Show filters
841 Total Results
Displaying 41-50 of 841
Sort by:
Attacker Value
Unknown
CVE-2022-26187
Disclosure Date: March 22, 2022 (last updated February 23, 2025)
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function.
0
Attacker Value
Unknown
CVE-2022-26186
Disclosure Date: March 22, 2022 (last updated February 23, 2025)
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.
0
Attacker Value
Unknown
CVE-2022-22688
Disclosure Date: March 21, 2022 (last updated February 23, 2025)
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2021-45876
Disclosure Date: March 21, 2022 (last updated February 23, 2025)
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is used to generate code which then gets executed when downloading new firmware.
0
Attacker Value
Unknown
CVE-2022-21822
Disclosure Date: March 17, 2022 (last updated February 23, 2025)
NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Throttling, which may lead to cause system unavailable.
0
Attacker Value
Unknown
CVE-2022-26354
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.
0
Attacker Value
Unknown
CVE-2022-26353
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.
0
Attacker Value
Unknown
CVE-2022-27002
Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
0
Attacker Value
Unknown
CVE-2022-27001
Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
0
Attacker Value
Unknown
CVE-2022-27000
Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_backup_ntp_server, and h_time_zone parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
0