Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2022-28557EPSS 23% There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, … Ac15 Firmware No fix yet Fix from $2,3002022-05-04 HIGH 8.8 CVE-2022-27903 An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allo… Eve Ng after 4.0.1-65 Fix from $1,9502022-05-04 CRITICAL 9.8 CVE-2022-28055 Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function. Fusionpbx after 4.4.0 Fix from $2,3002022-05-04 HIGH 8.8 CVE-2021-43164EPSS 35% A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the u… Reyeeos after 1.55.1915_ew_3.0 Fix from $1,9502022-05-04 HIGH 7.3 CVE-2022-1292EPSS 83% The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating system… OpenSSL 1.0.2ze / 1.1.1o+ Fix from $1,9502022-05-03 HIGH 8.8 CVE-2021-42165EPSS 14% MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file … Gpt 2541gnac N1 Firmware No fix yet Fix from $1,9502022-05-03 CRITICAL 9.8 CVE-2022-28573EPSS 28% D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. This vulnerability allows a… Dir 823 Pro Firmware No fix yet Fix from $2,3002022-05-02 CRITICAL 9.8 CVE-2022-28571EPSS 6% D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli. Dir 882 Firmware No fix yet Fix from $2,3002022-05-02 HIGH 8.8 CVE-2022-28572 Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function Ax1806 Firmware No fix yet Fix from $1,9502022-05-02 HIGH 8.8 CVE-2022-29937 USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because some common OS commands are bloc… Oracle Optimization No fix yet Fix from $1,9502022-04-29 HIGH 8.8 CVE-2021-34602 In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell … Cc612 Firmware 5.11.2 / 5.12.5+ Fix from $1,9502022-04-27 CRITICAL 9.8 CVE-2021-46422EPSS 95% Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any auth… Sdt Cs3b1 Firmware No fix yet Fix from $2,3002022-04-27 HIGH 8.8 CVE-2021-46441EPSS 33% In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary s… Dir 825 Firmware No fix yet Fix from $1,9502022-04-27 CRITICAL 9.8 CVE-2022-1440 Command Injection vulnerability in [email protected] in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input,… Git Interface 2.1.2+ Fix from $2,3002022-04-22 MEDIUM 6.8 CVE-2022-28810 KEVEPSS 71% Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYST… Manageengine Adselfservice Plus 6.1+ Fix from $1,6002022-04-18 HIGH 7.2 CVE-2022-20718 Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary com… Ios Xe No fix yet Fix from $1,9502022-04-15 HIGH 7.2 CVE-2022-20693 A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against a… Ios Xe Mitigation only Fix from $1,9502022-04-15 HIGH 7.8 CVE-2022-27188 OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.… B\/m9000 Vp Mitigation only Fix from $1,9502022-04-15 CRITICAL 9.8 CVE-2021-22795 A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code… Struxureware Data Center Expert after 7.8.1 Fix from $2,3002022-04-13 CRITICAL 9.8 CVE-2022-29080 The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON … Npm Dependency Versions after 0.3.0 Fix from $2,3002022-04-12 HIGH 7.8 CVE-2022-1262 A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary comm… Dir 1360 Firmware No fix yet Fix from $1,9502022-04-11 HIGH 8.8 CVE-2022-0999 An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior. Mypro after 8.25.0 Fix from $1,9502022-04-11 HIGH 8.0 CVE-2022-26413 A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker… Vmg3312 T20a Firmware 5.13 / 5.17+ Fix from $1,9502022-04-11 CRITICAL 9.8 CVE-2022-27268 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the … Inrouter 900 Firmware 1.0.0.r11700+ Fix from $2,3002022-04-10 CRITICAL 9.8 CVE-2022-27269 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the … Inrouter 900 Firmware 1.0.0.r11700+ Fix from $2,3002022-04-10 CRITICAL 9.8 CVE-2022-27270 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the … Inrouter 900 Firmware 1.0.0.r11700+ Fix from $2,3002022-04-10 CRITICAL 9.8 CVE-2022-27271 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the … Inrouter 900 Firmware 1.0.0.r11700+ Fix from $2,3002022-04-10 CRITICAL 9.8 CVE-2022-27272 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the … Inrouter 900 Firmware 1.0.0.r11700+ Fix from $2,3002022-04-10 CRITICAL 9.8 CVE-2022-27273 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the … Inrouter 900 Firmware 1.0.0.r11700+ Fix from $2,3002022-04-10 CRITICAL 9.8 CVE-2022-27274 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the … Inrouter 900 Firmware 1.0.0.r11700+ Fix from $2,3002022-04-10