Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-46169 KEVEPSS 100%
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected …
Cacti
1.2.23+
CRITICAL 9.8
CVE-2022-42496
OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain ap…
Nadesiko3
after 3.3.74
CRITICAL 9.8
CVE-2022-41642
OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.61 and earlier allows a remote attacker to execute an arbitrary OS command when pro…
Nadesiko3
after 3.3.68
CRITICAL 9.8
CVE-2022-44930
D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.
Dhp W310av Firmware
No fix yet
CRITICAL 9.8
CVE-2022-43325
An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows a…
Omnia Mpx Node Firmware
No fix yet
CRITICAL 9.8
CVE-2022-44928
D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.
Dvg G5402sp Firmware
No fix yet
HIGH 7.2
CVE-2022-3226
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version …
Xg Firewall Firmware
after 19.0
CRITICAL 9.8
CVE-2022-4257EPSS 44%
A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknown processing of the file cgi-…
C Data Web Management System
No fix yet
CRITICAL 9.8
CVE-2022-4221
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated at…
Nas M25 Firmware
after 1.0.1.7
HIGH 8.8
CVE-2022-45045
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow …
Mbd6304t
No fix yet
HIGH 8.8
CVE-2021-4242
A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical. Affected by this issue is some unknown functionality…
Br270n Firmware
No fix yet
MEDIUM 6.3
CVE-2022-22984
The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-coc…
Snyk Cli
1.1.6 / 1.24.2+
HIGH 8.8
CVE-2022-24441
The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious p…
Snyk Cli
1.1064.0+
HIGH 7.2
CVE-2022-36962EPSS 9%
SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds data…
Orion Platform
2020.2.6+
HIGH 7.8
CVE-2022-45939
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses …
Debian Linux
after 28.2
CRITICAL 9.8
CVE-2022-44843
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnCl…
A7100ru Firmware
No fix yet
CRITICAL 9.8
CVE-2022-44844
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCf…
A7100ru Firmware
No fix yet
CRITICAL 9.8
CVE-2022-44249
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.
Lr350 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-44250
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.
Lr350 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-44251
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.
Lr350 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-44252
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.
Lr350 Firmware
No fix yet
HIGH 7.8
CVE-2022-41942
Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present i…
Sourcegraph
4.1.0+
CRITICAL 9.8
CVE-2022-44808
A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrar…
Dir 823g Firmware
No fix yet
CRITICAL 9.8
CVE-2022-44201
D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.
Dir 823g Firmware
No fix yet
CRITICAL 9.8
CVE-2022-40189
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airfl…
Airflow
2.3.0 / 4.0.0+
MEDIUM 5.5
CVE-2022-40954
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Air…
Airflow
2.3.0 / 4.0.0+
HIGH 7.8
CVE-2022-41131
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airf…
Airflow
2.3.0 / 4.1.0+
CRITICAL 9.8
CVE-2022-38649
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Air…
Airflow
2.3.0 / 4.0.0+
HIGH 8.8
CVE-2022-45461
The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that hav…
Netbackup
after 10.1
MEDIUM 6.7
CVE-2022-20934
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to e…
Secure Firewall Threat Defense
after 7.0.4