Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Prc2402m Firmware CRITICAL 9.8
CVE-2021-36707

In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff contains a…

Fix: after 1.0.18
Fix from $2,300 2021-08-06
Itop HIGH 8.8
CVE-2021-21406

Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the S…

Fix: 2.7.4+
Fix from $1,950 2021-07-21
Enterprise Server MEDIUM 6.5
CVE-2021-22867

A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled …

Fix: 2.22.17 / 3.0.11+
Fix from $1,600 2021-07-14
Sanos CRITICAL 9.8
CVE-2021-32529

Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary commands. Suggest contacting with QS…

Fix: 1.2.0+
Fix from $2,300 2021-07-07
Evernote HIGH 8.8
CVE-2020-17759

An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution…

Mitigation only
Fix from $1,950 2021-06-24
Ibos HIGH 8.8
CVE-2020-21785

In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.

No fix yet
Fix from $1,950 2021-06-24
Download Station HIGH 8.8
CVE-2021-34809

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download S…

Fix: 3.8.16-3566+
Fix from $1,950 2021-06-18
Roon Server HIGH 7.2
CVE-2021-28811

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. Roon Labs has already fixed this vulnerabi…

Fix: 2021-05-18+
Fix from $1,950 2021-06-08
Un462a Firmware CRITICAL 9.8
CVE-2021-20699

Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN…

Mitigation only
Fix from $2,300 2021-06-07
\@backstage\/plugin Techdocs HIGH 7.3
CVE-2021-32661

Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.…

Fix: 0.9.5+
Fix from $1,950 2021-06-03
\@backstage\/techdocs Common HIGH 8.1
CVE-2021-32660

Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versio…

Fix: 0.6.4+
Fix from $1,950 2021-06-03
Video Station HIGH 8.8
CVE-2021-28812

A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attac…

Fix: 5.5.4+
Fix from $1,950 2021-06-03
Debian Linux HIGH 8.8
CVE-2015-1877

The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which all…

Patch available
Fix from $1,950 2021-06-02
Pglogical MEDIUM 6.7
CVE-2021-3515

A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server…

Fix: 2.3.4 / 3.6.26+
Fix from $1,600 2021-06-01
Restapps CRITICAL 9.8
CVE-2020-10666

The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a URL vari…

Fix: after 15.0.19.2
Fix from $2,300 2021-05-31
MariaDB CRITICAL 9.0
CVE-2020-15180EPSS 6%

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be e…

Fix: 5.6.49 / 5.6.49-28.42.2+
Fix from $2,300 2021-05-27
Connect Secure HIGH 8.8
CVE-2021-22899 KEVEPSS 23%

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execut…

Mitigation only
Fix from $1,950 2021-05-27
Versa Director CRITICAL 9.8
CVE-2019-25029

In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnera…

Mitigation only
Fix from $2,300 2021-05-26
Fusion CRITICAL 9.8
CVE-2020-28908EPSS 6%

Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.

Fix: after 4.1.8
Fix from $2,300 2021-05-24
Fusion CRITICAL 9.8
CVE-2020-28901EPSS 9%

Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt compone…

Fix: after 4.1.8
Fix from $2,300 2021-05-24
Fusion CRITICAL 9.8
CVE-2020-28902EPSS 6%

Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.

Fix: after 4.1.8
Fix from $2,300 2021-05-24
Wap125 Firmware HIGH 7.2
CVE-2021-1547

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-22
Wap125 Firmware HIGH 7.2
CVE-2021-1548

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-22
Wap125 Firmware HIGH 7.2
CVE-2021-1549

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-22
Wap125 Firmware HIGH 7.2
CVE-2021-1550

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-22
Wap125 Firmware HIGH 7.2
CVE-2021-1551

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-22
Wap125 Firmware HIGH 7.2
CVE-2021-1552

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-22
Wap125 Firmware HIGH 7.2
CVE-2021-1553

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-22
Wap125 Firmware HIGH 7.2
CVE-2021-1554

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-22
Wap125 Firmware HIGH 7.2
CVE-2021-1555

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-22