Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2022-20925 A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker… Secure Firewall Management Center Mitigation only Fix from $1,9502022-11-15 HIGH 8.8 CVE-2022-20926 A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker… Secure Firewall Management Center Mitigation only Fix from $1,9502022-11-15 HIGH 7.8 CVE-2022-41396 Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunne… W15e Firmware No fix yet Fix from $1,9502022-11-15 HIGH 7.8 CVE-2022-42053 Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in… W15e Firmware No fix yet Fix from $1,9502022-11-15 HIGH 7.8 CVE-2022-41395 Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDM… W15e Firmware No fix yet Fix from $1,9502022-11-15 HIGH 7.8 CVE-2022-40847 In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. This vulnerabi… W15e Firmware No fix yet Fix from $1,9502022-11-15 HIGH 8.8 CVE-2022-38387 IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on the system b… Cloud Pak For Security after 1.10.2.0 Fix from $1,9502022-11-11 HIGH 7.8 CVE-2022-35717 "IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a special… Infosphere Information Server Patch available Fix from $1,9502022-11-03 MEDIUM 5.4 CVE-2022-35642 "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in … Infosphere Information Server Patch available Fix from $1,6002022-11-03 HIGH 7.8 CVE-2022-33870 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 3.0.0 thro… Fortitester Patch available Fix from $1,9502022-11-02 CRITICAL 9.8 CVE-2022-40741 Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerabil… Mail Sqr Expert Mitigation only Fix from $2,3002022-10-31 HIGH 8.8 CVE-2022-44019 In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter. Total.js 2022-09-26+ Fix from $1,9502022-10-30 CRITICAL 9.8 CVE-2022-37915 A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to … Aruba Edgeconnect Enterprise Orchestrator 9.1.3.40197+ Fix from $2,3002022-10-28 MEDIUM 6.5 CVE-2022-42055 Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools… Goodcloud No fix yet Fix from $1,6002022-10-27 MEDIUM 6.8 CVE-2022-31898EPSS 16% gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr … Gl Mt300n V2 Firmware No fix yet Fix from $1,6002022-10-27 HIGH 7.5 CVE-2022-42999 D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/set… Dir 816 Firmware No fix yet Fix from $1,9502022-10-26 CRITICAL 9.8 CVE-2022-39327 Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code in… Azure Command Line Interface 2.40.0+ Fix from $2,3002022-10-25 CRITICAL 9.9 CVE-2022-39321 GitHub Actions Runner is the application that runs a job from a GitHub Actions workflow. The actions runner invokes the docker cli directly in order … Runner 2.283.4 / 2.285.2+ Fix from $2,3002022-10-25 CRITICAL 10.0 CVE-2022-33194 Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9… Iota All In One Security Kit Firmware Mitigation only Fix from $2,3002022-10-25 CRITICAL 10.0 CVE-2022-33195 Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9… Iota All In One Security Kit Firmware Mitigation only Fix from $2,3002022-10-25 CRITICAL 9.9 CVE-2022-33204 Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Se… Iota All In One Security Kit Firmware No fix yet Fix from $2,3002022-10-25 CRITICAL 9.9 CVE-2022-33205 Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Se… Iota All In One Security Kit Firmware No fix yet Fix from $2,3002022-10-25 CRITICAL 9.9 CVE-2022-33206 Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Se… Iota All In One Security Kit Firmware No fix yet Fix from $2,3002022-10-25 CRITICAL 9.9 CVE-2022-33207 Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Se… Iota All In One Security Kit Firmware No fix yet Fix from $2,3002022-10-25 HIGH 7.2 CVE-2022-34850 An OS command injection vulnerability exists in the web_server /action/import_authorized_keys/ functionality of Robustel R1510 3.1.16 and 3.3.0. A sp… R1510 Firmware No fix yet Fix from $1,9502022-10-25 HIGH 8.8 CVE-2022-35132 Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module. Usermin after 1.850 Fix from $1,9502022-10-25 CRITICAL 9.8 CVE-2022-30541 An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A s… Iota All In One Security Kit Firmware No fix yet Fix from $2,3002022-10-25 HIGH 8.8 CVE-2022-30603EPSS 6% An OS command injection vulnerability exists in the web interface /action/iperf functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9… Iota All In One Security Kit Firmware No fix yet Fix from $1,9502022-10-25 HIGH 8.8 CVE-2022-32586 An OS command injection vulnerability exists in the web interface /action/ipcamRecordPost functionality of Abode Systems, Inc. iota All-In-One Securi… Iota All In One Security Kit Firmware No fix yet Fix from $1,9502022-10-25 CRITICAL 9.8 CVE-2022-32765 An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafte… R1510 Firmware No fix yet Fix from $2,3002022-10-25