Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2021-45382 KEVEPSS 98% A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L rout… Dir 820l Firmware Mitigation only Fix from $2,3002022-02-17 CRITICAL 9.8 CVE-2021-46314EPSS 33% A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bi… Dir 846 Firmware No fix yet Fix from $2,3002022-02-17 CRITICAL 9.9 CVE-2021-3781EPSS 84% A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe comm… Fedora Patch available Fix from $2,3002022-02-16 HIGH 7.8 CVE-2022-22945 VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary comman… Cloud Foundation 6.4.13+ Fix from $1,9502022-02-16 HIGH 8.8 CVE-2021-26726 A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM p… Dna after 2021 Fix from $1,9502022-02-16 HIGH 8.8 CVE-2022-25173 Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typ… Pipeline\ after 2648.va9433432b33c Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25174 Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libr… Pipeline\ after 552.vd9cc05b8a2e1 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25175 Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, all… Pipeline\ after 706.vd43c65dec013 Fix from $1,9502022-02-15 CRITICAL 9.8 CVE-2022-23389EPSS 22% PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter. Publiccms No fix yet Fix from $2,3002022-02-14 HIGH 7.2 CVE-2022-0557EPSS 51% OS Command Injection in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,9502022-02-11 HIGH 8.0 CVE-2022-20708 KEVEPSS 15% Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex… Rv340 Firmware after 1.0.03.24 Fix from $1,9502022-02-10 CRITICAL 9.8 CVE-2021-26616 An OS command injection was found in SecuwaySSL, when special characters injection on execute command with runCommand arguments. Secuwayssl U after 2.0.0.8 Fix from $2,3002022-02-09 HIGH 8.8 CVE-2021-43928 Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mail sending and receiving component in S… Mail Station 20211105+ Fix from $1,9502022-02-07 CRITICAL 9.8 CVE-2022-24552 A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go d… Nas 0.2+ Fix from $2,3002022-02-06 CRITICAL 9.8 CVE-2022-23611 iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize im… Itunesrpc Remastered Patch available Fix from $2,3002022-02-04 CRITICAL 9.8 CVE-2022-0365 The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and execute arbitrary shell comman… S9922l Firmware Mitigation only Fix from $2,3002022-02-04 CRITICAL 9.8 CVE-2021-29393 Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated use… Northstar Club Management Mitigation only Fix from $2,3002022-02-04 CRITICAL 9.8 CVE-2021-45986 Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This v… G1 Firmware Mitigation only Fix from $2,3002022-02-04 CRITICAL 9.8 CVE-2021-45987 Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This … G1 Firmware Mitigation only Fix from $2,3002022-02-04 HIGH 8.8 CVE-2021-41018 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and… Fortiweb 6.2.7 / 6.3.16+ Fix from $1,9502022-02-02 HIGH 8.8 CVE-2021-41016 A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and be… Fortiextender Firmware 4.1.8 / 4.2.4+ Fix from $1,9502022-02-02 HIGH 8.8 CVE-2021-43073 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.… Fortiweb 6.2.7 / 6.3.17+ Fix from $1,9502022-02-02 HIGH 7.2 CVE-2021-40407 KEVEPSS 48% An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], bas… Rlc 410w Firmware Mitigation only Fix from $1,9502022-01-28 CRITICAL 9.8 CVE-2021-40408 An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], bas… Rlc 410w Firmware No fix yet Fix from $2,3002022-01-28 CRITICAL 9.8 CVE-2021-40409 An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], bas… Rlc 410w Firmware No fix yet Fix from $2,3002022-01-28 HIGH 7.2 CVE-2021-40410EPSS 28% An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [4] the dns_dat… Rlc 410w Firmware No fix yet Fix from $1,9502022-01-28 HIGH 7.2 CVE-2021-40411 An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [6] the dns_dat… Rlc 410w Firmware No fix yet Fix from $1,9502022-01-28 HIGH 7.2 CVE-2021-40412EPSS 27% An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [8] the devname … Rlc 410w Firmware No fix yet Fix from $1,9502022-01-28 HIGH 7.2 CVE-2020-28884 Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute a… Liferay Portal Mitigation only Fix from $1,9502022-01-28 HIGH 7.2 CVE-2020-28885 Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo … Liferay Portal Mitigation only Fix from $1,9502022-01-28