VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2021-36667High· 7.8
4y ago

Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.

Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.

▾ Twilightdruva · insync_clientEPSS 2.7%via NVD
CVE-2022-30023High· 8.8⚠ ExploitedPoC
4y ago

Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

▾ Midnighttenda · hg9_firmwareEPSS 39%via NVD
CVE-2021-42875Critical· 9.8
4y ago

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.

▾ Midnighttotolink · ex1200t_firmwareEPSS 4.4%via NVD
CVE-2021-42872Critical· 9.8
4y ago

TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.

TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.

▾ Midnighttotolink · ex1200t_firmwareEPSS 6.6%via NVD
CVE-2021-43164High· 8.8PoC
4y ago

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

▾ Midnightruijienetworks · reyeeosEPSS 35%via NVD
CVE-2020-27373High· 8.8
4y ago

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE.

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE.

▾ Twilightdrtrustusa · icheck_connect_bp_monitor_bp_testing_118_firmwareEPSS 1.00%via NVD
CVE-2021-46007Critical· 9.8
4y ago

totolink a3100r V5.9c.4577 is vulnerable to os command injection

totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks.

▾ Midnighttotolink · ar3100r_firmwareEPSS 2.6%via NVD
CVE-2022-26258Critical· 9.8CISA KEV
4y ago

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

▾ Hadaldlink · dir-820l_firmwareEPSS 92%via NVD
CVE-2022-25064Critical· 9.8PoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 36%via NVD
CVE-2022-25061Critical· 9.8PoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 59%via NVD
CVE-2022-25060Critical· 9.8⚠ ExploitedPoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 40%via NVD
CVE-2021-42912High· 8.8
4y ago

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, b…

▾ Twilightfiberhome · an5506-01-a_firmwareEPSS 10%via NVD
CVE-2020-25367Critical· 9.8
4y ago

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.

▾ Midnightdlink · dir-823g_firmwareEPSS 8.6%via NVD
CVE-2020-25368Critical· 9.8
4y ago

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.

▾ Midnightdlink · dir-823g_firmwareEPSS 8.6%via NVD
CVE-2021-1448High· 7.8
5y ago

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device that is …

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device that is …

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 0.30%via NVD
CVE-2020-21883High· 8.8
5y ago

Unibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerability in /tools/ping, which can leads to complete device takeover.

Unibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerability in /tools/ping, which can leads to complete device takeover.

▾ Twilightindionetworks · unibox_u50_firmwareEPSS 4.1%via NVD
CVE-2021-28927High· 7.8
5y ago

The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the accessibility_speak_windows function, which allows attackers who have write access on filesystems t…

The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the accessibility_speak_windows function, which allows attackers who have write access on filesystems t…

▾ Twilightlibretro · retroarchEPSS 1.3%via NVD
CVE-2020-27575High· 8.8
5y ago

Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability

Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrators are able to manage users. The edit users form contains a parameter vulnerable to comma…

▾ Twilightmaxum · rumpusEPSS 3.1%via NVD
CVE-2021-25298High· 8.8CISA KEVPoC
5y ago

Nagios XI version xi-5.7.5 is affected by OS command injection

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled …

▾ Abyssalnagios · nagios_xiEPSS 75%via NVD
CVE-2021-25297High· 8.8CISA KEVPoC
5y ago

Nagios XI version xi-5.7.5 is affected by OS command injection

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled inpu…

▾ Abyssalnagios · nagios_xiEPSS 57%via NVD
CVE-2018-19949Critical· 9.8CISA KEV0day
5y ago

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130…

▾ Hadalqnap · qtsEPSS 28%via NVD
CVE-2020-3167High· 7.8
6y ago

A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS)

A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 0.89%via NVD
CVE-2019-18184Critical· 9.8
6y ago

Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.

Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.

▾ Midnightcrestron · dmc-stro_firmwareEPSS 8.1%via NVD
CVE-2019-12699High· 7.8
6y ago

Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges

Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges. T…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 0.90%via NVD
CVE-2019-15107Critical· 9.8CISA KEVPoC
7y ago

An issue was discovered in Webmin <=1.920

An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

▾ Hadalwebmin · webminEPSS 100%via NVD
CVE-2019-1971Critical· 9.8
7y ago

A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges

A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vuln…

▾ Midnightcisco · enterprise_nfv_infrastructure_softwareEPSS 3.6%via NVD
CVE-2019-1960Medium· 4.4
7y ago

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information abo…

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.35%via NVD
CVE-2019-1959Medium· 4.4
7y ago

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information abo…

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.35%via NVD
CVE-2019-1709Medium· 6.0
7y ago

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could …

▾ Sunlitcisco · secure_firewall_management_centerEPSS 0.68%via NVD
CVE-2018-19908High· 8.8PoC
7y ago

An issue was discovered in MISP 2.4.9x before 2.4.99

An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulnerability can be abused by a malicious authenticated user …

▾ Midnightmisp-project · mispEPSS 17%via NVD
CWE-78 vulnerabilities (CVEs) — page 24 · VulnSea