Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2022-48107 D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerabil… Dir 878 Firmware No fix yet Fix from $2,3002023-01-27 CRITICAL 9.8 CVE-2022-48108 D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerabi… Dir 878 Firmware No fix yet Fix from $2,3002023-01-27 HIGH 7.8 CVE-2022-48070 Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function. K2 Firmware No fix yet Fix from $1,9502023-01-27 HIGH 7.8 CVE-2022-48072 Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function. K2 Firmware No fix yet Fix from $1,9502023-01-27 HIGH 7.5 CVE-2022-48069 Totolink A830R V4.1.2cu.5182 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter. A830r Firmware No fix yet Fix from $1,9502023-01-27 CRITICAL 9.8 CVE-2022-42493 Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network reque… Quartz Gold Firmware Mitigation only Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2022-42490 Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network reque… Quartz Gold Firmware Mitigation only Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2022-42491 Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network reque… Quartz Gold Firmware Mitigation only Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2022-42492 Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network reque… Quartz Gold Firmware Mitigation only Fix from $2,3002023-01-26 HIGH 8.8 CVE-2022-40969EPSS 6% An os command injection vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafte… Quartz Gold Firmware No fix yet Fix from $1,9502023-01-26 HIGH 8.8 CVE-2022-40220 An OS command injection vulnerability exists in the httpd txt/restore.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-cr… Quartz Gold Firmware No fix yet Fix from $1,9502023-01-26 CRITICAL 9.8 CVE-2022-40222 An OS command injection vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-craf… Quartz Gold Firmware No fix yet Fix from $2,3002023-01-26 HIGH 8.8 CVE-2022-38066EPSS 7% An OS command injection vulnerability exists in the httpd SNMP functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP … Quartz Gold Firmware No fix yet Fix from $1,9502023-01-26 HIGH 8.8 CVE-2023-24422 A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with pe… Script Security 1229.v4880b_b_e905a_6+ Fix from $1,9502023-01-26 CRITICAL 9.8 CVE-2022-29843 A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.… My Cloud Pr2100 Firmware 5.26.119+ Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2022-25962 All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization. Vagrant.js Mitigation only Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2022-25860 Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() metho… Simple Git 3.16.0+ Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2022-25908 All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitiza… Create Choo Electron No fix yet Fix from $2,3002023-01-26 HIGH 7.8 CVE-2022-25350 All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization. Puppet Facter No fix yet Fix from $1,9502023-01-26 HIGH 7.8 CVE-2022-21810 All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization. Smartctl No fix yet Fix from $1,9502023-01-26 HIGH 8.8 CVE-2022-40719 This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers. Authen… Dir 2150 Firmware after 4.0.1 Fix from $1,9502023-01-26 HIGH 8.8 CVE-2022-40720 This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers. Authen… Dir 2150 Firmware after 4.0.1 Fix from $1,9502023-01-26 HIGH 7.8 CVE-2022-45639 OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter… The Sleuth Kit No fix yet Fix from $1,9502023-01-24 HIGH 8.8 CVE-2022-37718 The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allow… Application Delivery Controller No fix yet Fix from $1,9502023-01-23 CRITICAL 9.8 CVE-2022-48126 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username parameter in the setting/setOpenV… A7100ru Firmware No fix yet Fix from $2,3002023-01-20 CRITICAL 9.8 CVE-2022-48124 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName parameter in the setting/setOpenV… A7100ru Firmware No fix yet Fix from $2,3002023-01-20 CRITICAL 9.8 CVE-2022-48125 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the password parameter in the setting/setOpenV… A7100ru Firmware No fix yet Fix from $2,3002023-01-20 CRITICAL 9.8 CVE-2022-48121 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits parameter in the setting/delStatic… A7100ru Firmware No fix yet Fix from $2,3002023-01-20 CRITICAL 9.8 CVE-2022-48122 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid parameter in the setting/delStati… A7100ru Firmware No fix yet Fix from $2,3002023-01-20 CRITICAL 9.8 CVE-2022-48123 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the setting/delSta… A7100ru Firmware No fix yet Fix from $2,3002023-01-20