Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Remote Collector HIGH 8.8
CVE-2021-41315

The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows an authenticated attacker (w…

Fix: 17.05.01+
Fix from $1,950 2021-09-17
Oaklouds Portal CRITICAL 9.8
CVE-2021-37913

The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interface card setting page. Remote …

Fix: after 3.0-2
Fix from $2,300 2021-09-15
Oaklouds Portal CRITICAL 9.8
CVE-2021-37912

The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network interface card setting page. Remo…

Fix: after 3.0-2
Fix from $2,300 2021-09-15
Big Ip Access Policy Manager HIGH 8.8
CVE-2021-23025

On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote com…

Fix: 13.1.3.5 / 14.1.3.1+
Fix from $1,950 2021-09-14
Big Ip Advanced Web Application Firewall CRITICAL 9.9
CVE-2021-23031

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5…

Fix: after 16.0.1.1
Fix from $2,300 2021-09-14
Netweaver Knowledge Management Xml Forms HIGH 8.8
CVE-2021-37531

SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerability which allows a non-adminis…

No fix yet
Fix from $1,950 2021-09-14
Desigo Cc CRITICAL 10.0
CVE-2021-31891

A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or …

Patch available
Fix from $2,300 2021-09-14
G Cam Ebc 2110 Firmware HIGH 7.2
CVE-2021-33550EPSS 57%

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …

Fix: after 1.12.0.27
Fix from $1,950 2021-09-13
G Cam Ebc 2110 Firmware HIGH 7.2
CVE-2021-33551EPSS 49%

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …

Fix: after 1.12.0.27
Fix from $1,950 2021-09-13
G Cam Ebc 2110 Firmware HIGH 7.2
CVE-2021-33552EPSS 49%

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …

Fix: after 1.12.0.27
Fix from $1,950 2021-09-13
G Cam Ebc 2110 Firmware HIGH 7.2
CVE-2021-33553EPSS 49%

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …

Fix: after 1.12.0.27
Fix from $1,950 2021-09-13
G Cam Ebc 2110 Firmware HIGH 7.2
CVE-2021-33554EPSS 57%

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …

Fix: after 1.12.0.27
Fix from $1,950 2021-09-13
G Cam Ebc 2110 Firmware HIGH 7.2
CVE-2021-33548EPSS 57%

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …

Fix: after 1.12.0.27
Fix from $1,950 2021-09-13
G Cam Ebc 2110 Firmware HIGH 7.2
CVE-2021-33544EPSS 95%

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …

Fix: after 1.12.0.27
Fix from $1,950 2021-09-13
Cmc Pu Iii 7030.000 Firmware HIGH 7.2
CVE-2021-40222

Rittal CMC PU III Web management Version affected: V3.11.00_2. Version fixed: V3.17.10 is affected by a remote code execution vulnerablity. It is pos…

Fix: 3.17.10+
Fix from $1,950 2021-09-09
Redaxo HIGH 7.2
CVE-2021-39459

Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the ho…

No fix yet
Fix from $1,950 2021-09-09
Ios Xr HIGH 7.8
CVE-2021-34719

Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate pr…

Fix: 7.3.2 / 7.4.1+
Fix from $1,950 2021-09-09
Ios Xr MEDIUM 6.7
CVE-2021-34721

Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell…

Fix: 7.3.2 / 7.4.1+
Fix from $1,600 2021-09-09
Ios Xr MEDIUM 6.7
CVE-2021-34722

Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell…

Fix: 7.3.2 / 7.4.1+
Fix from $1,600 2021-09-09
Ios Xr HIGH 7.8
CVE-2021-34728

Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate pr…

Fix: 7.3.2 / 7.4.1+
Fix from $1,950 2021-09-09
Systeminformation CRITICAL 9.8
CVE-2020-26300

systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is …

Fix: 4.26.2+
Fix from $2,300 2021-09-09
Ppgo Jobs CRITICAL 9.8
CVE-2020-26772

Command Injection in PPGo_Jobs v2.8.0 allows remote attackers to execute arbitrary code via the 'AjaxRun()' function.

No fix yet
Fix from $2,300 2021-09-08
After Effects HIGH 8.8
CVE-2021-28571

Adobe After Effects version 18.1 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debuggi…

Fix: after 18.1
Fix from $1,950 2021-09-08
Fortiweb HIGH 8.8
CVE-2021-36182

A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker t…

Fix: 6.3.14+
Fix from $1,950 2021-09-08
Wac 2004 Firmware HIGH 8.8
CVE-2021-39279

Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell…

No fix yet
Fix from $1,950 2021-09-07
Adobe Commerce HIGH 7.2
CVE-2021-36022

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the W…

Fix: after 2.4.2
Fix from $1,950 2021-09-01
Adobe Commerce HIGH 7.2
CVE-2021-36024

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special E…

Fix: after 2.4.2
Fix from $1,950 2021-09-01
Zentao HIGH 7.2
CVE-2021-27556

The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type parameter to…

No fix yet
Fix from $1,950 2021-08-31
Testerfassung HIGH 8.1
CVE-2021-35062

A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attacker with a valid token of a C…

No fix yet
Fix from $1,950 2021-08-30
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2021-33055EPSS 18%

Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.

Fix: 6.1+
Fix from $2,300 2021-08-30