Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Bosch Video Management System HIGH 7.2
CVE-2021-23862

A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue a…

Fix: 10.0.2+
Fix from $1,950 2021-12-08
Fortiweb HIGH 8.8
CVE-2021-36195

Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2…

Fix: after 6.3.15
Fix from $1,950 2021-12-08
Fortiweb HIGH 8.8
CVE-2021-36180

Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3…

Fix: after 6.3.15
Fix from $1,950 2021-12-08
Sma 200 Firmware HIGH 8.8
CVE-2021-20044EPSS 40%

A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands…

Mitigation only
Fix from $1,950 2021-12-08
Sma 200 Firmware HIGH 8.8
CVE-2021-20039EPSS 78%

Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated att…

No fix yet
Fix from $1,950 2021-12-08
Git It CRITICAL 9.8
CVE-2021-44685

Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verification process, it attempts t…

Fix: after 4.4.0
Fix from $2,300 2021-12-07
Github Todos CRITICAL 9.8
CVE-2021-44684

naholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenated without any validation, an…

Fix: after 3.1.0
Fix from $2,300 2021-12-07
Unitrends Backup CRITICAL 9.8
CVE-2021-43033EPSS 6%

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary r…

Fix: 10.5.5+
Fix from $2,300 2021-12-06
Wrc 1167gst2 Firmware HIGH 8.0
CVE-2021-20859

ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS…

Fix: after 2.11
Fix from $1,950 2021-12-01
Wrc 1167gst2 Firmware HIGH 8.0
CVE-2021-20863

OS command injection vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H fi…

Fix: after 2.11
Fix from $1,950 2021-12-01
Wrh 733gbk Firmware MEDIUM 6.8
CVE-2021-20853

ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an admin…

Fix: after 1.02.9
Fix from $1,600 2021-12-01
Wrh 733gbk Firmware MEDIUM 6.8
CVE-2021-20854

ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an admin…

Fix: after 1.02.9
Fix from $1,600 2021-12-01
Wr1200 Firmware HIGH 8.8
CVE-2021-43283

An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the web interface of the device, …

Fix: after 1.0.3
Fix from $1,950 2021-11-30
C200 Firmware CRITICAL 9.8
CVE-2020-7879

This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera …

Fix: after 1.0.16
Fix from $2,300 2021-11-30
Oh My Zsh CRITICAL 9.8
CVE-2021-3769

# Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to …

Fix: 2021-11-11+
Fix from $2,300 2021-11-30
Oh My Zsh HIGH 8.8
CVE-2021-3725

Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt…

Fix: 11-11-2021+
Fix from $1,950 2021-11-30
Oh My Zsh CRITICAL 9.8
CVE-2021-3726

# Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` to set the terminal title to …

Fix: 2021-11-11+
Fix from $2,300 2021-11-30
Oh My Zsh CRITICAL 9.8
CVE-2021-3727

# Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hito…

Fix: 72928432+
Fix from $2,300 2021-11-30
Basercms HIGH 8.8
CVE-2021-41243

There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to up…

Fix: 4.5.4+
Fix from $1,950 2021-11-26
Qvr CRITICAL 9.8
CVE-2021-38685

A command injection vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability allows remote attackers to run a…

Fix: 5.1.6+
Fix from $2,300 2021-11-26
Powercms CRITICAL 9.8
CVE-2021-20850

PowerCMS XMLRPC API of PowerCMS 5.19 and earlier, PowerCMS 4.49 and earlier, PowerCMS 3.295 and earlier, and PowerCMS 2 Series (End-of-Life, EOL) all…

Fix: after 5.19
Fix from $2,300 2021-11-24
Dwr 932c E1 Firmware CRITICAL 9.8
CVE-2021-42784EPSS 7%

OS Command Injection vulnerability in debug_fcgi of D-Link DWR-932C E1 firmware allows a remote attacker to perform command injection via a crafted H…

Fix: after 1.0.0.4
Fix from $2,300 2021-11-23
Cloudlink HIGH 7.2
CVE-2021-36313

Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged attacker, may potentially explo…

Fix: 7.1.1+
Fix from $1,950 2021-11-23
Docker Cli Js CRITICAL 9.0
CVE-2021-23732

This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least be partially controlled by a u…

No fix yet
Fix from $2,300 2021-11-22
Sharetribe CRITICAL 9.8
CVE-2021-41280

Sharetribe Go is a source available marketplace software. In affected versions operating system command injection is possible on installations of Sha…

Fix: 10.2.1+
Fix from $2,300 2021-11-19
System X3550 M3 Firmware HIGH 8.8
CVE-2021-3723

A command injection vulnerability was reported in the Integrated Management Module (IMM) of legacy IBM System x 3550 M3 and IBM System x 3650 M3 serv…

Mitigation only
Fix from $1,950 2021-11-12
Halo\+ Camera Firmware HIGH 8.8
CVE-2021-3577EPSS 60%

An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on …

Fix: 03.40.00 / 03.40.02+
Fix from $1,950 2021-11-12
Kustomize Controller HIGH 8.8
CVE-2021-41254

kustomize-controller is a Kubernetes operator, specialized in running continuous delivery pipelines for infrastructure and workloads defined with Kub…

Fix: 0.15.0+
Fix from $1,950 2021-11-12
Oh My Zsh HIGH 7.5
CVE-2021-3934

ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command

Fix: 2021-11-11+
Fix from $1,950 2021-11-12
Pan Os HIGH 8.1
CVE-2021-3059

An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerabilit…

Fix: 10.0.8 / 10.1.3+
Fix from $1,950 2021-11-10