Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Mypro CRITICAL 9.8
CVE-2021-43984

mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating s…

Fix: after 8.20.0
Fix from $2,300 2021-12-23
Mypro CRITICAL 9.8
CVE-2021-44453

mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitr…

Fix: after 8.20.0
Fix from $2,300 2021-12-23
Mypro CRITICAL 9.8
CVE-2021-23198

mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating…

Fix: after 8.20.0
Fix from $2,300 2021-12-23
Mypro CRITICAL 9.8
CVE-2021-22657

mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary opera…

Fix: after 8.20.0
Fix from $2,300 2021-12-23
Tl Wr802n Firmware HIGH 8.8
CVE-2021-4144

TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.

Fix: 211202+
Fix from $1,950 2021-12-23
Premierwave 2050 Firmware CRITICAL 9.9
CVE-2021-21881EPSS 36%

An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A spe…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware HIGH 8.8
CVE-2021-21882EPSS 6%

An OS command injection vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted …

No fix yet
Fix from $1,950 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.9
CVE-2021-21883EPSS 6%

An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21884EPSS 5%

An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-cra…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21888

An OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.9
CVE-2021-21872EPSS 6%

An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A spec…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21873

A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can make an authenticated HTTP reque…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21874

A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can make an authenticated HTTP reque…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21875

A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter. An attacker can make an authenticated HTTP reques…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21876

Specially-crafted HTTP requests can lead to arbitrary command execution in PUT requests. An attacker can make authenticated HTTP requests to trigger …

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21877

Specially-crafted HTTP requests can lead to arbitrary command execution in “GET” requests. An attacker can make authenticated HTTP requests to trigge…

No fix yet
Fix from $2,300 2021-12-22
Framework HIGH 8.8
CVE-2020-19316

OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.

Fix: 5.8.17+
Fix from $1,950 2021-12-20
Iota All In One Security Kit Firmware HIGH 7.8
CVE-2020-8105

OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gai…

Fix: 1.0.2.23_6.9v_dev_t2_homekit_rf_2.0.19_s2_kvsabode_oz+
Fix from $1,950 2021-12-20
An5506 01 A Firmware HIGH 8.8
CVE-2021-42912EPSS 10%

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, t…

Mitigation only
Fix from $1,950 2021-12-16
Netweaver Application Server Abap MEDIUM 6.7
CVE-2021-44235

Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow a…

Mitigation only
Fix from $1,600 2021-12-14
Spectrum Copy Data Management CRITICAL 9.8
CVE-2021-39065

IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper va…

Fix: after 2.2.13
Fix from $2,300 2021-12-13
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20143

An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service on Gryphon Tower routers…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20144

An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Eufy Homebase 2 Firmware CRITICAL 9.9
CVE-2021-21954

A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h.…

No fix yet
Fix from $2,300 2021-12-09
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20138

An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interface at /cgi-bin/luci/rc. An …

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20139

An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server service on Gryphon Tower routers.…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20140

An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20141

An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon Tower routers…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20142

An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon Tower routers…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Meru Firmware MEDIUM 6.7
CVE-2021-42759

A violation of secure design principles in Fortinet Meru AP version 8.6.1 and below, version 8.5.5 and below allows attacker to execute unauthorized …

Fix: 8.6.2+
Fix from $1,600 2021-12-09