Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Ecs2020 Firmware CRITICAL 9.8
CVE-2019-6288

Edgecore ECS2020 Firmware 1.0.0.0 devices allow Unauthenticated Command Injection via the command1 HTTP header to the /EXCU_SHELL URI.

No fix yet
Fix from $2,300 2021-09-22
Desktop Central CRITICAL 9.8
CVE-2021-28960

Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-d…

Fix: 10.0.683+
Fix from $2,300 2021-09-21
R6020 Firmware HIGH 7.2
CVE-2021-41383

setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters in the ntp_server field.

No fix yet
Fix from $1,950 2021-09-17
Ax3600 CRITICAL 9.8
CVE-2020-14119

There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi ro…

Fix: 1.1.12+
Fix from $2,300 2021-09-16
Ax3600 Firmware HIGH 7.2
CVE-2020-14109

There is command injection in the meshd program in the routing system, resulting in command execution under administrator authority on Xiaomi router …

Fix: after 1.1.12
Fix from $1,950 2021-09-16
Jfinal Cms HIGH 8.8
CVE-2020-19151EPSS 5%

Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via …

Fix: after 4.7.1
Fix from $1,950 2021-09-15
Systeminformation CRITICAL 9.8
CVE-2020-26300

systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is …

Fix: 4.26.2+
Fix from $2,300 2021-09-09
Cx5500 Firmware HIGH 7.2
CVE-2021-37145

A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attacker to Privi…

Mitigation only
Fix from $1,950 2021-09-07
Sd Wan HIGH 7.2
CVE-2021-37717

A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): …

Fix: 2.2.0.6 / 8.3.0.16+
Fix from $1,950 2021-09-07
Sd Wan HIGH 7.2
CVE-2021-37718

A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): …

Fix: 2.2.0.6 / 8.3.0.16+
Fix from $1,950 2021-09-07
Sd Wan HIGH 7.2
CVE-2021-37719

A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): …

Fix: 2.2.0.4 / 6.4.4.25+
Fix from $1,950 2021-09-07
Sd Wan HIGH 7.2
CVE-2021-37720

A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): …

Fix: 2.2.0.4 / 6.4.4.25+
Fix from $1,950 2021-09-07
Sd Wan HIGH 7.2
CVE-2021-37721

A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): …

Fix: 2.2.0.4 / 6.4.4.25+
Fix from $1,950 2021-09-07
Sd Wan HIGH 7.2
CVE-2021-37722

A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): …

Fix: 2.2.0.4 / 6.4.4.25+
Fix from $1,950 2021-09-07
Arubaos HIGH 7.2
CVE-2021-37723

A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12,…

Fix: 8.3.0.16 / 8.5.0.12+
Fix from $1,950 2021-09-07
Arubaos HIGH 7.2
CVE-2021-37724

A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12,…

Fix: 8.3.0.16 / 8.5.0.12+
Fix from $1,950 2021-09-07
Craigms CRITICAL 9.8
CVE-2020-18048

An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered into the DB Name field.

No fix yet
Fix from $2,300 2021-09-02
Zeppelin CRITICAL 9.8
CVE-2019-10095EPSS 6%

bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affe…

Fix: after 0.9.0
Fix from $2,300 2021-09-02
Adobe Commerce HIGH 7.2
CVE-2021-36024

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special E…

Fix: after 2.4.2
Fix from $1,950 2021-09-01
Orion Platform HIGH 7.2
CVE-2021-35220

Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.

Fix: 2020.2.6+
Fix from $1,950 2021-08-31
Simiki CRITICAL 9.8
CVE-2020-19001

Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob…

No fix yet
Fix from $2,300 2021-08-27
Application Policy Infrastructure Controller HIGH 7.2
CVE-2021-1580

Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow…

Fix: 3.2 / 4.2+
Fix from $1,950 2021-08-25
Dir 816 Firmware CRITICAL 9.8
CVE-2021-39510EPSS 9%

An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /gofor…

No fix yet
Fix from $2,300 2021-08-24
Dir 816 Firmware CRITICAL 9.8
CVE-2021-39509EPSS 5%

An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/f…

No fix yet
Fix from $2,300 2021-08-24
Raspap HIGH 8.8
CVE-2021-38556EPSS 13%

includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.

No fix yet
Fix from $1,950 2021-08-24
Remkon Device Manager CRITICAL 9.8
CVE-2021-38611

A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to execute arbitrary com…

No fix yet
Fix from $2,300 2021-08-24
Phpmywind HIGH 7.2
CVE-2020-18885

Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.…

No fix yet
Fix from $1,950 2021-08-20
Smartermail HIGH 8.1
CVE-2020-29548

An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS comma…

Fix: after 100.0.7537
Fix from $1,950 2021-08-17
Diez HIGH 7.0
CVE-2021-32830

The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability. Clients of th…

No fix yet
Fix from $1,950 2021-08-17
S\/qmail MEDIUM 5.9
CVE-2020-15955

In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmai…

Fix: after 4.0.07
Fix from $1,600 2021-08-17