9.8
CVE-2022-27005EPSS 5%

Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in th…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26206

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26207

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26208

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26209

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26210EPSS 6%

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26211

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26212

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15
X5000r Firmware CRITICAL 9.8
CVE-2022-26213EPSS 26%

Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz par…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26214

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15
Sbr Ac1900p Firmware CRITICAL 9.8
CVE-2022-26990

Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in …

No fix yet
Fix from $2,300 2022-03-15
Sbr Ac1900p Firmware CRITICAL 9.8
CVE-2022-26991

Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in …

No fix yet
Fix from $2,300 2022-03-15
Sbr Ac1900p Firmware CRITICAL 9.8
CVE-2022-26992

Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in …

No fix yet
Fix from $2,300 2022-03-15
Sbr Ac1900p Firmware CRITICAL 9.8
CVE-2022-26993

Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in …

No fix yet
Fix from $2,300 2022-03-15
Sbr Ac1900p Firmware CRITICAL 9.8
CVE-2022-26994

Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in …

No fix yet
Fix from $2,300 2022-03-15
Univerge Wa1020 Firmware CRITICAL 9.8
CVE-2022-25621

UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.11 and pri…

Fix: after 8.2.11
Fix from $2,300 2022-03-11
Moodle MEDIUM 5.4
CVE-2021-32475

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8…

Fix: 3.5.18 / 3.8.9+
Fix from $1,600 2022-03-11
Casaos CRITICAL 9.8
CVE-2022-24193EPSS 6%

CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.

Fix: 0.2.7+
Fix from $2,300 2022-03-10
Stripe Cli HIGH 7.0
CVE-2022-24753

Stripe CLI is a command-line tool for the Stripe eCommerce platform. A vulnerability in Stripe CLI exists on Windows when certain commands are run in…

Fix: 1.7.13+
Fix from $1,950 2022-03-09
Genieacs CRITICAL 9.8
CVE-2021-46704EPSS 22%

In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts …

Fix: 1.2.8+
Fix from $2,300 2022-03-06