Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2019-6288 Edgecore ECS2020 Firmware 1.0.0.0 devices allow Unauthenticated Command Injection via the command1 HTTP header to the /EXCU_SHELL URI. Ecs2020 Firmware No fix yet Fix from $2,3002021-09-22 CRITICAL 9.8 CVE-2021-28960 Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-d… Desktop Central 10.0.683+ Fix from $2,3002021-09-21 HIGH 7.2 CVE-2021-41383 setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters in the ntp_server field. R6020 Firmware No fix yet Fix from $1,9502021-09-17 CRITICAL 9.8 CVE-2020-14119 There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi ro… Ax3600 1.1.12+ Fix from $2,3002021-09-16 HIGH 7.2 CVE-2020-14109 There is command injection in the meshd program in the routing system, resulting in command execution under administrator authority on Xiaomi router … Ax3600 Firmware after 1.1.12 Fix from $1,9502021-09-16 HIGH 8.8 CVE-2020-19151EPSS 5% Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via … Jfinal Cms after 4.7.1 Fix from $1,9502021-09-15 CRITICAL 9.8 CVE-2020-26300 systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is … Systeminformation 4.26.2+ Fix from $2,3002021-09-09 HIGH 7.2 CVE-2021-37145 A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attacker to Privi… Cx5500 Firmware Mitigation only Fix from $1,9502021-09-07 HIGH 7.2 CVE-2021-37717 A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): … Sd Wan 2.2.0.6 / 8.3.0.16+ Fix from $1,9502021-09-07 HIGH 7.2 CVE-2021-37718 A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): … Sd Wan 2.2.0.6 / 8.3.0.16+ Fix from $1,9502021-09-07 HIGH 7.2 CVE-2021-37719 A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): … Sd Wan 2.2.0.4 / 6.4.4.25+ Fix from $1,9502021-09-07 HIGH 7.2 CVE-2021-37720 A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): … Sd Wan 2.2.0.4 / 6.4.4.25+ Fix from $1,9502021-09-07 HIGH 7.2 CVE-2021-37721 A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): … Sd Wan 2.2.0.4 / 6.4.4.25+ Fix from $1,9502021-09-07 HIGH 7.2 CVE-2021-37722 A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): … Sd Wan 2.2.0.4 / 6.4.4.25+ Fix from $1,9502021-09-07 HIGH 7.2 CVE-2021-37723 A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12,… Arubaos 8.3.0.16 / 8.5.0.12+ Fix from $1,9502021-09-07 HIGH 7.2 CVE-2021-37724 A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12,… Arubaos 8.3.0.16 / 8.5.0.12+ Fix from $1,9502021-09-07 CRITICAL 9.8 CVE-2020-18048 An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered into the DB Name field. Craigms No fix yet Fix from $2,3002021-09-02 CRITICAL 9.8 CVE-2019-10095EPSS 6% bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affe… Zeppelin after 0.9.0 Fix from $2,3002021-09-02 HIGH 7.2 CVE-2021-36024 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special E… Adobe Commerce after 2.4.2 Fix from $1,9502021-09-01 HIGH 7.2 CVE-2021-35220 Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Settings page. Orion Platform 2020.2.6+ Fix from $1,9502021-08-31 CRITICAL 9.8 CVE-2020-19001 Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob… Simiki No fix yet Fix from $2,3002021-08-27 HIGH 7.2 CVE-2021-1580 Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow… Application Policy Infrastructure Controller 3.2 / 4.2+ Fix from $1,9502021-08-25 CRITICAL 9.8 CVE-2021-39510EPSS 9% An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /gofor… Dir 816 Firmware No fix yet Fix from $2,3002021-08-24 CRITICAL 9.8 CVE-2021-39509EPSS 5% An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/f… Dir 816 Firmware No fix yet Fix from $2,3002021-08-24 HIGH 8.8 CVE-2021-38556EPSS 13% includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection. Raspap No fix yet Fix from $1,9502021-08-24 CRITICAL 9.8 CVE-2021-38611 A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to execute arbitrary com… Remkon Device Manager No fix yet Fix from $2,3002021-08-24 HIGH 7.2 CVE-2020-18885 Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.… Phpmywind No fix yet Fix from $1,9502021-08-20 HIGH 8.1 CVE-2020-29548 An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS comma… Smartermail after 100.0.7537 Fix from $1,9502021-08-17 HIGH 7.0 CVE-2021-32830 The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability. Clients of th… Diez No fix yet Fix from $1,9502021-08-17 MEDIUM 5.9 CVE-2020-15955 In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmai… S\/qmail after 4.0.07 Fix from $1,6002021-08-17