Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
MEDIUM 5.5 CVE-2021-26321 Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP. Epyc 7601 Firmware Mitigation only Fix from $1,6002021-11-16 HIGH 8.8 CVE-2021-43339EPSS 10% In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functiona… Network Location 2021-07-31+ Fix from $1,9502021-11-03 HIGH 7.2 CVE-2021-40345EPSS 23% An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injec… Nagios Xi No fix yet Fix from $1,9502021-10-26 HIGH 8.8 CVE-2021-42538 The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input. Wireless 1410 Gateway Firmware 4.7.94+ Fix from $1,9502021-10-22 CRITICAL 9.8 CVE-2021-41744 All versions of yongyou PLM are affected by a command injection issue. UFIDA PLM (Product Life Cycle Management) is a strategic management method. It… Ufida Product Lifecycle Management Mitigation only Fix from $2,3002021-10-22 HIGH 7.2 CVE-2021-34362 A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remo… Media Streaming Add On 430.1.8.12 / 500.0.0.3+ Fix from $1,9502021-10-22 HIGH 8.8 CVE-2021-41146 qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser re… Qutebrowser 2.4.0+ Fix from $1,9502021-10-21 CRITICAL 9.8 CVE-2021-42740 The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex desi… Shell Quote 1.7.3+ Fix from $2,3002021-10-21 HIGH 7.8 CVE-2021-31358 A command injection vulnerability in sftp command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to… Junos Os Evolved after 20.3 Fix from $1,9502021-10-19 HIGH 7.8 CVE-2021-31356 A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be a… Junos Os Evolved after 20.3 Fix from $1,9502021-10-19 HIGH 7.8 CVE-2021-31357 A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access… Junos Os Evolved after 20.3 Fix from $1,9502021-10-19 MEDIUM 6.3 CVE-2021-40994 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior… Clearpass Policy Manager 6.8.9 / 6.9.7+ Fix from $1,6002021-10-15 MEDIUM 6.3 CVE-2021-40995 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior… Clearpass Policy Manager 6.8.9 / 6.9.7+ Fix from $1,6002021-10-15 HIGH 7.2 CVE-2021-40998 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior… Clearpass Policy Manager 6.8.9 / 6.9.7+ Fix from $1,9502021-10-15 HIGH 7.2 CVE-2021-40987 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior… Clearpass Policy Manager 6.8.9 / 6.9.7+ Fix from $1,9502021-10-15 HIGH 7.2 CVE-2021-37739 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior… Clearpass Policy Manager 6.10.2+ Fix from $1,9502021-10-15 HIGH 7.2 CVE-2021-40986 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior… Clearpass Policy Manager 6.8.9 / 6.9.7+ Fix from $1,9502021-10-15 HIGH 7.2 CVE-2021-40999 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior… Clearpass Policy Manager 6.8.9 / 6.9.7+ Fix from $1,9502021-10-15 CRITICAL 9.8 CVE-2021-42094 An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages. Zammad 4.1.1+ Fix from $2,3002021-10-07 HIGH 8.8 CVE-2021-34748 A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform … Intersight Virtual Appliance after 1.0.9-292 Fix from $1,9502021-10-06 CRITICAL 9.8 CVE-2021-41116 Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependen… Composer 1.10.23 / 2.1.9+ Fix from $2,3002021-10-05 CRITICAL 9.8 CVE-2021-34352 A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers … Qvr 5.1.5+ Fix from $2,3002021-10-01 HIGH 7.2 CVE-2021-37106 There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certifica… Fusioncompute Mitigation only Fix from $1,9502021-09-28 CRITICAL 9.8 CVE-2021-38124 Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting versions 7.0.2 through 7.5. The vuln… Arcsight Enterprise Security Manager after 7.5 Fix from $2,3002021-09-28 CRITICAL 9.8 CVE-2021-34348 A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers … Qvr 5.1.5+ Fix from $2,3002021-09-27 HIGH 7.2 CVE-2021-34349 A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers … Qvr 5.1.5+ Fix from $1,9502021-09-27 CRITICAL 9.8 CVE-2021-34351 A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers … Qvr 5.1.5+ Fix from $2,3002021-09-27 MEDIUM 6.7 CVE-2021-34725 A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed w… Ios Xe Sd Wan after 17.2.1r Fix from $1,6002021-09-23 MEDIUM 6.7 CVE-2021-34726 A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with roo… Sd Wan 18.4.6 / 19.2.3+ Fix from $1,6002021-09-23 MEDIUM 6.7 CVE-2021-34729 A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrar… Ios Xe after 17.3.1a Fix from $1,6002021-09-23