Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Dir 820l Firmware CRITICAL 9.8
CVE-2021-45382 KEVEPSS 98%

A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L rout…

Mitigation only
Fix from $2,300 2022-02-17
Dir 846 Firmware CRITICAL 9.8
CVE-2021-46314EPSS 33%

A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bi…

No fix yet
Fix from $2,300 2022-02-17
Fedora CRITICAL 9.9
CVE-2021-3781EPSS 84%

A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe comm…

Patch available
Fix from $2,300 2022-02-16
Cloud Foundation HIGH 7.8
CVE-2022-22945

VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary comman…

Fix: 6.4.13+
Fix from $1,950 2022-02-16
Dna HIGH 8.8
CVE-2021-26726

A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM p…

Fix: after 2021
Fix from $1,950 2022-02-16
Pipeline\ HIGH 8.8
CVE-2022-25173

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typ…

Fix: after 2648.va9433432b33c
Fix from $1,950 2022-02-15
Pipeline\ HIGH 8.8
CVE-2022-25174

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libr…

Fix: after 552.vd9cc05b8a2e1
Fix from $1,950 2022-02-15
Pipeline\ HIGH 8.8
CVE-2022-25175

Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, all…

Fix: after 706.vd43c65dec013
Fix from $1,950 2022-02-15
Publiccms CRITICAL 9.8
CVE-2022-23389EPSS 22%

PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.

No fix yet
Fix from $2,300 2022-02-14
Microweber HIGH 7.2
CVE-2022-0557EPSS 51%

OS Command Injection in Packagist microweber/microweber prior to 1.2.11.

Fix: 1.2.11+
Fix from $1,950 2022-02-11
Rv340 Firmware HIGH 8.0
CVE-2022-20708 KEVEPSS 15%

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex…

Fix: after 1.0.03.24
Fix from $1,950 2022-02-10
Secuwayssl U CRITICAL 9.8
CVE-2021-26616

An OS command injection was found in SecuwaySSL, when special characters injection on execute command with runCommand arguments.

Fix: after 2.0.0.8
Fix from $2,300 2022-02-09
Mail Station HIGH 8.8
CVE-2021-43928

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mail sending and receiving component in S…

Fix: 20211105+
Fix from $1,950 2022-02-07
Nas CRITICAL 9.8
CVE-2022-24552

A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go d…

Fix: 0.2+
Fix from $2,300 2022-02-06
Itunesrpc Remastered CRITICAL 9.8
CVE-2022-23611

iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize im…

Patch available
Fix from $2,300 2022-02-04
S9922l Firmware CRITICAL 9.8
CVE-2022-0365

The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and execute arbitrary shell comman…

Mitigation only
Fix from $2,300 2022-02-04
Northstar Club Management CRITICAL 9.8
CVE-2021-29393

Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated use…

Mitigation only
Fix from $2,300 2022-02-04
G1 Firmware CRITICAL 9.8
CVE-2021-45986

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This v…

Mitigation only
Fix from $2,300 2022-02-04
G1 Firmware CRITICAL 9.8
CVE-2021-45987

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This …

Mitigation only
Fix from $2,300 2022-02-04
Fortiweb HIGH 8.8
CVE-2021-41018

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and…

Fix: 6.2.7 / 6.3.16+
Fix from $1,950 2022-02-02
Fortiextender Firmware HIGH 8.8
CVE-2021-41016

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and be…

Fix: 4.1.8 / 4.2.4+
Fix from $1,950 2022-02-02
Fortiweb HIGH 8.8
CVE-2021-43073

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.…

Fix: 6.2.7 / 6.3.17+
Fix from $1,950 2022-02-02
Rlc 410w Firmware HIGH 7.2
CVE-2021-40407 KEVEPSS 48%

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], bas…

Mitigation only
Fix from $1,950 2022-01-28
Rlc 410w Firmware CRITICAL 9.8
CVE-2021-40408

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], bas…

No fix yet
Fix from $2,300 2022-01-28
Rlc 410w Firmware CRITICAL 9.8
CVE-2021-40409

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], bas…

No fix yet
Fix from $2,300 2022-01-28
Rlc 410w Firmware HIGH 7.2
CVE-2021-40410EPSS 28%

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [4] the dns_dat…

No fix yet
Fix from $1,950 2022-01-28
Rlc 410w Firmware HIGH 7.2
CVE-2021-40411

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [6] the dns_dat…

No fix yet
Fix from $1,950 2022-01-28
Rlc 410w Firmware HIGH 7.2
CVE-2021-40412EPSS 27%

An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [8] the devname …

No fix yet
Fix from $1,950 2022-01-28
Liferay Portal HIGH 7.2
CVE-2020-28884

Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute a…

Mitigation only
Fix from $1,950 2022-01-28
Liferay Portal HIGH 7.2
CVE-2020-28885

Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo …

Mitigation only
Fix from $1,950 2022-01-28