Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.8 CVE-2022-36481 TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the ip parameter in the function setDiagnosisC… N350rt Firmware No fix yet Fix from $1,9502022-08-25 HIGH 7.8 CVE-2022-36485 TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpMo… N350rt Firmware No fix yet Fix from $1,9502022-08-25 HIGH 7.8 CVE-2022-36486 TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadF… N350rt Firmware No fix yet Fix from $1,9502022-08-25 HIGH 7.8 CVE-2022-36487 TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the command parameter in the function setTrace… N350rt Firmware No fix yet Fix from $1,9502022-08-25 HIGH 7.8 CVE-2022-36456 TOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi. A720r Firmware No fix yet Fix from $1,9502022-08-25 HIGH 7.8 CVE-2022-36458 TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the command parameter in the function setTrace… A3700r Firmware No fix yet Fix from $1,9502022-08-25 HIGH 7.8 CVE-2022-36459 TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyn… A3700r Firmware No fix yet Fix from $1,9502022-08-25 HIGH 7.8 CVE-2022-36460 TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadF… A3700r Firmware No fix yet Fix from $1,9502022-08-25 HIGH 7.8 CVE-2022-36461 TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpMo… A3700r Firmware No fix yet Fix from $1,9502022-08-25 HIGH 8.8 CVE-2022-36804 KEVEPSS 99% Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from ver… Bitbucket 7.6.17 / 7.17.10+ Fix from $1,9502022-08-25 HIGH 8.8 CVE-2022-2234EPSS 42% An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system. Mypro after 8.26.0 Fix from $1,9502022-08-24 HIGH 8.8 CVE-2022-36633EPSS 49% Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by … Teleport 10.1.2+ Fix from $1,9502022-08-24 HIGH 8.8 CVE-2022-38132 Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connect… Mr8300 Firmware Mitigation only Fix from $1,9502022-08-24 HIGH 8.8 CVE-2022-1513 A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a specially craft… Pcmanager 5.0.10.4191+ Fix from $1,9502022-08-23 CRITICAL 9.8 CVE-2021-42232 TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the progr… Archer A7 Firmware Mitigation only Fix from $2,3002022-08-23 HIGH 8.8 CVE-2022-32572EPSS 24% An os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-… Avideo No fix yet Fix from $1,9502022-08-22 HIGH 8.8 CVE-2022-30534EPSS 74% An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A speci… Avideo Mitigation only Fix from $1,9502022-08-22 CRITICAL 9.8 CVE-2022-35976 The GitOps Tools Extension for VSCode relies on kubeconfigs in order to communicate with Kubernetes clusters. A specially crafted kubeconfig leads to… Gitops Tools after 0.20.9 Fix from $2,3002022-08-18 CRITICAL 9.8 CVE-2022-35975 The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution … Gitops Tools after 0.20.2 Fix from $2,3002022-08-18 CRITICAL 9.8 CVE-2022-37061EPSS 100% All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject a… Flir Ax8 Firmware after 1.46.16 Fix from $2,3002022-08-18 HIGH 8.8 CVE-2022-1410 OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authenticated attacker to execute re… Cmdb 18.01.00+ Fix from $1,9502022-08-17 CRITICAL 9.8 CVE-2022-36273 Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg. Ac9 Firmware No fix yet Fix from $2,3002022-08-16 HIGH 7.2 CVE-2022-36381 OS command injection vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to exec… Wi Fi Network Adaptor Wap 001 Firmware Mitigation only Fix from $1,9502022-08-16 HIGH 8.8 CVE-2022-36309EPSS 24% Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the reco… Airvelocity 1500 Firmware after 15.18.00.2511 Fix from $1,9502022-08-16 CRITICAL 9.8 CVE-2022-2314EPSS 17% The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site. Vr Calendar after 2.3.2 Fix from $2,3002022-08-15 CRITICAL 9.8 CVE-2022-35555EPSS 25% A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters fo… W6 Firmware No fix yet Fix from $2,3002022-08-12 CRITICAL 10.0 CVE-2022-20827 Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to exe… Rv160 Firmware 1.0.01.05 / 1.0.03.26+ Fix from $2,3002022-08-10 CRITICAL 9.8 CVE-2022-21178 An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-… Linkhub Mesh Wifi Ac1200 No fix yet Fix from $2,3002022-08-05 CRITICAL 9.8 CVE-2022-22140 An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-cra… Linkhub Mesh Wifi Ac1200 No fix yet Fix from $2,3002022-08-05 MEDIUM 5.5 CVE-2022-34769 Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. After he performs log into the sy… Michlol 187.4392+ Fix from $1,6002022-08-05