Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
An Lianbao Wf 1 Firmware HIGH 8.8
CVE-2021-33965

China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the paramet…

Mitigation only
Fix from $1,950 2022-01-18
An Lianbao Wf 1 Firmware HIGH 8.8
CVE-2021-33964

China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, a…

Mitigation only
Fix from $1,950 2022-01-18
An Lianbao Wf 1 Firmware CRITICAL 9.8
CVE-2021-33963

China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the paramete…

Mitigation only
Fix from $2,300 2022-01-15
My Cloud Os HIGH 8.8
CVE-2022-22991

A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecure…

Fix: 5.19.117+
Fix from $1,950 2022-01-13
Caldera HIGH 8.8
CVE-2021-42559

An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these c…

Fix: after 2.8.1
Fix from $1,950 2022-01-12
Fedora HIGH 8.6
CVE-2022-21668

pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requiremen…

Fix: 2022.1.8+
Fix from $1,950 2022-01-10
Kylin CRITICAL 9.8
CVE-2021-45456EPSS 89%

Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch bet…

Mitigation only
Fix from $2,300 2022-01-06
Ex200 Firmware CRITICAL 9.8
CVE-2021-43711EPSS 38%

The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The p…

No fix yet
Fix from $2,300 2022-01-04
James MEDIUM 5.9
CVE-2021-38542

Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-mi…

Fix: 3.6.1+
Fix from $1,600 2022-01-04
Rax43 Firmware HIGH 8.0
CVE-2021-20167EPSS 8%

Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the n…

Mitigation only
Fix from $1,950 2021-12-30
Celery HIGH 7.5
CVE-2021-23727

This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task me…

Fix: 5.2.2+
Fix from $1,950 2021-12-29
Rbk20 Firmware HIGH 8.8
CVE-2021-45626

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK20 before 2.6.1.36, RBR20 before 2.6.1.36, …

Fix: 2.6.1.36 / 2.6.1.38+
Fix from $1,950 2021-12-26
Cbr750 Firmware CRITICAL 9.8
CVE-2021-45627

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK852 before 3.2.17.12…

Fix: 3.2.17.12 / 4.6.3.6+
Fix from $2,300 2021-12-26
Cbr40 Firmware HIGH 8.8
CVE-2021-45628

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 3.2.18.2,…

Fix: 2.5.0.24 / 3.2.17.12+
Fix from $1,950 2021-12-26
Cbr750 Firmware HIGH 8.8
CVE-2021-45629

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12…

Fix: 3.2.17.12 / 4.6.3.6+
Fix from $1,950 2021-12-26
Cbr40 Firmware CRITICAL 9.8
CVE-2021-45630

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, …

Fix: 2.5.0.24 / 3.2.17.12+
Fix from $2,300 2021-12-26
Cbr40 Firmware HIGH 8.8
CVE-2021-45631

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, …

Fix: 2.5.0.24 / 3.2.17.12+
Fix from $1,950 2021-12-26
Cbr750 Firmware HIGH 8.8
CVE-2021-45632

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12…

Fix: 3.2.17.12 / 4.6.3.6+
Fix from $1,950 2021-12-26
Cbr750 Firmware HIGH 8.8
CVE-2021-45633

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBR750 before 3.2.17.12…

Fix: 3.2.17.12 / 4.6.3.6+
Fix from $1,950 2021-12-26
Cbr750 Firmware HIGH 8.8
CVE-2021-45634

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12…

Fix: 3.2.17.12 / 4.6.3.6+
Fix from $1,950 2021-12-26
Cbr750 Firmware HIGH 8.8
CVE-2021-45635

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12…

Fix: 3.2.17.12 / 4.6.3.6+
Fix from $1,950 2021-12-26
Cbr40 Firmware CRITICAL 9.8
CVE-2021-45612

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, …

Fix: 1.0.0.58 / 1.0.0.74+
Fix from $2,300 2021-12-26
Cbr40 Firmware CRITICAL 9.8
CVE-2021-45613

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, …

Fix: 1.0.0.74 / 1.0.3.96+
Fix from $2,300 2021-12-26
D7000v2 Firmware CRITICAL 9.8
CVE-2021-45614

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1.0.0.74, LAX20 before 1.1.6.28…

Fix: 1.0.0.74 / 1.0.3.96+
Fix from $2,300 2021-12-26
Cbr40 Firmware HIGH 8.8
CVE-2021-45615

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, …

Fix: 1.0.2.154 / 1.4.2.84+
Fix from $1,950 2021-12-26
Cbr750 Firmware CRITICAL 9.8
CVE-2021-45616

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 3.2.18.2, LAX20 before 1.1.6.28,…

Fix: 1.0.6.116 / 1.0.11.126+
Fix from $2,300 2021-12-26
Cbr40 Firmware CRITICAL 9.8
CVE-2021-45617

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, EAX20 before 1.0.0.48, …

Fix: 1.0.0.48 / 1.0.0.72+
Fix from $2,300 2021-12-26
D7800 Firmware CRITICAL 9.8
CVE-2021-45618

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.64, EX6200v2 before 1.0.1.8…

Fix: 1.0.0.134 / 1.0.0.216+
Fix from $2,300 2021-12-26
Ex6250 Firmware CRITICAL 9.8
CVE-2021-45619

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects EX6200v2 before 1.0.1.86, EX6250 before 1.0.0.…

Fix: 1.0.0.134 / 1.0.0.216+
Fix from $2,300 2021-12-26
Cbr40 Firmware CRITICAL 9.8
CVE-2021-45620

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, …

Fix: 1.0.0.58 / 1.0.1.68+
Fix from $2,300 2021-12-26