Fallos del tipo CWE-78

3821 resultados
CVE-2022-50794CRITICALSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Command Injection via UsernameEPSS 3.3%CVE-2025-15254MEDIUMTenda W6-S ATE Service ate TendaAte os command injectionEPSS 3.3%CVE-2022-25168Command injection in org.apache.hadoop.fs.FileUtil.unTarUsingTarEPSS 3.3%CVE-2014-125118CRITICALeScan 5.5-2 Web Management Console Command InjectionEPSS 3.3%CVE-2023-43482HIGHA command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322EPSS 3.3%CVE-2025-8259MEDIUMVaelsys VaelsysV4 Web interface vgrid_server.php execute_DataObjectProc os command injectionEPSS 3.2%CVE-2022-33195CRITICALFour OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9EPSS 3.2%CVE-2022-33192CRITICALFour OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9EPSS 3.2%CVE-2022-33189CRITICALAn OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A EPSS 3.2%CVE-2022-32773CRITICALAn OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and EPSS 3.2%CVE-2019-1581CRITICALPAN-OS: Remote code execution vulnerability in the PAN-OS SSH device management interfaceEPSS 3.2%CVE-2023-26153HIGHVersions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_EPSS 3.2%CVE-2022-42491CRITICALSeveral OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted netwEPSS 3.2%CVE-2022-42492CRITICALSeveral OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted netwEPSS 3.2%CVE-2025-24971CRITICALOS Command Injection endpoint '/upload/init' parameter 'filename' (RCE) in DumpDropEPSS 3.2%CVE-2022-38649CRITICALApache Airflow Pinot provider allowed Command InjectionEPSS 3.2%CVE-2020-2000HIGHPAN-OS: OS command injection and memory corruption vulnerabilityEPSS 3.2%CVE-2024-23109CRITICALAn improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to EPSS 3.2%CVE-2025-20292MEDIUMCisco NXOS Software Command Injection VulnerabilityEPSS 3.2%CVE-2025-54857CRITICALImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge BASIC MB-A130 Ver.1.5.8EPSS 3.2%