Total
1397 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-46421 | 1 Apache | 1 Apache-airflow-providers-apache-hive | 2022-12-30 | N/A | 9.8 CRITICAL |
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0. | |||||
CVE-2022-24431 | 1 Abacus-ext-cmdline Project | 1 Abacus-ext-cmdline | 2022-12-30 | N/A | 9.8 CRITICAL |
All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper user-input sanitization. | |||||
CVE-2022-22744 | 2 Microsoft, Mozilla | 4 Windows, Firefox, Firefox Esr and 1 more | 2022-12-29 | N/A | 8.8 HIGH |
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. | |||||
CVE-2022-25171 | 1 P4 Project | 1 P4 | 2022-12-29 | N/A | 9.8 CRITICAL |
The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization | |||||
CVE-2022-47210 | 1 Netgear | 2 Rax30, Rax30 Firmware | 2022-12-29 | N/A | 7.8 HIGH |
The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any authenticated user to execute arbitrary commands on the device. | |||||
CVE-2022-46404 | 1 Atos | 2 Unify Openscape 4000 Assistant, Unify Openscape 4000 Manager | 2022-12-27 | N/A | 9.8 CRITICAL |
A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may allow an unauthenticated attacker to upload arbitrary files and achieve administrative access to the system. | |||||
CVE-2022-46538 | 1 Tenda | 2 F1203, F1203 Firmware | 2022-12-23 | N/A | 9.8 CRITICAL |
Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac. | |||||
CVE-2022-46634 | 1 Totolink | 2 A7100ru, A7100ru Firmware | 2022-12-21 | N/A | 9.8 CRITICAL |
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiWpsCfg function. | |||||
CVE-2022-46631 | 1 Totolink | 2 A7100ru, A7100ru Firmware | 2022-12-21 | N/A | 9.8 CRITICAL |
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiSignalCfg function. | |||||
CVE-2022-31702 | 1 Vmware | 1 Vrealize Network Insight | 2022-12-16 | N/A | 9.8 CRITICAL |
vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication. | |||||
CVE-2022-44832 | 1 Dlink | 2 Dir-3040, Dir-3040 Firmware | 2022-12-16 | N/A | 9.8 CRITICAL |
D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function. | |||||
CVE-2022-24377 | 1 Cycle-import-check Project | 1 Cycle-import-check | 2022-12-16 | N/A | 9.8 CRITICAL |
The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization. | |||||
CVE-2022-45005 | 1 Ip-com | 2 Ew9, Ew9 Firmware | 2022-12-16 | N/A | 9.8 CRITICAL |
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function. | |||||
CVE-2022-37901 | 1 Arubanetworks | 12 7005, 7008, 7010 and 9 more | 2022-12-15 | N/A | 7.2 HIGH |
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |||||
CVE-2022-37900 | 1 Arubanetworks | 12 7005, 7008, 7010 and 9 more | 2022-12-15 | N/A | 7.2 HIGH |
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |||||
CVE-2022-37899 | 1 Arubanetworks | 12 7005, 7008, 7010 and 9 more | 2022-12-15 | N/A | 7.2 HIGH |
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |||||
CVE-2022-37902 | 1 Arubanetworks | 12 7005, 7008, 7010 and 9 more | 2022-12-15 | N/A | 7.2 HIGH |
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |||||
CVE-2022-45043 | 1 Tenda | 2 Ax12, Ax12 Firmware | 2022-12-14 | N/A | 8.8 HIGH |
Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set. | |||||
CVE-2022-45977 | 1 Tenda | 2 Ax12, Ax12 Firmware | 2022-12-14 | N/A | 8.8 HIGH |
Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function. | |||||
CVE-2022-45996 | 1 Tenda | 2 W15e, W20e Firmware | 2022-12-14 | N/A | 7.2 HIGH |
Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output. |