Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Prisma Access HIGH 8.1
CVE-2021-3060EPSS 34%

An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated netwo…

Fix: 10.0.8 / 10.1.3+
Fix from $1,950 2021-11-10
Prisma Access HIGH 7.2
CVE-2021-3061

An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with acces…

Fix: 10.0.8 / 10.1.3+
Fix from $1,950 2021-11-10
Pan Os HIGH 7.2
CVE-2021-3058

An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use X…

Fix: 10.0.8 / 10.1.3+
Fix from $1,950 2021-11-10
Ubc1319 Firmware HIGH 7.2
CVE-2021-39474

Vulnerability in the product Docsis 3.0 UBC1319BA00 Router supported affected version 1319010201r009. The vulnerability allows an attacker with privi…

No fix yet
Fix from $1,950 2021-11-10
Opengamepanel HIGH 8.8
CVE-2021-37158

An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by starting a Counter…

Fix: after 2021-08-14
Fix from $1,950 2021-11-10
Lpar2rrd HIGH 8.8
CVE-2021-42372EPSS 6%

A shell command injection in the HW Events SNMP community in XoruX LPAR2RRD and STOR2RRD before 7.30 allows authenticated remote attackers to execute…

Fix: 7.30+
Fix from $1,950 2021-11-08
Tensorflow HIGH 7.8
CVE-2021-41228

TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's `saved_model_cli` tool is vulnerable to a code injectio…

Fix: 2.4.4 / 2.5.2+
Fix from $1,950 2021-11-05
Catalyst Pon Switch Cgp Ont 1p Firmware CRITICAL 9.8
CVE-2021-40113

Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Te…

Fix: 1.1.1.14 / 1.1.3.17+
Fix from $2,300 2021-11-04
Ios Xr HIGH 7.2
CVE-2021-40120

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker…

Mitigation only
Fix from $1,950 2021-11-04
Dir 823g Firmware CRITICAL 9.8
CVE-2020-25368EPSS 9%

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to exe…

Mitigation only
Fix from $2,300 2021-11-04
Dir 823g Firmware CRITICAL 9.8
CVE-2020-25367EPSS 9%

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to exe…

Mitigation only
Fix from $2,300 2021-11-04
Mahara HIGH 7.3
CVE-2021-43266

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters i…

Fix: 20.04.5 / 20.10.3+
Fix from $1,950 2021-11-02
Fortiwlm HIGH 8.8
CVE-2021-36185

A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM version 8.6.1 and below allows atta…

Fix: after 8.6.1
Fix from $1,950 2021-11-02
Aaptjs CRITICAL 9.8
CVE-2020-36378

An issue was discovered in the packageCmd function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

No fix yet
Fix from $2,300 2021-10-31
Aaptjs CRITICAL 9.8
CVE-2020-36379

An issue was discovered in the remove function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

No fix yet
Fix from $2,300 2021-10-31
Aaptjs CRITICAL 9.8
CVE-2020-36380

An issue was discovered in the crunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

No fix yet
Fix from $2,300 2021-10-31
Aaptjs CRITICAL 9.8
CVE-2020-36381

An issue was discovered in the singleCrunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

No fix yet
Fix from $2,300 2021-10-31
Aaptjs CRITICAL 9.8
CVE-2020-26707

An issue was discovered in the add function in Shenzhim AAPTJS 1.3.1 which allows attackers to execute arbitrary code via the filePath parameter.

No fix yet
Fix from $2,300 2021-10-31
Aaptjs CRITICAL 9.8
CVE-2020-36376

An issue was discovered in the list function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

No fix yet
Fix from $2,300 2021-10-31
Aaptjs CRITICAL 9.8
CVE-2020-36377

An issue was discovered in the dump function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

No fix yet
Fix from $2,300 2021-10-31
Firepower Management Center Virtual Appliance HIGH 7.8
CVE-2021-34755

Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrar…

Fix: 6.4.0.13 / 6.6.5+
Fix from $1,950 2021-10-27
Firepower Management Center Virtual Appliance HIGH 7.8
CVE-2021-34756

Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrar…

Fix: 6.4.0.13 / 6.6.5+
Fix from $1,950 2021-10-27
Websvn CRITICAL 9.8
CVE-2011-2195

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl…

No fix yet
Fix from $2,300 2021-10-26
Movable Type CRITICAL 9.8
CVE-2021-20837EPSS 88%

Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and…

Fix: after 7.8.1
Fix from $2,300 2021-10-26
Storm CRITICAL 9.8
CVE-2021-38294EPSS 84%

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4…

Fix: 1.2.4 / 2.1.1+
Fix from $2,300 2021-10-25
Wireless 1410 Gateway Firmware HIGH 8.8
CVE-2021-42538

The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input.

Fix: 4.7.94+
Fix from $1,950 2021-10-22
Media Streaming Add On HIGH 7.2
CVE-2021-34362

A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remo…

Fix: 430.1.8.12 / 500.0.0.3+
Fix from $1,950 2021-10-22
Ios Xe HIGH 7.8
CVE-2021-1529

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privi…

Fix: 17.2.3 / 17.3.4+
Fix from $1,950 2021-10-21
Junos Os Evolved HIGH 7.8
CVE-2021-31358

A command injection vulnerability in sftp command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to…

Fix: after 20.3
Fix from $1,950 2021-10-19
Junos Os Evolved HIGH 7.8
CVE-2021-31356

A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be a…

Fix: after 20.3
Fix from $1,950 2021-10-19