Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Archer C20i Firmware HIGH 8.8
CVE-2021-44827EPSS 54%

There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6…

Fix: after 170221
Fix from $1,950 2022-03-04
Part Db CRITICAL 9.8
CVE-2022-0848EPSS 35%

OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.

Fix: 0.5.11+
Fix from $2,300 2022-03-04
Shescape MEDIUM 5.5
CVE-2022-24725

Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when…

Fix: 1.5.1+
Fix from $1,600 2022-03-03
Npm Lockfile CRITICAL 9.8
CVE-2022-0841

OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4.

Patch available
Fix from $2,300 2022-03-03
Fortiap C HIGH 7.8
CVE-2022-22301

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiAP-C console 5.4.0 through 5.4.3, 5.2.0 through 5…

Patch available
Fix from $1,950 2022-03-02
Fortiwlm HIGH 8.8
CVE-2021-43075

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.…

Fix: 8.6.3+
Fix from $1,950 2022-03-01
Nwa1100 Nh Firmware CRITICAL 9.8
CVE-2021-4039EPSS 71%

A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on …

Fix: 2.12+
Fix from $2,300 2022-03-01
Hicos CRITICAL 9.8
CVE-2020-12775

Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated re…

Fix: after 3.0.0
Fix from $2,300 2022-03-01
Strapi MEDIUM 6.7
CVE-2022-0764

Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.

Fix: 4.1.0+
Fix from $1,600 2022-02-26
Tl Wr840n Firmware CRITICAL 9.8
CVE-2022-25060EPSS 40%

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

Mitigation only
Fix from $2,300 2022-02-25
Tl Wr840n Firmware CRITICAL 9.8
CVE-2022-25061EPSS 58%

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

Mitigation only
Fix from $2,300 2022-02-25
Tl Wr840n Firmware CRITICAL 9.8
CVE-2022-25064EPSS 36%

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

Mitigation only
Fix from $2,300 2022-02-25
Teamcity CRITICAL 9.8
CVE-2022-25263

JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.

Fix: 2021.2.3+
Fix from $2,300 2022-02-25
Fscrypt HIGH 7.3
CVE-2022-25328

The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set …

Fix: 0.3.3+
Fix from $1,950 2022-02-25
Airflow HIGH 8.8
CVE-2022-24288EPSS 78%

In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command In…

Fix: 2.2.4+
Fix from $1,950 2022-02-25
A3000ru Firmware CRITICAL 9.8
CVE-2022-25075EPSS 54%

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows a…

Patch available
Fix from $2,300 2022-02-24
A800r Firmware CRITICAL 9.8
CVE-2022-25076

TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows …

Patch available
Fix from $2,300 2022-02-24
A3100r Firmware CRITICAL 9.8
CVE-2022-25077EPSS 33%

TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows…

Patch available
Fix from $2,300 2022-02-24
A3600r Firmware CRITICAL 9.8
CVE-2022-25078

TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows…

Patch available
Fix from $2,300 2022-02-24
A810r Firmware CRITICAL 9.8
CVE-2022-25079

TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows …

Patch available
Fix from $2,300 2022-02-24
A830r Firmware CRITICAL 9.8
CVE-2022-25080

TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows att…

Patch available
Fix from $2,300 2022-02-24
T10 V2 Firmware CRITICAL 9.8
CVE-2022-25081

TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attac…

Patch available
Fix from $2,300 2022-02-24
A950rg Firmware CRITICAL 9.8
CVE-2022-25082EPSS 16%

TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function.…

Patch available
Fix from $2,300 2022-02-24
A860r Firmware CRITICAL 9.8
CVE-2022-25083

TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows …

Patch available
Fix from $2,300 2022-02-24
T6 Firmware CRITICAL 9.8
CVE-2022-25084EPSS 25%

TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attack…

Patch available
Fix from $2,300 2022-02-24
Nbg6816 Firmware HIGH 8.8
CVE-2021-4029

A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commands via a…

Fix: 1.00+
Fix from $1,950 2022-02-24
Nx Os HIGH 8.8
CVE-2022-20650EPSS 15%

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root p…

Mitigation only
Fix from $1,950 2022-02-23
Mimosa Management Platform CRITICAL 9.8
CVE-2022-21143

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does…

Fix: 1.0.3 / 2.5.4.1+
Fix from $2,300 2022-02-18
Dir 846 Firmware CRITICAL 9.8
CVE-2021-46315EPSS 7%

Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enF…

No fix yet
Fix from $2,300 2022-02-17
Dir 846 Firmware CRITICAL 9.8
CVE-2021-46319EPSS 7%

Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicious users c…

No fix yet
Fix from $2,300 2022-02-17