Vulnerabilities (CVE)

Filtered by CWE-78
Total 3852 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45996 1 Tenda 2 W15e, W20e Firmware 2024-11-21 N/A 7.2 HIGH
Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.
CVE-2022-45977 1 Tenda 2 Ax12, Ax12 Firmware 2024-11-21 N/A 8.8 HIGH
Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.
CVE-2022-45942 1 Baijiacms Project 1 Baijiacms 2024-11-21 N/A 8.8 HIGH
A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.
CVE-2022-45939 3 Debian, Fedoraproject, Gnu 3 Debian Linux, Fedora, Emacs 2024-11-21 N/A 7.8 HIGH
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command (suggested in the ctags documentation) in a situation where the current working directory has contents that depend on untrusted input.
CVE-2022-45915 1 Ilias 1 Ilias 2024-11-21 N/A 8.8 HIGH
ILIAS before 7.16 allows OS Command Injection.
CVE-2022-45768 1 Edimax 2 Br-6428ns, Br-6428ns Firmware 2024-11-21 N/A 8.8 HIGH
Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute arbitrary code via the formWlanMP function.
CVE-2022-45717 1 Ip-com 2 M50, M50 Firmware 2024-11-21 N/A 9.8 CRITICAL
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function. This vulnerability is exploited via a crafted GET request.
CVE-2022-45711 1 Ip-com 2 M50, M50 Firmware 2024-11-21 N/A 9.8 CRITICAL
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools function.
CVE-2022-45709 1 Ip-com 2 M50, M50 Firmware 2024-11-21 N/A 9.8 CRITICAL
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function.
CVE-2022-45699 1 Apsystems 2 Ecu-r, Ecu-r Firmware 2024-11-21 N/A 9.8 CRITICAL
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.
CVE-2022-45639 1 Sleuthkit 1 The Sleuth Kit 2024-11-21 N/A 7.8 HIGH
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.
CVE-2022-45506 1 Tenda 2 W30e, W30e Firmware 2024-11-21 N/A 9.8 CRITICAL
Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.
CVE-2022-45497 1 Tenda 2 W6-s, W6-s Firmware 2024-11-21 N/A 9.8 CRITICAL
Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommand.
CVE-2022-45461 3 Linux, Opengroup, Veritas 3 Linux Kernel, Unix, Netbackup 2024-11-21 N/A 7.5 HIGH
The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.
CVE-2022-45145 1 Call-cc 1 Chicken 2024-11-21 N/A 9.8 CRITICAL
egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.
CVE-2022-45104 1 Dell 3 Evasa Provider Virtual Appliance, Solutions Enabler Virtual Appliance, Unisphere For Powermax Virtual Appliance 2024-11-21 N/A 8.8 HIGH
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands on the underlying system.
CVE-2022-45045 1 Xiongmaitech 144 Mbd6304t, Mbd6304t Firmware, Nbd6808t-pl and 141 more 2024-11-21 N/A 8.8 HIGH
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 2021, Xiongmai has applied patches to prevent attackers from using this mechanism to execute telnetd.
CVE-2022-45043 1 Tenda 2 Ax12, Ax12 Firmware 2024-11-21 N/A 8.8 HIGH
Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set.
CVE-2022-45026 1 Markdown Preview Enhanced Project 1 Markdown Preview Enhanced 2024-11-21 N/A 9.8 CRITICAL
An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GFM export process.
CVE-2022-45025 1 Markdown Preview Enhanced Project 1 Markdown Preview Enhanced 2024-11-21 N/A 9.8 CRITICAL
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import function.