Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2022-2488EPSS 33% A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/… Wl Wn535k2 Firmware No fix yet Fix from $2,3002022-07-20 HIGH 8.8 CVE-2022-34538 Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/ad… Megapix Firmware Mitigation only Fix from $1,9502022-07-19 HIGH 8.8 CVE-2022-34539 Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/curltest.c… Megapix Firmware Mitigation only Fix from $1,9502022-07-19 HIGH 8.8 CVE-2022-34540 Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/licens… Megapix Firmware Mitigation only Fix from $1,9502022-07-19 HIGH 8.8 CVE-2022-27373 Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerability via… Fir303b Firmware No fix yet Fix from $1,9502022-07-19 HIGH 7.2 CVE-2022-27483 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.… Fortianalyzer after 7.0.3 Fix from $1,9502022-07-19 HIGH 8.8 CVE-2022-33891 KEVEPSS 93% The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks … Spark after 3.2.1 Fix from $1,9502022-07-18 HIGH 8.8 CVE-2022-26481 An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) actio… Studio X30 Firmware 3.7.0+ Fix from $1,9502022-07-17 HIGH 7.2 CVE-2022-26482EPSS 23% An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin. Eagleeye Director Ii Firmware 2.2.2.1+ Fix from $1,9502022-07-17 HIGH 8.1 CVE-2022-32212EPSS 6% A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easil… Node.js 1.0 / 14.20.1+ Fix from $1,9502022-07-14 CRITICAL 9.8 CVE-2022-28373 Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition function of th… Lvskihp Indoorunit Firmware No fix yet Fix from $2,3002022-07-14 HIGH 8.8 CVE-2022-28374 Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settings page… Lvskihp Outdoorunit Firmware No fix yet Fix from $1,9502022-07-14 CRITICAL 9.8 CVE-2022-28375 Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function o… Lvskihp Outdoorunit Firmware No fix yet Fix from $2,3002022-07-14 HIGH 8.8 CVE-2022-34753EPSS 71% A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote roo… Spacelogic C Bus Home Controller Firmware after 1.31.460 Fix from $1,9502022-07-13 CRITICAL 9.8 CVE-2022-28888 Spryker Commerce OS 1.4.2 allows Remote Command Execution. Cloud Commerce 1.7.0+ Fix from $2,3002022-07-13 CRITICAL 9.8 CVE-2022-22997 Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed … My Cloud Home Duo Firmware 8.5.1-102+ Fix from $2,3002022-07-12 HIGH 7.8 CVE-2021-36667 Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP… Insync Client 7.0.0+ Fix from $1,9502022-07-12 HIGH 8.8 CVE-2022-31138 mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the… Mailcow\ 2022-06a+ Fix from $1,9502022-07-11 CRITICAL 9.8 CVE-2022-31137EPSS 90% Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code executi… Roxy Wi 6.1.1.0+ Fix from $2,3002022-07-08 CRITICAL 9.8 CVE-2022-32054EPSS 32% Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter. Ac10 Firmware Patch available Fix from $2,3002022-07-07 HIGH 8.8 CVE-2022-25048EPSS 19% Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user. Webpanel No fix yet Fix from $1,9502022-07-07 CRITICAL 9.8 CVE-2022-34595 Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status. Ax1803 Firmware No fix yet Fix from $2,3002022-07-06 CRITICAL 9.8 CVE-2022-34596 Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSetting. Ax1803 Firmware No fix yet Fix from $2,3002022-07-06 CRITICAL 9.8 CVE-2022-34597 Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting. Ax1806 Firmware No fix yet Fix from $2,3002022-07-06 HIGH 8.8 CVE-2022-33948 HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHCP server. An adjacent attacke… Home Spot Cube 2 Firmware Mitigation only Fix from $1,9502022-07-04 HIGH 8.8 CVE-2022-2185EPSS 77% A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15… GitLab 14.10.5 / 15.0.4+ Fix from $1,9502022-07-01 CRITICAL 9.1 CVE-2022-2253 A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 may send OS commands to execute on the host server. Webhmi Firmware after 4.1.1.7662 Fix from $2,3002022-07-01 CRITICAL 9.8 CVE-2014-0156 Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If unt… Awesomespawn 1.5.0+ Fix from $2,3002022-06-30 CRITICAL 9.8 CVE-2022-33312 Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted netw… R1510 Firmware No fix yet Fix from $2,3002022-06-30 CRITICAL 9.8 CVE-2022-33313 Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted netw… R1510 Firmware No fix yet Fix from $2,3002022-06-30