Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
MEDIUM 6.7 CVE-2022-20930 A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt files on an affect… Catalyst Sd Wan Manager 20.6.2+ Fix from $1,6002022-09-30 HIGH 7.2 CVE-2022-20851 A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against a… Ios Xe Mitigation only Fix from $1,9502022-09-30 MEDIUM 6.7 CVE-2022-20855 A vulnerability in the self-healing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst Access Points could allow an… Ios Xe Mitigation only Fix from $1,6002022-09-30 CRITICAL 9.8 CVE-2022-40475 TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi. A860r Firmware No fix yet Fix from $2,3002022-09-29 CRITICAL 9.8 CVE-2022-40929 XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended a… Xxl Job No fix yet Fix from $2,3002022-09-28 CRITICAL 9.8 CVE-2022-28811 In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper in… Cpy Car Park Server 2.8.3 / 8.5.0.3+ Fix from $2,3002022-09-28 HIGH 8.8 CVE-2022-40785 Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3.1.2003161406. This allows an attacker to gain remot… Mipc Camera Firmware Mitigation only Fix from $1,9502022-09-26 HIGH 7.8 CVE-2022-39224 Arr-pm is an RPM reader/writer library written in Ruby. Versions prior to 0.0.12 are subject to OS command injection resulting in shell execution if … Ruby Arr Pm 0.0.12+ Fix from $1,9502022-09-21 HIGH 7.2 CVE-2022-37878 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.12 / 6.10.7+ Fix from $1,9502022-09-20 HIGH 7.2 CVE-2022-37880 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.12 / 6.10.7+ Fix from $1,9502022-09-20 HIGH 7.2 CVE-2022-37882 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde… Clearpass Policy Manager 6.9.12 / 6.10.7+ Fix from $1,9502022-09-20 CRITICAL 9.8 CVE-2022-38828EPSS 19% TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi T6 Firmware No fix yet Fix from $2,3002022-09-16 CRITICAL 9.8 CVE-2022-38826 In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi. T6 Firmware No fix yet Fix from $2,3002022-09-16 HIGH 7.2 CVE-2022-38534 TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setdiagnosicfg function. A720r Firmware No fix yet Fix from $1,9502022-09-15 HIGH 7.2 CVE-2022-38535 TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg function. A720r Firmware No fix yet Fix from $1,9502022-09-15 CRITICAL 9.8 CVE-2022-38308EPSS 20% TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter in the function cstesystem. … A7000ru Firmware Patch available Fix from $2,3002022-09-14 HIGH 8.8 CVE-2022-39819 In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execute commands on the operating s… 1350 Optical Management System Mitigation only Fix from $1,9502022-09-13 CRITICAL 9.8 CVE-2022-39815 In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on … 1350 Optical Management System Mitigation only Fix from $2,3002022-09-13 CRITICAL 9.8 CVE-2022-36779 PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Proscend M330-w / M33-W5 / M350-… M330 W Firmware 1.02 / 1.11+ Fix from $2,3002022-09-13 CRITICAL 9.8 CVE-2022-37860EPSS 80% The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerabil… M7350 Firmware Patch available Fix from $2,3002022-09-12 HIGH 7.8 CVE-2022-3133 OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0. Drawio 20.3.0+ Fix from $1,9502022-09-09 HIGH 7.2 CVE-2022-29061 An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2… Fortisoar 7.0.3+ Fix from $1,9502022-09-09 HIGH 8.8 CVE-2022-30079EPSS 25% Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acos_service that could allow … R6200 Mitigation only Fix from $1,9502022-09-08 HIGH 8.8 CVE-2022-35273 OS command injection vulnerability in GUI setting page of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated atta… Centrecom Ar260s Firmware 3.3.7+ Fix from $1,9502022-09-08 HIGH 8.8 CVE-2022-38094 OS command injection vulnerability in the telnet function of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated a… Centrecom Ar260s Firmware 3.3.7+ Fix from $1,9502022-09-08 CRITICAL 9.8 CVE-2022-33941 PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted message by POST method to Power… Powercms after 6.021 Fix from $2,3002022-09-08 HIGH 8.8 CVE-2022-38531 FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function. G 97rg6m Firmware No fix yet Fix from $1,9502022-09-08 HIGH 8.8 CVE-2022-30078 NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0.4.52_10.0.93 allow remote au… R6200 Firmware after 1.0.4.52_10.0.93 Fix from $1,9502022-09-07 HIGH 7.8 CVE-2022-23682 Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. A successful exploit could al… Aos Cx 10.06.0220 / 10.08.1080+ Fix from $1,9502022-09-06 HIGH 7.2 CVE-2022-23683 Authenticated command injection vulnerabilities exist in the AOS-CX Network Analytics Engine via NAE scripts. Successful exploitation of these vulner… Aos Cx 10.06.0220 / 10.08.1080+ Fix from $1,9502022-09-06