Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Gerapy HIGH 8.8
CVE-2021-32849EPSS 8%

Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is f…

Fix: 0.9.9+
Fix from $1,950 2022-01-26
Emc Unity Operating Environment HIGH 7.2
CVE-2021-36295

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with pri…

Fix: after 8.1.21.266
Fix from $1,950 2022-01-25
Emc Unity Operating Environment HIGH 7.2
CVE-2021-36296

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with pri…

Fix: after 8.1.21.266
Fix from $1,950 2022-01-25
Debian Linux HIGH 7.8
CVE-2021-45845

The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted …

Patch available
Fix from $1,950 2022-01-25
Debian Linux HIGH 7.8
CVE-2021-45844

Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.

Patch available
Fix from $1,950 2022-01-25
Exiftool HIGH 7.8
CVE-2022-23935EPSS 8%

lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.

Fix: 12.38+
Fix from $1,950 2022-01-25
Emc Unity Operating Environment MEDIUM 6.7
CVE-2021-43589

Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerabil…

Fix: 5.1.2.0.5.007+
Fix from $1,600 2022-01-24
Quickbox HIGH 8.8
CVE-2021-44981

In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); function …

Fix: after 2.5.8
Fix from $1,950 2022-01-24
Agent HIGH 7.8
CVE-2021-31854

A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cle…

Fix: 5.7.5+
Fix from $1,950 2022-01-19
Filenet Content Manager HIGH 8.8
CVE-2021-38965

IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sendin…

Patch available
Fix from $1,950 2022-01-17
Files Antivirus HIGH 7.2
CVE-2021-33827

The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.

Fix: 1.0.0+
Fix from $1,950 2022-01-15
An Lianbao Wf Firmware 1 CRITICAL 9.8
CVE-2021-33962

China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device compon…

Mitigation only
Fix from $2,300 2022-01-14
My Cloud Os HIGH 8.8
CVE-2022-22991

A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecure…

Fix: 5.19.117+
Fix from $1,950 2022-01-13
Docker Commons HIGH 8.8
CVE-2022-20617

Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability ex…

Fix: after 1.17
Fix from $1,950 2022-01-12
Fedora HIGH 8.6
CVE-2022-21668

pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requiremen…

Fix: 2022.1.8+
Fix from $1,950 2022-01-10
Lens HIGH 7.8
CVE-2021-23154

In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed…

Fix: after 5.3.3
Fix from $1,950 2022-01-10
Addressing CRITICAL 9.9
CVE-2021-43779EPSS 9%

GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers fro…

Fix: 2.9.1+
Fix from $2,300 2022-01-05
Real Time Agent HIGH 7.8
CVE-2021-45912

An unauthenticated Named Pipe channel in Controlup Real-Time Agent (cuAgent.exe) before 8.5 potentially allows an attacker to run OS commands via the…

Fix: 8.5+
Fix from $1,950 2022-01-04
Pdf Editor HIGH 7.8
CVE-2021-45978

Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via xfa.host.gotoURL in the XFA API.

Fix: 11.1+
Fix from $1,950 2022-01-04
Pdf Editor HIGH 7.8
CVE-2021-45979

Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.

Fix: 11.1+
Fix from $1,950 2022-01-04
Tew 827dru Firmware HIGH 8.8
CVE-2021-20159

Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmware allows for command inject…

No fix yet
Fix from $1,950 2021-12-30
Tew 827dru Firmware HIGH 8.8
CVE-2021-20160

Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the device. The username parameter …

No fix yet
Fix from $1,950 2021-12-30
R6700 Firmware HIGH 8.8
CVE-2021-20173

Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system up…

No fix yet
Fix from $1,950 2021-12-30
Gs1900 8 Firmware HIGH 8.0
CVE-2021-35031

A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authen…

Fix: 2.70+
Fix from $1,950 2021-12-28
Gs1900 8 Firmware HIGH 7.8
CVE-2021-35032

A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS c…

Fix: 2.70+
Fix from $1,950 2021-12-28
Gerapy HIGH 8.8
CVE-2021-43857EPSS 55%

Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched…

Fix: 0.9.8+
Fix from $1,950 2021-12-27
D7800 Firmware HIGH 7.8
CVE-2021-45602

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.66, EX2700 before 1.0.1.68, WN300…

Fix: 1.0.0.90 / 1.0.1.66+
Fix from $1,950 2021-12-26
Virtualization HIGH 8.8
CVE-2021-3621

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This fl…

Patch available
Fix from $1,950 2021-12-23
Satellite HIGH 7.2
CVE-2021-3584

A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to …

Fix: 2.4.1 / 2.5.1+
Fix from $1,950 2021-12-23
Mypro CRITICAL 9.8
CVE-2021-43981

mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands thro…

Fix: after 8.20.0
Fix from $2,300 2021-12-23