Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Epyc 7601 Firmware MEDIUM 5.5
CVE-2021-26321

Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP.

Mitigation only
Fix from $1,600 2021-11-16
Network Location HIGH 8.8
CVE-2021-43339EPSS 10%

In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functiona…

Fix: 2021-07-31+
Fix from $1,950 2021-11-03
Nagios Xi HIGH 7.2
CVE-2021-40345EPSS 23%

An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injec…

No fix yet
Fix from $1,950 2021-10-26
Wireless 1410 Gateway Firmware HIGH 8.8
CVE-2021-42538

The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input.

Fix: 4.7.94+
Fix from $1,950 2021-10-22
Ufida Product Lifecycle Management CRITICAL 9.8
CVE-2021-41744

All versions of yongyou PLM are affected by a command injection issue. UFIDA PLM (Product Life Cycle Management) is a strategic management method. It…

Mitigation only
Fix from $2,300 2021-10-22
Media Streaming Add On HIGH 7.2
CVE-2021-34362

A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remo…

Fix: 430.1.8.12 / 500.0.0.3+
Fix from $1,950 2021-10-22
Qutebrowser HIGH 8.8
CVE-2021-41146

qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser re…

Fix: 2.4.0+
Fix from $1,950 2021-10-21
Shell Quote CRITICAL 9.8
CVE-2021-42740

The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex desi…

Fix: 1.7.3+
Fix from $2,300 2021-10-21
Junos Os Evolved HIGH 7.8
CVE-2021-31358

A command injection vulnerability in sftp command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to…

Fix: after 20.3
Fix from $1,950 2021-10-19
Junos Os Evolved HIGH 7.8
CVE-2021-31356

A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be a…

Fix: after 20.3
Fix from $1,950 2021-10-19
Junos Os Evolved HIGH 7.8
CVE-2021-31357

A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access…

Fix: after 20.3
Fix from $1,950 2021-10-19
Clearpass Policy Manager MEDIUM 6.3
CVE-2021-40994

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior…

Fix: 6.8.9 / 6.9.7+
Fix from $1,600 2021-10-15
Clearpass Policy Manager MEDIUM 6.3
CVE-2021-40995

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior…

Fix: 6.8.9 / 6.9.7+
Fix from $1,600 2021-10-15
Clearpass Policy Manager HIGH 7.2
CVE-2021-40998

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior…

Fix: 6.8.9 / 6.9.7+
Fix from $1,950 2021-10-15
Clearpass Policy Manager HIGH 7.2
CVE-2021-40987

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior…

Fix: 6.8.9 / 6.9.7+
Fix from $1,950 2021-10-15
Clearpass Policy Manager HIGH 7.2
CVE-2021-37739

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior…

Fix: 6.10.2+
Fix from $1,950 2021-10-15
Clearpass Policy Manager HIGH 7.2
CVE-2021-40986

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior…

Fix: 6.8.9 / 6.9.7+
Fix from $1,950 2021-10-15
Clearpass Policy Manager HIGH 7.2
CVE-2021-40999

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior…

Fix: 6.8.9 / 6.9.7+
Fix from $1,950 2021-10-15
Zammad CRITICAL 9.8
CVE-2021-42094

An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.

Fix: 4.1.1+
Fix from $2,300 2021-10-07
Intersight Virtual Appliance HIGH 8.8
CVE-2021-34748

A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform …

Fix: after 1.0.9-292
Fix from $1,950 2021-10-06
Composer CRITICAL 9.8
CVE-2021-41116

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependen…

Fix: 1.10.23 / 2.1.9+
Fix from $2,300 2021-10-05
Qvr CRITICAL 9.8
CVE-2021-34352

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers …

Fix: 5.1.5+
Fix from $2,300 2021-10-01
Fusioncompute HIGH 7.2
CVE-2021-37106

There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certifica…

Mitigation only
Fix from $1,950 2021-09-28
Arcsight Enterprise Security Manager CRITICAL 9.8
CVE-2021-38124

Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting versions 7.0.2 through 7.5. The vuln…

Fix: after 7.5
Fix from $2,300 2021-09-28
Qvr CRITICAL 9.8
CVE-2021-34348

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers …

Fix: 5.1.5+
Fix from $2,300 2021-09-27
Qvr HIGH 7.2
CVE-2021-34349

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers …

Fix: 5.1.5+
Fix from $1,950 2021-09-27
Qvr CRITICAL 9.8
CVE-2021-34351

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers …

Fix: 5.1.5+
Fix from $2,300 2021-09-27
Ios Xe Sd Wan MEDIUM 6.7
CVE-2021-34725

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed w…

Fix: after 17.2.1r
Fix from $1,600 2021-09-23
Sd Wan MEDIUM 6.7
CVE-2021-34726

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with roo…

Fix: 18.4.6 / 19.2.3+
Fix from $1,600 2021-09-23
Ios Xe MEDIUM 6.7
CVE-2021-34729

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrar…

Fix: after 17.3.1a
Fix from $1,600 2021-09-23