Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Junos Os Evolved HIGH 7.8
CVE-2021-31357

A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access…

Fix: after 20.3
Fix from $1,950 2021-10-19
Mobile Access Portal Agent HIGH 7.2
CVE-2021-30358EPSS 27%

Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from other locati…

Patch available
Fix from $1,950 2021-10-19
Ir615 Firmware CRITICAL 9.1
CVE-2021-38470

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a ping tool to inject commands into the devic…

Mitigation only
Fix from $2,300 2021-10-19
Ir615 Firmware CRITICAL 9.1
CVE-2021-38478

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a traceroute tool to inject commands into the…

Mitigation only
Fix from $2,300 2021-10-19
Pdf Light Viewer HIGH 8.8
CVE-2021-24684

The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary OS command on the server via…

Fix: 1.4.12+
Fix from $1,950 2021-10-18
Device Management CRITICAL 9.8
CVE-2021-27561 KEVEPSS 83%

Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.

Fix: after 3.6.0.20
Fix from $2,300 2021-10-15
Mer1200 Firmware CRITICAL 9.8
CVE-2020-22724EPSS 6%

A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.…

No fix yet
Fix from $2,300 2021-10-14
Aruba Instant HIGH 7.2
CVE-2021-37732

A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 6.4.x.x: 6.4.4.8-4.2.4.17 and …

Fix: 6.4.4.8-4.2.4.18 / 6.5.4.19+
Fix from $1,950 2021-10-12
Aruba Instant HIGH 7.2
CVE-2021-37727

A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): 6.4.x.x: 6.4.4.8-4.2.4.18 and below; Aruba I…

Fix: 6.4.4.8-4.2.4.19 / 6.5.4.20+
Fix from $1,950 2021-10-12
Aruba Instant HIGH 7.2
CVE-2021-37730

A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 6.4.x.x: 6.4.4.8-4.2.4.18 and …

Fix: 6.4.4.8-4.2.4.19 / 6.5.4.20+
Fix from $1,950 2021-10-12
Prv65b444a S Ts Firmware HIGH 7.2
CVE-2021-20122EPSS 7%

The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in multiple param…

No fix yet
Fix from $1,950 2021-10-11
Dvr Vx16 Firmware CRITICAL 9.8
CVE-2021-42071EPSS 70%

In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/lo…

No fix yet
Fix from $2,300 2021-10-07
Intersight Virtual Appliance HIGH 8.8
CVE-2021-34748

A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform …

Fix: after 1.0.9-292
Fix from $1,950 2021-10-06
Ata 190 Firmware HIGH 8.8
CVE-2021-34710

Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack …

Mitigation only
Fix from $1,950 2021-10-06
Identity Services Engine HIGH 8.1
CVE-2021-1594

A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injectio…

Fix: 2.6.0+
Fix from $1,950 2021-10-06
Slo Generator HIGH 7.8
CVE-2021-22557

SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Genera…

Fix: 2.0.1+
Fix from $1,950 2021-10-04
Qvr CRITICAL 9.8
CVE-2021-34352

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers …

Fix: 5.1.5+
Fix from $2,300 2021-10-01
Zywall Vpn2s Firmware HIGH 7.8
CVE-2021-35028

A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arb…

Patch available
Fix from $1,950 2021-09-29
Sma 200 Firmware MEDIUM 6.5
CVE-2021-20035 KEV

Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as…

Fix: 9.0.0.11-31sv / 10.2.0.8-37sv+
Fix from $1,600 2021-09-27
Digital Editions HIGH 8.6
CVE-2021-39826

Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by an arbitrary command execution vulnerability. An authenticated attacker could leve…

Fix: after 4.5.11.187646
Fix from $1,950 2021-09-27
Openvpn Monitor HIGH 7.5
CVE-2021-31605

furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via si…

Fix: after 1.1.3
Fix from $1,950 2021-09-27
Qvr CRITICAL 9.8
CVE-2021-34348

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers …

Fix: 5.1.5+
Fix from $2,300 2021-09-27
Qvr HIGH 7.2
CVE-2021-34349

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers …

Fix: 5.1.5+
Fix from $1,950 2021-09-27
Qvr CRITICAL 9.8
CVE-2021-34351

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers …

Fix: 5.1.5+
Fix from $2,300 2021-09-27
Ios Xe Sd Wan MEDIUM 6.7
CVE-2021-34725

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed w…

Fix: after 17.2.1r
Fix from $1,600 2021-09-23
Sd Wan MEDIUM 6.7
CVE-2021-34726

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with roo…

Fix: 18.4.6 / 19.2.3+
Fix from $1,600 2021-09-23
Ios Xe MEDIUM 6.7
CVE-2021-34729

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrar…

Fix: after 17.3.1a
Fix from $1,600 2021-09-23
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37925EPSS 10%

Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.

Fix: 7.1+
Fix from $2,300 2021-09-22
Ds 2cd2026g2 Iu\/sl Firmware CRITICAL 9.8
CVE-2021-36260 KEVEPSS 100%

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vul…

Mitigation only
Fix from $2,300 2021-09-22
Ssh2 CRITICAL 10.0
CVE-2020-26301

ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. Th…

Fix: 1.4.0+
Fix from $2,300 2021-09-20