Vulnerabilities (CVE)

Filtered by CWE-77
Total 3837 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-26187 1 Totolink 2 N600r, N600r Firmware 2026-06-17 7.5 HIGH 9.8 CRITICAL
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function.
CVE-2022-26186 1 Totolink 2 N600r, N600r Firmware 2026-06-17 7.5 HIGH 9.8 CRITICAL
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.
CVE-2022-26151 1 Citrix 1 Xenmobile Server 2026-06-17 9.0 HIGH 7.2 HIGH
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
CVE-2022-26085 1 Inhandnetworks 2 Ir302, Ir302 Firmware 2026-06-17 6.5 MEDIUM 8.8 HIGH
An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVE-2022-26042 1 Inhandnetworks 2 Ir302, Ir302 Firmware 2026-06-17 6.5 MEDIUM 8.8 HIGH
An OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.
CVE-2022-26007 1 Inhandnetworks 2 Ir302, Ir302 Firmware 2026-06-17 9.0 HIGH 7.2 HIGH
An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.
CVE-2022-25962 1 Vagrant.js Project 1 Vagrant.js 2026-06-17 N/A 7.4 HIGH
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
CVE-2022-25923 1 Exec-local-bin Project 1 Exec-local-bin 2026-06-17 N/A 7.4 HIGH
Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input sanitization.
CVE-2022-25916 1 Mt7688-wiscan Project 1 Mt7688-wiscan 2026-06-17 N/A 7.4 HIGH
Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' function.
CVE-2022-25908 1 Create-choo-electron Project 1 Create-choo-electron 2026-06-17 N/A 7.4 HIGH
All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.
CVE-2022-25855 1 Create-choo-app3 Project 1 Create-choo-app3 2026-06-17 N/A 7.4 HIGH
All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.
CVE-2022-25834 1 Percona 1 Xtrabackup 2026-06-17 N/A 7.8 HIGH
In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected command shell execution of arbitrary commands.
CVE-2022-25619 1 Profelis 1 Sambabox 2026-06-17 4.6 MEDIUM 3.8 LOW
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause run arbitrary code. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86.
CVE-2022-25350 1 Helecloud 1 Puppet-facter 2026-06-17 N/A 7.4 HIGH
All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.
CVE-2022-25137 1 Totolink 4 T10, T10 Firmware, T6 and 1 more 2026-06-17 7.5 HIGH 9.8 CRITICAL
A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
CVE-2022-25136 1 Totolink 4 T10, T10 Firmware, T6 and 1 more 2026-06-17 7.5 HIGH 9.8 CRITICAL
A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
CVE-2022-25135 1 Totolink 2 T6, T6 Firmware 2026-06-17 7.5 HIGH 9.8 CRITICAL
A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
CVE-2022-25134 1 Totolink 2 T6, T6 Firmware 2026-06-17 7.5 HIGH 9.8 CRITICAL
A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
CVE-2022-25133 1 Totolink 2 T6, T6 Firmware 2026-06-17 7.5 HIGH 9.8 CRITICAL
A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
CVE-2022-25132 1 Totolink 4 T10, T10 Firmware, T6 and 1 more 2026-06-17 7.5 HIGH 9.8 CRITICAL
A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.