Skip to main content

CWE archive

CWE-77 CVEs

Programmatic archive

3,619 CVEs tagged with CWE-77952 Critical, 1,469 High, 772 Medium, 424 Low, 2 Unrated.

CVE-2022-0902

Published Jul 21, 2022

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability i…

CVSS 8.1 · High
evidence mentions
4
Buzz score
27.6

CVE-2022-31161

Published Jul 15, 2022

Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-28935

Published Jul 6, 2022

Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, Totolink A800R V4.1.2cu.5137_B20200730, Totolink A3000RU V5.…

CVSS 7.2 · High

CVE-2022-32262

Published Jun 14, 2022

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a file upload server that is vulnerable to command inj…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36529

Published Jun 7, 2022

A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the Traceroute Handler. The manip…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29712

Published Jun 2, 2022

LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-29256

Published May 25, 2022

sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm install` time when installing ve…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30321

Published May 25, 2022

go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29184

Published May 20, 2022

GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users who have permissions to edit or create pipeline materials o…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 2,626-2,650 of 3,619 CVEsPage 106 of 145