Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2022-46169 KEVEPSS 100% Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected … Cacti 1.2.23+ Fix from $2,3002022-12-05 CRITICAL 9.8 CVE-2022-42496 OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain ap… Nadesiko3 after 3.3.74 Fix from $2,3002022-12-05 CRITICAL 9.8 CVE-2022-41642 OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.61 and earlier allows a remote attacker to execute an arbitrary OS command when pro… Nadesiko3 after 3.3.68 Fix from $2,3002022-12-05 CRITICAL 9.8 CVE-2022-44930 D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function. Dhp W310av Firmware No fix yet Fix from $2,3002022-12-02 CRITICAL 9.8 CVE-2022-43325 An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows a… Omnia Mpx Node Firmware No fix yet Fix from $2,3002022-12-02 CRITICAL 9.8 CVE-2022-44928 D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function. Dvg G5402sp Firmware No fix yet Fix from $2,3002022-12-02 HIGH 7.2 CVE-2022-3226 An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version … Xg Firewall Firmware after 19.0 Fix from $1,9502022-12-01 CRITICAL 9.8 CVE-2022-4257EPSS 44% A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknown processing of the file cgi-… C Data Web Management System No fix yet Fix from $2,3002022-12-01 CRITICAL 9.8 CVE-2022-4221 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated at… Nas M25 Firmware after 1.0.1.7 Fix from $2,3002022-12-01 HIGH 8.8 CVE-2022-45045 Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow … Mbd6304t No fix yet Fix from $1,9502022-12-01 HIGH 8.8 CVE-2021-4242 A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical. Affected by this issue is some unknown functionality… Br270n Firmware No fix yet Fix from $1,9502022-11-30 MEDIUM 6.3 CVE-2022-22984 The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-coc… Snyk Cli 1.1.6 / 1.24.2+ Fix from $1,6002022-11-30 HIGH 8.8 CVE-2022-24441 The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious p… Snyk Cli 1.1064.0+ Fix from $1,9502022-11-30 HIGH 7.2 CVE-2022-36962EPSS 9% SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds data… Orion Platform 2020.2.6+ Fix from $1,9502022-11-29 HIGH 7.8 CVE-2022-45939 GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses … Debian Linux after 28.2 Fix from $1,9502022-11-28 CRITICAL 9.8 CVE-2022-44843 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnCl… A7100ru Firmware No fix yet Fix from $2,3002022-11-25 CRITICAL 9.8 CVE-2022-44844 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCf… A7100ru Firmware No fix yet Fix from $2,3002022-11-25 CRITICAL 9.8 CVE-2022-44249 TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function. Lr350 Firmware No fix yet Fix from $2,3002022-11-23 CRITICAL 9.8 CVE-2022-44250 TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function. Lr350 Firmware No fix yet Fix from $2,3002022-11-23 CRITICAL 9.8 CVE-2022-44251 TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function. Lr350 Firmware No fix yet Fix from $2,3002022-11-23 CRITICAL 9.8 CVE-2022-44252 TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function. Lr350 Firmware No fix yet Fix from $2,3002022-11-23 HIGH 7.8 CVE-2022-41942 Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present i… Sourcegraph 4.1.0+ Fix from $1,9502022-11-22 CRITICAL 9.8 CVE-2022-44808 A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrar… Dir 823g Firmware No fix yet Fix from $2,3002022-11-22 CRITICAL 9.8 CVE-2022-44201 D-Link DIR823G 1.02B05 is vulnerable to Commad Injection. Dir 823g Firmware No fix yet Fix from $2,3002022-11-22 CRITICAL 9.8 CVE-2022-40189 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airfl… Airflow 2.3.0 / 4.0.0+ Fix from $2,3002022-11-22 MEDIUM 5.5 CVE-2022-40954 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Air… Airflow 2.3.0 / 4.0.0+ Fix from $1,6002022-11-22 HIGH 7.8 CVE-2022-41131 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airf… Airflow 2.3.0 / 4.1.0+ Fix from $1,9502022-11-22 CRITICAL 9.8 CVE-2022-38649 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Air… Airflow 2.3.0 / 4.0.0+ Fix from $2,3002022-11-22 HIGH 8.8 CVE-2022-45461 The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that hav… Netbackup after 10.1 Fix from $1,9502022-11-17 MEDIUM 6.7 CVE-2022-20934 A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to e… Secure Firewall Threat Defense after 7.0.4 Fix from $1,6002022-11-15