Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.5 CVE-2022-1359 The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside… Cnmaestro Mitigation only Fix from $1,9502022-05-17 CRITICAL 9.8 CVE-2022-1360 The affected On-Premise cnMaestro is vulnerable to execution of code on the cnMaestro hosting server. This could allow a remote attacker to change se… Cnmaestro Mitigation only Fix from $2,3002022-05-17 HIGH 7.3 CVE-2022-1362 The affected On-Premise cnMaestro is vulnerable inside a specific route where a user can upload a crafted package to the system. An attacker could ab… Cnmaestro Mitigation only Fix from $1,9502022-05-17 HIGH 7.8 CVE-2022-1356 cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, w… Cnmaestro Mitigation only Fix from $1,9502022-05-17 CRITICAL 9.8 CVE-2022-1357 The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of t… Cnmaestro Mitigation only Fix from $2,3002022-05-17 HIGH 8.8 CVE-2022-24388 Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deceptio… Deception 9.4.5+ Fix from $1,9502022-05-17 HIGH 8.8 CVE-2022-24389 Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and De… Deception 9.4.5+ Fix from $1,9502022-05-17 HIGH 8.8 CVE-2022-24390 Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network … Deception 9.4.5+ Fix from $1,9502022-05-17 HIGH 8.8 CVE-2022-24392 Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “feed_comm_tes… Deception 9.4.5+ Fix from $1,9502022-05-17 HIGH 8.8 CVE-2022-24393 Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica… Deception 9.4.5+ Fix from $1,9502022-05-17 HIGH 8.8 CVE-2022-24394 Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkf… Deception 9.4.5+ Fix from $1,9502022-05-17 HIGH 7.2 CVE-2022-23672 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below… Clearpass Policy Manager 6.8.9+ Fix from $1,9502022-05-17 HIGH 7.2 CVE-2022-23673 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below… Clearpass Policy Manager 6.8.9+ Fix from $1,9502022-05-17 HIGH 7.2 CVE-2022-23667 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below… Clearpass Policy Manager 6.8.9 / 6.9.10+ Fix from $1,9502022-05-16 CRITICAL 9.1 CVE-2022-23661 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below… Clearpass Policy Manager 6.8.9 / 6.9.10+ Fix from $2,3002022-05-16 CRITICAL 9.1 CVE-2022-23662 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below… Clearpass Policy Manager 6.8.9 / 6.9.10+ Fix from $2,3002022-05-16 CRITICAL 9.1 CVE-2022-23663 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below… Clearpass Policy Manager 6.8.9 / 6.9.10+ Fix from $2,3002022-05-16 CRITICAL 9.1 CVE-2022-23664 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below… Clearpass Policy Manager 6.8.9 / 6.9.10+ Fix from $2,3002022-05-16 CRITICAL 9.1 CVE-2022-23665 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below… Clearpass Policy Manager 6.8.9 / 6.9.10+ Fix from $2,3002022-05-16 CRITICAL 9.1 CVE-2022-23666 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below… Clearpass Policy Manager 6.8.9 / 6.9.10+ Fix from $2,3002022-05-16 CRITICAL 9.8 CVE-2021-42897 A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed in… Feminer Wms No fix yet Fix from $2,3002022-05-16 HIGH 8.8 CVE-2021-42969 Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something … Anaconda3 No fix yet Fix from $1,9502022-05-13 HIGH 7.2 CVE-2022-26007EPSS 6% An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network … Ir302 Firmware No fix yet Fix from $1,9502022-05-12 HIGH 8.8 CVE-2022-26042EPSS 9% An OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network… Ir302 Firmware No fix yet Fix from $1,9502022-05-12 HIGH 8.8 CVE-2022-26075EPSS 6% An OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted … Ir302 Firmware No fix yet Fix from $1,9502022-05-12 HIGH 8.8 CVE-2022-26085EPSS 13% An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP re… Ir302 Firmware No fix yet Fix from $1,9502022-05-12 HIGH 8.8 CVE-2022-26420EPSS 6% An OS command injection vulnerability exists in the console infactory_port functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted … Ir302 Firmware No fix yet Fix from $1,9502022-05-12 HIGH 8.8 CVE-2022-26518 An OS command injection vulnerability exists in the console infactory_net functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted s… Ir302 Firmware No fix yet Fix from $1,9502022-05-12 CRITICAL 9.8 CVE-2022-29303 KEVEPSS 98% SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php. Sv Cpt Mc310 Firmware Mitigation only Fix from $2,3002022-05-12 CRITICAL 9.8 CVE-2022-29539 resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are pr… Gemini Net Mitigation only Fix from $2,3002022-05-12