Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2023-23596EPSS 15% jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted u… Nginx Proxy Manager after 2.9.19 Fix from $1,9502023-01-20 HIGH 7.2 CVE-2023-20007 A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could all… Rv340 Firmware 1.0.03.29+ Fix from $1,9502023-01-20 HIGH 8.8 CVE-2022-20964EPSS 31% A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbit… Identity Services Engine 2.6.0+ Fix from $1,9502023-01-20 CRITICAL 9.8 CVE-2022-46476EPSS 41% D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function. Dir 859 A1 Firmware No fix yet Fix from $2,3002023-01-19 HIGH 8.8 CVE-2023-0164 OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the applic… Orangescrum No fix yet Fix from $1,9502023-01-18 HIGH 7.2 CVE-2022-47911 Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly validate the input module name to t… Real Time Location System Studio after 2.6.2 Fix from $1,9502023-01-18 HIGH 7.2 CVE-2022-43483 Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly validate the input module name to t… Real Time Location System Studio after 2.6.2 Fix from $1,9502023-01-18 HIGH 8.0 CVE-2022-2251 Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows … Runner 15.3.5 / 15.4.4+ Fix from $1,9502023-01-17 CRITICAL 9.8 CVE-2022-47853 TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a stable root sh… A7100ru Firmware No fix yet Fix from $2,3002023-01-17 CRITICAL 9.8 CVE-2023-22279 MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer Mobile… Maho Pbx Netdevancer Firmware 1.11.00+ Fix from $2,3002023-01-17 HIGH 7.2 CVE-2023-22280 MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer Mobile… Maho Pbx Netdevancer Firmware 1.11.00+ Fix from $1,9502023-01-17 HIGH 8.0 CVE-2023-22304 OS command injection vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker who can a… Pix Rt100 Firmware Mitigation only Fix from $1,9502023-01-17 HIGH 8.8 CVE-2022-41955 Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer au… Autolab 2.10.0+ Fix from $1,9502023-01-14 CRITICAL 9.8 CVE-2022-21191 Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sa… Global Modules Path 3.0.0+ Fix from $2,3002023-01-13 HIGH 8.8 CVE-2022-42289 NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code executi… Dgx A100 Firmware 00.19.07+ Fix from $1,9502023-01-13 HIGH 8.8 CVE-2022-42290 NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code executi… Dgx A100 Firmware 00.19.07+ Fix from $1,9502023-01-13 HIGH 8.8 CVE-2022-42279 NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code executi… Dgx A100 Firmware 00.19.07+ Fix from $1,9502023-01-13 HIGH 7.2 CVE-2023-22598 InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CW… Inrouter302 Firmware 2.3.0.r5542 / 3.5.56+ Fix from $1,9502023-01-12 HIGH 8.8 CVE-2022-43390 A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker t… Lte7480 M804 Firmware 1.00 / 1.15+ Fix from $1,9502023-01-11 CRITICAL 9.8 CVE-2022-48252 The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter) OS Command Injection. Pi.alert No fix yet Fix from $2,3002023-01-11 HIGH 7.2 CVE-2022-43971 An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <= 1.0.02 (build3). The do_set… Wumc710 Firmware 1.0.02+ Fix from $1,9502023-01-09 HIGH 7.2 CVE-2022-43973 An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI functio… Wrt54gl Firmware after 4.30.18.006 Fix from $1,9502023-01-09 HIGH 7.8 CVE-2022-36926 Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this… Rooms 5.11.3+ Fix from $1,9502023-01-09 CRITICAL 9.8 CVE-2022-25890 All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization. Wifey No fix yet Fix from $2,3002023-01-09 HIGH 8.8 CVE-2022-44149EPSS 64% The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON… Amp300 Firmware No fix yet Fix from $1,9502023-01-06 CRITICAL 9.8 CVE-2022-25923 Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input… Exec Local Bin 1.2.0+ Fix from $2,3002023-01-06 CRITICAL 9.8 CVE-2022-44877 KEVEPSS 100% login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via s… Webpanel 0.9.8.1147+ Fix from $2,3002023-01-05 HIGH 8.8 CVE-2022-43536 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.12 / 6.10.7+ Fix from $1,9502023-01-05 HIGH 7.2 CVE-2022-43537 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.12 / 6.10.7+ Fix from $1,9502023-01-05 HIGH 7.2 CVE-2022-43538 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.12 / 6.10.7+ Fix from $1,9502023-01-05