Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Dna Spaces\ HIGH 7.2
CVE-2021-1560

Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affe…

Fix: 2.0.519+
Fix from $1,950 2021-05-22
Pluck CRITICAL 9.8
CVE-2020-20951

In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.

No fix yet
Fix from $2,300 2021-05-18
Epyc 7232p HIGH 7.2
CVE-2020-12967

The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a ma…

Mitigation only
Fix from $1,950 2021-05-13
Epyc 7232p HIGH 7.2
CVE-2021-26311

In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be u…

Mitigation only
Fix from $1,950 2021-05-13
Malware Remover MEDIUM 6.7
CVE-2020-36198

A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote att…

Fix: 4.6.1.0+
Fix from $1,600 2021-05-13
Dav Cogs MEDIUM 6.5
CVE-2021-29501

Ticketer is a command based ticket system cog (plugin) for the red discord bot. A vulnerability allowing discord users to expose sensitive informatio…

Fix: 1.0.1+
Fix from $1,600 2021-05-10
Hyperflex Hx Data Platform CRITICAL 9.8
CVE-2021-1498 KEVEPSS 100%

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform comma…

Fix: 4.0 / 4.5+
Fix from $2,300 2021-05-06
Drupal HIGH 8.8
CVE-2020-13664

Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malic…

Fix: 8.8.8 / 8.9.1+
Fix from $1,950 2021-05-05
Secure Firewall Threat Defense MEDIUM 6.7
CVE-2021-1488

A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could al…

Fix: 6.6.4 / 6.7.0.2+
Fix from $1,600 2021-04-29
An Lianbao Wf 1 Firmware CRITICAL 9.8
CVE-2021-25812

Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/ZRQos/set_online_client.

Mitigation only
Fix from $2,300 2021-04-29
C315 Firmware CRITICAL 9.8
CVE-2021-31726

Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default roo…

Mitigation only
Fix from $2,300 2021-04-25
Session Border Controller For Enterprise HIGH 8.8
CVE-2020-7034

A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially c…

Fix: 8.1.2.0+
Fix from $1,950 2021-04-23
Junos HIGH 7.8
CVE-2021-0252

NFX Series devices using Juniper Networks Junos OS are susceptible to a local code execution vulnerability thereby allowing an attacker to elevate th…

No fix yet
Fix from $1,950 2021-04-22
Junos HIGH 7.8
CVE-2021-0253

NFX Series devices using Juniper Networks Junos OS are susceptible to a local command execution vulnerability thereby allowing an attacker to elevate…

No fix yet
Fix from $1,950 2021-04-22
Resilient HIGH 7.2
CVE-2021-20527

IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as another user. IBM X-Force ID: 198…

Fix: 38.2.41 / 39.0.6536+
Fix from $1,950 2021-04-19
Home Center 2 Firmware HIGH 8.8
CVE-2021-20991EPSS 5%

In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command in…

Fix: after 4.540
Fix from $1,950 2021-04-19
Qts CRITICAL 9.8
CVE-2020-2509 KEVEPSS 33%

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitra…

Fix: 4.2.6 / 4.3.6+
Fix from $2,300 2021-04-17
Openclinic Ga CRITICAL 9.8
CVE-2020-27227

An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be execute…

No fix yet
Fix from $2,300 2021-04-13
Linux Kernel HIGH 7.8
CVE-2021-29154

BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code wit…

Fix: 4.4.266 / 4.9.266+
Fix from $1,950 2021-04-08
Grp2612 Firmware HIGH 7.2
CVE-2020-25217

Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.

Mitigation only
Fix from $1,950 2021-03-29
Automatic Device Management HIGH 8.8
CVE-2020-10580

A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers …

Fix: after 5.0
Fix from $1,950 2021-03-25
Ios Xe HIGH 7.2
CVE-2021-1443

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges o…

Mitigation only
Fix from $1,950 2021-03-24
Ios Xe MEDIUM 6.7
CVE-2021-1382

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed w…

Fix: 17.3.3 / 17.5.1a+
Fix from $1,600 2021-03-24
Ios Xe HIGH 7.2
CVE-2021-1384EPSS 35%

A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remote attacker to inject command…

Fix: 16.6.9 / 16.9.7+
Fix from $1,950 2021-03-24
Enterprise Server HIGH 8.8
CVE-2021-22864

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-cont…

Fix: 2.21.17 / 2.22.9+
Fix from $1,950 2021-03-23
Rbw30 Firmware CRITICAL 9.6
CVE-2021-29077

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBW30 before 2.6.2.2, RBS40V before 2.6.2.4, R…

Fix: 2.6.2.2 / 2.6.2.4+
Fix from $2,300 2021-03-23
Rbk852 Firmware CRITICAL 9.6
CVE-2021-29078

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.…

Fix: 3.2.17.12+
Fix from $2,300 2021-03-23
Rbk852 Firmware CRITICAL 9.6
CVE-2021-29079

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.…

Fix: 3.2.17.12+
Fix from $2,300 2021-03-23
Xr450 Firmware HIGH 8.4
CVE-2021-29069

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR450 before 2.3.2.114, XR500 before 2.3.2.114, and …

Fix: 1.0.0.76 / 2.3.2.114+
Fix from $1,950 2021-03-23
Rbk852 Firmware HIGH 8.4
CVE-2021-29070

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RB…

Fix: 3.2.17.12+
Fix from $1,950 2021-03-23