Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2022-33314 Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted netw… R1510 Firmware No fix yet Fix from $2,3002022-06-30 CRITICAL 9.8 CVE-2022-33325 Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted networ… R1510 Firmware No fix yet Fix from $2,3002022-06-30 CRITICAL 9.8 CVE-2022-33326 Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted networ… R1510 Firmware No fix yet Fix from $2,3002022-06-30 CRITICAL 9.8 CVE-2022-33327 Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted networ… R1510 Firmware No fix yet Fix from $2,3002022-06-30 CRITICAL 9.8 CVE-2022-33328 Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted networ… R1510 Firmware No fix yet Fix from $2,3002022-06-30 CRITICAL 9.8 CVE-2022-33329 Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted networ… R1510 Firmware No fix yet Fix from $2,3002022-06-30 CRITICAL 9.8 CVE-2022-31885EPSS 32% Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts. Marval Msm No fix yet Fix from $2,3002022-06-28 CRITICAL 9.8 CVE-2022-32092EPSS 6% D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __ajax_explorer.sgi. Dir 645 Firmware after 1.03 Fix from $2,3002022-06-27 CRITICAL 9.8 CVE-2022-28171EPSS 52% The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validat… Ds A71024 Firmware after 2.3.8-6 Fix from $2,3002022-06-27 CRITICAL 9.8 CVE-2022-31767EPSS 5% IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted reque… Cics Tx 11.1+ Fix from $2,3002022-06-24 CRITICAL 9.8 CVE-2022-32534 The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostic… Pra Es8p2s Firmware after 1.01.05 Fix from $2,3002022-06-23 HIGH 7.3 CVE-2022-2068EPSS 96% In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sa… OpenSSL 1.0 / 1.0.2zf+ Fix from $1,9502022-06-21 CRITICAL 9.8 CVE-2022-26147 The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection. Rg502q Ea Firmware 2022-02-23+ Fix from $2,3002022-06-21 CRITICAL 9.8 CVE-2022-31794 An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the request… Eternus Cs8000 Firmware 8.1+ Fix from $2,3002022-06-20 CRITICAL 9.8 CVE-2022-31795 An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_fi… Eternus Cs8000 Firmware 8.1+ Fix from $2,3002022-06-20 CRITICAL 9.8 CVE-2022-30329 An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. An OS injection vulnerability exists within the web interface, allowing an attac… Tew 831dr Firmware Mitigation only Fix from $2,3002022-06-16 HIGH 8.8 CVE-2022-30023EPSS 39% Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function. Hg9 Firmware Mitigation only Fix from $1,9502022-06-16 HIGH 8.8 CVE-2022-33140 The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group … Nifi after 1.16.2 Fix from $1,9502022-06-15 CRITICAL 9.8 CVE-2022-31311 An issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to execute arbitrary commands via a crafted POST request. Aerial X 1200m Firmware No fix yet Fix from $2,3002022-06-14 CRITICAL 9.8 CVE-2022-31446EPSS 34% Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/gof… Ac18 Firmware No fix yet Fix from $2,3002022-06-14 CRITICAL 9.8 CVE-2022-30308 In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for po… Controller Cecc X M1 Firmware after 3.8.14 Fix from $2,3002022-06-13 CRITICAL 9.8 CVE-2022-30309 In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for p… Controller Cecc X M1 Firmware after 3.8.14 Fix from $2,3002022-06-13 CRITICAL 9.8 CVE-2022-30310 In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syn… Controller Cecc X M1 Firmware after 3.8.14 Fix from $2,3002022-06-13 CRITICAL 9.8 CVE-2022-30311 In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syn… Controller Cecc X M1 Firmware after 3.8.14 Fix from $2,3002022-06-13 HIGH 8.8 CVE-2021-41738 ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system … Zeroshell Mitigation only Fix from $1,9502022-06-11 CRITICAL 9.8 CVE-2019-25065EPSS 7% A vulnerability was found in OpenNetAdmin 18.1.1. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulati… Opennetadmin No fix yet Fix from $2,3002022-06-09 HIGH 8.8 CVE-2019-25066EPSS 5% A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipul… Ajenti Patch available Fix from $1,9502022-06-09 CRITICAL 9.8 CVE-2022-1986 OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9. Gogs 0.12.9+ Fix from $2,3002022-06-09 CRITICAL 9.8 CVE-2022-29013EPSS 77% A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a cr… Sila Firmware No fix yet Fix from $2,3002022-06-09 HIGH 8.8 CVE-2022-1703EPSS 12% Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inj… Sma 210 Firmware after 10.2.1.4-31sv Fix from $1,9502022-06-08