Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Rbk752 Firmware MEDIUM 6.8
CVE-2021-45561

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS7…

Fix: 3.2.16.6+
Fix from $1,600 2021-12-26
Rbk752 Firmware MEDIUM 6.8
CVE-2021-45562

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS7…

Fix: 3.2.16.6+
Fix from $1,600 2021-12-26
Rbk752 Firmware MEDIUM 6.8
CVE-2021-45563

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS7…

Fix: 3.2.16.6+
Fix from $1,600 2021-12-26
D6220 Firmware HIGH 8.8
CVE-2021-45531

NETGEAR D6220 devices before 1.0.0.76 are affected by command injection by an authenticated user.

Fix: 1.0.0.76+
Fix from $1,950 2021-12-26
R8000 Firmware HIGH 7.8
CVE-2021-45532

NETGEAR R8000 devices before 1.0.4.76 are affected by command injection by an authenticated user.

Fix: 1.0.4.76+
Fix from $1,950 2021-12-26
Ex6120 Firmware MEDIUM 6.8
CVE-2021-45533

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects EX6120 before 1.0.0.66, EX6130 before 1.0.0.46, EX70…

Fix: 1.0.0.46 / 1.0.0.66+
Fix from $1,600 2021-12-26
Ac2100 Firmware HIGH 7.8
CVE-2021-45534

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects AC2100 before 1.2.0.88, AC2400 before 1.2.0.88, AC26…

Fix: 1.0.1.82 / 1.1.0.84+
Fix from $1,950 2021-12-26
Rax200 Firmware MEDIUM 6.8
CVE-2021-45535

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.3.106, RAX80 before 1.0.3.106, RAX…

Fix: 1.0.3.106 / 3.2.16.6+
Fix from $1,600 2021-12-26
Rax75 Firmware MEDIUM 6.8
CVE-2021-45536

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX75 before 1.0.3.106, RAX80 before 1.0.3.106, RBK7…

Fix: 1.0.3.106 / 3.2.16.6+
Fix from $1,600 2021-12-26
Rax200 Firmware MEDIUM 6.8
CVE-2021-45537

Certain NETGEAR devices are affected by command injection by an authenticated user . This affects RAX200 before 1.0.3.106, RAX75 before 1.0.3.106, RA…

Fix: 1.0.3.106 / 3.2.16.6+
Fix from $1,600 2021-12-26
Rax75 Firmware MEDIUM 6.8
CVE-2021-45538

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX75 before 1.0.3.106, RAX80 before 1.0.3.106, RBK7…

Fix: 1.0.3.106 / 3.2.16.6+
Fix from $1,600 2021-12-26
R7900p Firmware MEDIUM 6.8
CVE-2021-45539

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84, R7960P before 1.4.2.84, R800…

Fix: 1.0.2.28 / 1.0.2.82+
Fix from $1,600 2021-12-26
R7900p Firmware HIGH 8.4
CVE-2021-45540

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7000 before 1.0.11.126, R7900 before 1.0.4.46, R790…

Fix: 1.0.2.66 / 1.0.3.106+
Fix from $1,950 2021-12-26
Rax200 Firmware HIGH 8.8
CVE-2021-45541

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900 before 1.0.4.38, R7900P before 1.4.2.84, R8000…

Fix: 1.0.2.72 / 1.0.3.106+
Fix from $1,950 2021-12-26
Rax200 Firmware MEDIUM 6.8
CVE-2021-45542

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120, RAX75 before 1.0.4.120, RAX…

Fix: 1.0.4.120 / 3.2.17.12+
Fix from $1,600 2021-12-26
Xr1000 Firmware CRITICAL 9.6
CVE-2021-45513

NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.

Fix: 1.0.0.58+
Fix from $2,300 2021-12-26
Xr1000 Firmware HIGH 8.8
CVE-2021-45514

NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.

Fix: 1.0.0.58+
Fix from $1,950 2021-12-26
Virtualization HIGH 8.8
CVE-2021-3621

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This fl…

Patch available
Fix from $1,950 2021-12-23
Node Windows CRITICAL 9.8
CVE-2021-45459

lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.

Fix: after 0.1.14
Fix from $2,300 2021-12-22
Amegaview CRITICAL 9.8
CVE-2021-27447

Mesa Labs AmegaView version 3.0 is vulnerable to a command injection, which may allow an attacker to remotely execute arbitrary code.

Fix: after 3.0
Fix from $2,300 2021-12-21
Amegaview HIGH 8.8
CVE-2021-27449

Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute commands in the web server.

Fix: after 3.0
Fix from $1,950 2021-12-21
Debian Linux CRITICAL 9.8
CVE-2021-43113EPSS 5%

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghost…

Fix: 7.1.17+
Fix from $2,300 2021-12-15
Transport Dr64 Firmware CRITICAL 9.8
CVE-2021-35978

An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges.…

Fix: after 8.3.1.2
Fix from $2,300 2021-12-10
Avalanche HIGH 8.8
CVE-2021-42129EPSS 77%

A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary…

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Avalanche HIGH 8.8
CVE-2021-42132EPSS 70%

A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary…

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Wr N300u Firmware HIGH 8.8
CVE-2021-43469

VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.

No fix yet
Fix from $1,950 2021-12-06
Manageengine Network Configuration Manager CRITICAL 9.8
CVE-2021-43319EPSS 21%

Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.

Mitigation only
Fix from $2,300 2021-11-30
Fusioncompute HIGH 8.8
CVE-2021-37102

There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software …

Mitigation only
Fix from $1,950 2021-11-23
Apisix HIGH 7.5
CVE-2021-43557EPSS 15%

The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without…

Fix: 2.10.2+
Fix from $1,950 2021-11-22
Wazuh CRITICAL 9.8
CVE-2021-44079

In the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl command line, potentially resulting…

Fix: 4.2.5+
Fix from $2,300 2021-11-22