Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2021-36707 In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff contains a… Prc2402m Firmware after 1.0.18 Fix from $2,3002021-08-06 HIGH 8.8 CVE-2021-21406 Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the S… Itop 2.7.4+ Fix from $1,9502021-07-21 MEDIUM 6.5 CVE-2021-22867 A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled … Enterprise Server 2.22.17 / 3.0.11+ Fix from $1,6002021-07-14 CRITICAL 9.8 CVE-2021-32529 Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary commands. Suggest contacting with QS… Sanos 1.2.0+ Fix from $2,3002021-07-07 HIGH 8.8 CVE-2020-17759 An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution… Evernote Mitigation only Fix from $1,9502021-06-24 HIGH 8.8 CVE-2020-21785 In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability. Ibos No fix yet Fix from $1,9502021-06-24 HIGH 8.8 CVE-2021-34809 Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download S… Download Station 3.8.16-3566+ Fix from $1,9502021-06-18 HIGH 7.2 CVE-2021-28811 If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. Roon Labs has already fixed this vulnerabi… Roon Server 2021-05-18+ Fix from $1,9502021-06-08 CRITICAL 9.8 CVE-2021-20699 Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN… Un462a Firmware Mitigation only Fix from $2,3002021-06-07 HIGH 7.3 CVE-2021-32661 Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.… \@backstage\/plugin Techdocs 0.9.5+ Fix from $1,9502021-06-03 HIGH 8.1 CVE-2021-32660 Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versio… \@backstage\/techdocs Common 0.6.4+ Fix from $1,9502021-06-03 HIGH 8.8 CVE-2021-28812 A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attac… Video Station 5.5.4+ Fix from $1,9502021-06-03 HIGH 8.8 CVE-2015-1877 The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which all… Debian Linux Patch available Fix from $1,9502021-06-02 MEDIUM 6.7 CVE-2021-3515 A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server… Pglogical 2.3.4 / 3.6.26+ Fix from $1,6002021-06-01 CRITICAL 9.8 CVE-2020-10666 The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a URL vari… Restapps after 15.0.19.2 Fix from $2,3002021-05-31 CRITICAL 9.0 CVE-2020-15180EPSS 6% A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be e… MariaDB 5.6.49 / 5.6.49-28.42.2+ Fix from $2,3002021-05-27 HIGH 8.8 CVE-2021-22899 KEVEPSS 23% A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execut… Connect Secure Mitigation only Fix from $1,9502021-05-27 CRITICAL 9.8 CVE-2019-25029 In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnera… Versa Director Mitigation only Fix from $2,3002021-05-26 CRITICAL 9.8 CVE-2020-28908EPSS 6% Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios. Fusion after 4.1.8 Fix from $2,3002021-05-24 CRITICAL 9.8 CVE-2020-28901EPSS 9% Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt compone… Fusion after 4.1.8 Fix from $2,3002021-05-24 CRITICAL 9.8 CVE-2020-28902EPSS 6% Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php. Fusion after 4.1.8 Fix from $2,3002021-05-24 HIGH 7.2 CVE-2021-1547 Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could … Wap125 Firmware after 1.1.2.4 Fix from $1,9502021-05-22 HIGH 7.2 CVE-2021-1548 Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could … Wap125 Firmware after 1.1.2.4 Fix from $1,9502021-05-22 HIGH 7.2 CVE-2021-1549 Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could … Wap125 Firmware after 1.1.2.4 Fix from $1,9502021-05-22 HIGH 7.2 CVE-2021-1550 Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could … Wap125 Firmware after 1.1.2.4 Fix from $1,9502021-05-22 HIGH 7.2 CVE-2021-1551 Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could … Wap125 Firmware after 1.1.2.4 Fix from $1,9502021-05-22 HIGH 7.2 CVE-2021-1552 Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could … Wap125 Firmware after 1.1.2.4 Fix from $1,9502021-05-22 HIGH 7.2 CVE-2021-1553 Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could … Wap125 Firmware after 1.1.2.4 Fix from $1,9502021-05-22 HIGH 7.2 CVE-2021-1554 Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could … Wap125 Firmware after 1.1.2.4 Fix from $1,9502021-05-22 HIGH 7.2 CVE-2021-1555 Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could … Wap125 Firmware after 1.1.2.4 Fix from $1,9502021-05-22