Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.8 CVE-2022-25926 Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization. Window Control 1.4.5+ Fix from $1,9502023-01-04 HIGH 8.8 CVE-2022-35845 Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.… Fortitester after 3.9.1 Fix from $1,9502023-01-03 HIGH 8.8 CVE-2022-39947 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiA… Fortiadc after 6.2.3 Fix from $1,9502023-01-03 HIGH 8.8 CVE-2022-46304 ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. An unauthenticated remote att… Servisign Mitigation only Fix from $1,9502023-01-03 HIGH 7.2 CVE-2022-40740 Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrator can exploit this vulnerabi… Usdk Mitigation only Fix from $1,9502023-01-03 CRITICAL 9.8 CVE-2022-46597 TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydlink (sub_… Tew 755ap Firmware No fix yet Fix from $2,3002022-12-30 CRITICAL 9.8 CVE-2022-46598 TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action set_sta_en… Tew 755ap Firmware No fix yet Fix from $2,3002022-12-30 CRITICAL 9.8 CVE-2021-4281 A vulnerability was found in Brave UX for-the-badge and classified as critical. Affected by this issue is some unknown functionality of the file .git… For The Badge 1.2.0+ Fix from $2,3002022-12-26 HIGH 8.8 CVE-2022-40005EPSS 35% Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaf… Wifiber 120ac Inmesh Firmware 1.1-220826+ Fix from $1,9502022-12-25 CRITICAL 9.8 CVE-2022-45717 IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartiti… M50 Firmware Mitigation only Fix from $2,3002022-12-23 CRITICAL 9.8 CVE-2022-45709 IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule parameters in… M50 Firmware Mitigation only Fix from $2,3002022-12-23 CRITICAL 9.8 CVE-2022-45711EPSS 20% IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools func… M50 Firmware No fix yet Fix from $2,3002022-12-23 CRITICAL 9.8 CVE-2022-44567 A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalVideoChat… Rocket.chat 3.8.14+ Fix from $2,3002022-12-23 CRITICAL 9.6 CVE-2021-32692 Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macO… Activitywatch 0.11.0+ Fix from $2,3002022-12-23 CRITICAL 9.8 CVE-2022-3183 Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the … Iboot Pdu4 N20 Firmware 1.42.06162022+ Fix from $2,3002022-12-21 CRITICAL 9.8 CVE-2022-4643 A vulnerability was found in docconv up to 1.2.0. It has been declared as critical. This vulnerability affects the function ConvertPDFImages of the f… Docconv 1.2.1+ Fix from $2,3002022-12-21 CRITICAL 9.8 CVE-2022-24431 All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper user-input sanitization. Abacus Ext Cmdline No fix yet Fix from $2,3002022-12-21 HIGH 7.8 CVE-2022-4515 A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified i… Debian Linux No fix yet Fix from $1,9502022-12-20 CRITICAL 9.8 CVE-2022-46538 Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac. F1203 Firmware No fix yet Fix from $2,3002022-12-20 CRITICAL 9.8 CVE-2022-40624EPSS 17% pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerabi… Pfblockerng 2.1.4_27+ Fix from $2,3002022-12-20 HIGH 8.8 CVE-2022-45942EPSS 22% A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4. Baijiacms No fix yet Fix from $1,9502022-12-20 CRITICAL 9.8 CVE-2022-25171 The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization P4 0.0.7+ Fix from $2,3002022-12-20 HIGH 8.8 CVE-2022-43443 OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a specially c… Wsr 3200ax4s Firmware after 1.26 Fix from $1,9502022-12-19 MEDIUM 6.8 CVE-2022-43466 OS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbit… Wsr 3200ax4s Firmware after 1.26 Fix from $1,6002022-12-19 CRITICAL 9.8 CVE-2022-44456EPSS 70% CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the … Conprosys Hmi System after 3.4.4 Fix from $2,3002022-12-19 MEDIUM 6.8 CVE-2022-26580 PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries in the ADB … Paydroid Mitigation only Fix from $1,6002022-12-16 HIGH 7.8 CVE-2022-26582 PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systool client. … Paydroid Mitigation only Fix from $1,9502022-12-16 HIGH 7.8 CVE-2022-47210 The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, ap… Rax30 Firmware 1.0.9.90+ Fix from $1,9502022-12-16 HIGH 8.8 CVE-2022-47208 The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated atta… Nighthawk Ax1800 Firmware 1.0.9.90+ Fix from $1,9502022-12-16 CRITICAL 9.8 CVE-2022-46631 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWi… A7100ru Firmware No fix yet Fix from $2,3002022-12-15