Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-2488EPSS 33%
A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/…
Wl Wn535k2 Firmware
No fix yet
HIGH 8.8
CVE-2022-34538
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/ad…
Megapix Firmware
Mitigation only
HIGH 8.8
CVE-2022-34539
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/curltest.c…
Megapix Firmware
Mitigation only
HIGH 8.8
CVE-2022-34540
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/licens…
Megapix Firmware
Mitigation only
HIGH 8.8
CVE-2022-27373
Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerability via…
Fir303b Firmware
No fix yet
HIGH 7.2
CVE-2022-27483
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.…
Fortianalyzer
after 7.0.3
HIGH 8.8
CVE-2022-33891 KEVEPSS 93%
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks …
Spark
after 3.2.1
HIGH 8.8
CVE-2022-26481
An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) actio…
Studio X30 Firmware
3.7.0+
HIGH 7.2
CVE-2022-26482EPSS 23%
An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.
Eagleeye Director Ii Firmware
2.2.2.1+
HIGH 8.1
CVE-2022-32212EPSS 6%
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easil…
Node.js
1.0 / 14.20.1+
CRITICAL 9.8
CVE-2022-28373
Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition function of th…
Lvskihp Indoorunit Firmware
No fix yet
HIGH 8.8
CVE-2022-28374
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settings page…
Lvskihp Outdoorunit Firmware
No fix yet
CRITICAL 9.8
CVE-2022-28375
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function o…
Lvskihp Outdoorunit Firmware
No fix yet
HIGH 8.8
CVE-2022-34753EPSS 71%
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote roo…
Spacelogic C Bus Home Controller Firmware
after 1.31.460
CRITICAL 9.8
CVE-2022-28888
Spryker Commerce OS 1.4.2 allows Remote Command Execution.
Cloud Commerce
1.7.0+
CRITICAL 9.8
CVE-2022-22997
Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed …
My Cloud Home Duo Firmware
8.5.1-102+
HIGH 7.8
CVE-2021-36667
Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP…
Insync Client
7.0.0+
HIGH 8.8
CVE-2022-31138
mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the…
Mailcow\
2022-06a+
CRITICAL 9.8
CVE-2022-31137EPSS 90%
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code executi…
Roxy Wi
6.1.1.0+
CRITICAL 9.8
CVE-2022-32054EPSS 32%
Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter.
Ac10 Firmware
Patch available
HIGH 8.8
CVE-2022-25048EPSS 19%
Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.
Webpanel
No fix yet
CRITICAL 9.8
CVE-2022-34595
Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status.
Ax1803 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-34596
Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSetting.
Ax1803 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-34597
Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting.
Ax1806 Firmware
No fix yet
HIGH 8.8
CVE-2022-33948
HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHCP server. An adjacent attacke…
Home Spot Cube 2 Firmware
Mitigation only
HIGH 8.8
CVE-2022-2185EPSS 77%
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15…
GitLab
14.10.5 / 15.0.4+
CRITICAL 9.1
CVE-2022-2253
A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 may send OS commands to execute on the host server.
Webhmi Firmware
after 4.1.1.7662
CRITICAL 9.8
CVE-2014-0156
Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If unt…
Awesomespawn
1.5.0+
CRITICAL 9.8
CVE-2022-33312
Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted netw…
R1510 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-33313
Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted netw…
R1510 Firmware
No fix yet