Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2021-44827EPSS 54% There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6… Archer C20i Firmware after 170221 Fix from $1,9502022-03-04 CRITICAL 9.8 CVE-2022-0848EPSS 35% OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11. Part Db 0.5.11+ Fix from $2,3002022-03-04 MEDIUM 5.5 CVE-2022-24725 Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when… Shescape 1.5.1+ Fix from $1,6002022-03-03 CRITICAL 9.8 CVE-2022-0841 OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4. Npm Lockfile Patch available Fix from $2,3002022-03-03 HIGH 7.8 CVE-2022-22301 An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiAP-C console 5.4.0 through 5.4.3, 5.2.0 through 5… Fortiap C Patch available Fix from $1,9502022-03-02 HIGH 8.8 CVE-2021-43075 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.… Fortiwlm 8.6.3+ Fix from $1,9502022-03-01 CRITICAL 9.8 CVE-2021-4039EPSS 71% A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on … Nwa1100 Nh Firmware 2.12+ Fix from $2,3002022-03-01 CRITICAL 9.8 CVE-2020-12775 Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated re… Hicos after 3.0.0 Fix from $2,3002022-03-01 MEDIUM 6.7 CVE-2022-0764 Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0. Strapi 4.1.0+ Fix from $1,6002022-02-26 CRITICAL 9.8 CVE-2022-25060EPSS 40% TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing. Tl Wr840n Firmware Mitigation only Fix from $2,3002022-02-25 CRITICAL 9.8 CVE-2022-25061EPSS 58% TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute. Tl Wr840n Firmware Mitigation only Fix from $2,3002022-02-25 CRITICAL 9.8 CVE-2022-25064EPSS 36% TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr. Tl Wr840n Firmware Mitigation only Fix from $2,3002022-02-25 CRITICAL 9.8 CVE-2022-25263 JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration. Teamcity 2021.2.3+ Fix from $2,3002022-02-25 HIGH 7.3 CVE-2022-25328 The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set … Fscrypt 0.3.3+ Fix from $1,9502022-02-25 HIGH 8.8 CVE-2022-24288EPSS 78% In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command In… Airflow 2.2.4+ Fix from $1,9502022-02-25 CRITICAL 9.8 CVE-2022-25075EPSS 54% TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows a… A3000ru Firmware Patch available Fix from $2,3002022-02-24 CRITICAL 9.8 CVE-2022-25076 TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows … A800r Firmware Patch available Fix from $2,3002022-02-24 CRITICAL 9.8 CVE-2022-25077EPSS 33% TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows… A3100r Firmware Patch available Fix from $2,3002022-02-24 CRITICAL 9.8 CVE-2022-25078 TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows… A3600r Firmware Patch available Fix from $2,3002022-02-24 CRITICAL 9.8 CVE-2022-25079 TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows … A810r Firmware Patch available Fix from $2,3002022-02-24 CRITICAL 9.8 CVE-2022-25080 TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows att… A830r Firmware Patch available Fix from $2,3002022-02-24 CRITICAL 9.8 CVE-2022-25081 TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attac… T10 V2 Firmware Patch available Fix from $2,3002022-02-24 CRITICAL 9.8 CVE-2022-25082EPSS 16% TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function.… A950rg Firmware Patch available Fix from $2,3002022-02-24 CRITICAL 9.8 CVE-2022-25083 TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows … A860r Firmware Patch available Fix from $2,3002022-02-24 CRITICAL 9.8 CVE-2022-25084EPSS 25% TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attack… T6 Firmware Patch available Fix from $2,3002022-02-24 HIGH 8.8 CVE-2021-4029 A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commands via a… Nbg6816 Firmware 1.00+ Fix from $1,9502022-02-24 HIGH 8.8 CVE-2022-20650EPSS 15% A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root p… Nx Os Mitigation only Fix from $1,9502022-02-23 CRITICAL 9.8 CVE-2022-21143 MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does… Mimosa Management Platform 1.0.3 / 2.5.4.1+ Fix from $2,3002022-02-18 CRITICAL 9.8 CVE-2021-46315EPSS 7% Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enF… Dir 846 Firmware No fix yet Fix from $2,3002022-02-17 CRITICAL 9.8 CVE-2021-46319EPSS 7% Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicious users c… Dir 846 Firmware No fix yet Fix from $2,3002022-02-17