Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2021-33965 China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the paramet… An Lianbao Wf 1 Firmware Mitigation only Fix from $1,9502022-01-18 HIGH 8.8 CVE-2021-33964 China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, a… An Lianbao Wf 1 Firmware Mitigation only Fix from $1,9502022-01-18 CRITICAL 9.8 CVE-2021-33963 China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the paramete… An Lianbao Wf 1 Firmware Mitigation only Fix from $2,3002022-01-15 HIGH 8.8 CVE-2022-22991 A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecure… My Cloud Os 5.19.117+ Fix from $1,9502022-01-13 HIGH 8.8 CVE-2021-42559 An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these c… Caldera after 2.8.1 Fix from $1,9502022-01-12 HIGH 8.6 CVE-2022-21668 pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requiremen… Fedora 2022.1.8+ Fix from $1,9502022-01-10 CRITICAL 9.8 CVE-2021-45456EPSS 89% Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch bet… Kylin Mitigation only Fix from $2,3002022-01-06 CRITICAL 9.8 CVE-2021-43711EPSS 38% The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The p… Ex200 Firmware No fix yet Fix from $2,3002022-01-04 MEDIUM 5.9 CVE-2021-38542 Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-mi… James 3.6.1+ Fix from $1,6002022-01-04 HIGH 8.0 CVE-2021-20167EPSS 8% Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the n… Rax43 Firmware Mitigation only Fix from $1,9502021-12-30 HIGH 7.5 CVE-2021-23727 This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task me… Celery 5.2.2+ Fix from $1,9502021-12-29 HIGH 8.8 CVE-2021-45626 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK20 before 2.6.1.36, RBR20 before 2.6.1.36, … Rbk20 Firmware 2.6.1.36 / 2.6.1.38+ Fix from $1,9502021-12-26 CRITICAL 9.8 CVE-2021-45627 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK852 before 3.2.17.12… Cbr750 Firmware 3.2.17.12 / 4.6.3.6+ Fix from $2,3002021-12-26 HIGH 8.8 CVE-2021-45628 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 3.2.18.2,… Cbr40 Firmware 2.5.0.24 / 3.2.17.12+ Fix from $1,9502021-12-26 HIGH 8.8 CVE-2021-45629 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12… Cbr750 Firmware 3.2.17.12 / 4.6.3.6+ Fix from $1,9502021-12-26 CRITICAL 9.8 CVE-2021-45630 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, … Cbr40 Firmware 2.5.0.24 / 3.2.17.12+ Fix from $2,3002021-12-26 HIGH 8.8 CVE-2021-45631 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, … Cbr40 Firmware 2.5.0.24 / 3.2.17.12+ Fix from $1,9502021-12-26 HIGH 8.8 CVE-2021-45632 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12… Cbr750 Firmware 3.2.17.12 / 4.6.3.6+ Fix from $1,9502021-12-26 HIGH 8.8 CVE-2021-45633 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBR750 before 3.2.17.12… Cbr750 Firmware 3.2.17.12 / 4.6.3.6+ Fix from $1,9502021-12-26 HIGH 8.8 CVE-2021-45634 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12… Cbr750 Firmware 3.2.17.12 / 4.6.3.6+ Fix from $1,9502021-12-26 HIGH 8.8 CVE-2021-45635 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12… Cbr750 Firmware 3.2.17.12 / 4.6.3.6+ Fix from $1,9502021-12-26 CRITICAL 9.8 CVE-2021-45612 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, … Cbr40 Firmware 1.0.0.58 / 1.0.0.74+ Fix from $2,3002021-12-26 CRITICAL 9.8 CVE-2021-45613 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, … Cbr40 Firmware 1.0.0.74 / 1.0.3.96+ Fix from $2,3002021-12-26 CRITICAL 9.8 CVE-2021-45614 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1.0.0.74, LAX20 before 1.1.6.28… D7000v2 Firmware 1.0.0.74 / 1.0.3.96+ Fix from $2,3002021-12-26 HIGH 8.8 CVE-2021-45615 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, … Cbr40 Firmware 1.0.2.154 / 1.4.2.84+ Fix from $1,9502021-12-26 CRITICAL 9.8 CVE-2021-45616 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 3.2.18.2, LAX20 before 1.1.6.28,… Cbr750 Firmware 1.0.6.116 / 1.0.11.126+ Fix from $2,3002021-12-26 CRITICAL 9.8 CVE-2021-45617 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, EAX20 before 1.0.0.48, … Cbr40 Firmware 1.0.0.48 / 1.0.0.72+ Fix from $2,3002021-12-26 CRITICAL 9.8 CVE-2021-45618 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.64, EX6200v2 before 1.0.1.8… D7800 Firmware 1.0.0.134 / 1.0.0.216+ Fix from $2,3002021-12-26 CRITICAL 9.8 CVE-2021-45619 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects EX6200v2 before 1.0.1.86, EX6250 before 1.0.0.… Ex6250 Firmware 1.0.0.134 / 1.0.0.216+ Fix from $2,3002021-12-26 CRITICAL 9.8 CVE-2021-45620 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, … Cbr40 Firmware 1.0.0.58 / 1.0.1.68+ Fix from $2,3002021-12-26