Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2022-46634 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWi… A7100ru Firmware No fix yet Fix from $2,3002022-12-15 CRITICAL 9.8 CVE-2022-24377 The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-inpu… Cycle Import Check 1.3.2+ Fix from $2,3002022-12-14 HIGH 8.8 CVE-2022-42139EPSS 18% Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL. Dvw W02w2 E2 Firmware No fix yet Fix from $1,9502022-12-14 HIGH 7.2 CVE-2022-42140 Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose. Dx 2100 L1 Cn Firmware No fix yet Fix from $1,9502022-12-14 CRITICAL 9.8 CVE-2022-45005EPSS 5% IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function. Ew9 Firmware No fix yet Fix from $2,3002022-12-13 HIGH 7.2 CVE-2022-45996 Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output. W20e Firmware No fix yet Fix from $1,9502022-12-12 HIGH 8.8 CVE-2022-45043 Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set. Ax12 Firmware No fix yet Fix from $1,9502022-12-12 HIGH 8.8 CVE-2022-45977 Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function. Ax12 Firmware No fix yet Fix from $1,9502022-12-12 HIGH 8.8 CVE-2022-37912 Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results… Sd Wan 6.5.4.22 / 8.6.0.17+ Fix from $1,9502022-12-12 HIGH 7.2 CVE-2022-37924 Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlyi… Edgeconnect Enterprise after 9.2.1.0 Fix from $1,9502022-12-12 CRITICAL 9.8 CVE-2022-37897 There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to … Sd Wan 6.5.4.22 / 8.6.0.17+ Fix from $2,3002022-12-12 HIGH 7.2 CVE-2022-37898 Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results… Sd Wan 6.5.4.23 / 8.6.0.18+ Fix from $1,9502022-12-12 HIGH 7.2 CVE-2022-37899 Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results… Sd Wan 6.5.4.23 / 8.6.0.18+ Fix from $1,9502022-12-12 HIGH 7.2 CVE-2022-37900 Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results… Sd Wan 6.5.4.23 / 8.6.0.18+ Fix from $1,9502022-12-12 HIGH 7.2 CVE-2022-37901 Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results… Sd Wan 6.5.4.23 / 8.6.0.18+ Fix from $1,9502022-12-12 HIGH 7.2 CVE-2022-37902 Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results… Sd Wan 6.5.4.23 / 8.6.0.18+ Fix from $1,9502022-12-12 CRITICAL 9.8 CVE-2022-45145 egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file. Chicken 5.3.1+ Fix from $2,3002022-12-10 CRITICAL 9.8 CVE-2022-33186 A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker t… Fabric Operating System Mitigation only Fix from $2,3002022-12-08 CRITICAL 9.8 CVE-2022-45497 Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommand. W6 S Firmware No fix yet Fix from $2,3002022-12-08 CRITICAL 9.8 CVE-2022-45506 Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName. W30e Firmware No fix yet Fix from $2,3002022-12-08 CRITICAL 9.8 CVE-2022-4364 A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of th… Flir Ax8 Firmware 1.46.16+ Fix from $2,3002022-12-08 HIGH 8.8 CVE-2022-44606 OS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated… Udr Ja1604 Firmware 71x10.1.107114.43a+ Fix from $1,9502022-12-07 HIGH 8.8 CVE-2022-43464 Hidden functionality vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated… Udr Ja1604 Firmware 71x10.1.107114.43a+ Fix from $1,9502022-12-07 CRITICAL 9.8 CVE-2022-45025EPSS 35% Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import … Markdown Preview Enhanced No fix yet Fix from $2,3002022-12-07 CRITICAL 9.8 CVE-2022-45026 An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GFM export pro… Markdown Preview Enhanced No fix yet Fix from $2,3002022-12-07 HIGH 8.8 CVE-2022-45915 ILIAS before 7.16 allows OS Command Injection. Ilias 7.16+ Fix from $1,9502022-12-07 HIGH 7.8 CVE-2022-43867 IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437. Spectrum Scale Container Native Storage Access after 5.1.4.1 Fix from $1,9502022-12-06 CRITICAL 9.8 CVE-2020-6627EPSS 12% The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_la… Stcg2000300 Firmware Patch available Fix from $2,3002022-12-06 CRITICAL 9.8 CVE-2022-25912 The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitab… Simple Git 3.15.0+ Fix from $2,3002022-12-06 HIGH 8.1 CVE-2022-43548EPSS 14% A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that… Node.js 14.21.1 / 16.18.1+ Fix from $1,9502022-12-05