Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
P65 F1 Firmware CRITICAL 9.8
CVE-2021-27944

Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthentic…

No fix yet
Fix from $2,300 2021-08-26
Nx Os MEDIUM 6.7
CVE-2021-1584

A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attac…

Patch available
Fix from $1,600 2021-08-25
Binderhub CRITICAL 9.8
CVE-2021-39159

BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments from code repositories. In a…

Fix: 0.2.0-n653+
Fix from $2,300 2021-08-25
Nbgitpuller HIGH 8.8
CVE-2021-39160

nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted li…

Fix: 0.10.2+
Fix from $1,950 2021-08-25
N1t1 Firmware CRITICAL 9.8
CVE-2021-38306EPSS 9%

Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/pl…

No fix yet
Fix from $2,300 2021-08-24
Nifi Minifi C\+\+ CRITICAL 9.8
CVE-2021-33191

From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. Th…

Fix: 0.10.0+
Fix from $2,300 2021-08-24
Nexto Nx3003 Firmware HIGH 8.8
CVE-2021-39244

Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the getlogs.cg…

No fix yet
Fix from $1,950 2021-08-23
Illustrator HIGH 7.8
CVE-2021-36011

Adobe Illustrator version 25.2.3 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debuggi…

Fix: after 25.2.3
Fix from $1,950 2021-08-20
Acrobat Dc HIGH 8.2
CVE-2021-28634

Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Improper Ne…

Fix: after 21.005.20054
Fix from $1,950 2021-08-20
Centreon HIGH 8.8
CVE-2020-22345

/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RR…

Patch available
Fix from $1,950 2021-08-18
Diez HIGH 7.0
CVE-2021-32830

The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability. Clients of th…

No fix yet
Fix from $1,950 2021-08-17
Mm1000 Firmware MEDIUM 6.8
CVE-2021-3459

A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arb…

No fix yet
Fix from $1,600 2021-08-17
Smart Camera C2e Firmware HIGH 7.2
CVE-2021-3617

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted network configu…

Fix: 01.03.29.16+
Fix from $1,950 2021-08-17
Emc Powerscale Onefs MEDIUM 6.7
CVE-2021-21599

Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. This may allow a user with ISI_PRIV_LOGIN_SSH or IS…

Fix: after 9.2.1
Fix from $1,600 2021-08-16
Proxyee Down HIGH 8.1
CVE-2021-32826

Proxyee-Down is open source proxy software. An attacker being able to provide an extension script (eg: through a MiTM attack or by hosting a maliciou…

No fix yet
Fix from $1,950 2021-08-16
Shopware CRITICAL 9.8
CVE-2021-37708

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.…

Fix: 6.4.3.1+
Fix from $2,300 2021-08-16
Rtl819x Jungle Software Development Kit CRITICAL 9.8
CVE-2021-35394 KEVEPSS 100%

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The bina…

Fix: after 3.4.14b
Fix from $2,300 2021-08-16
Bikeshed HIGH 7.8
CVE-2021-23422

This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. Whe…

Fix: 3.0.0+
Fix from $1,950 2021-08-16
Dsl 2750u Firmware HIGH 7.8
CVE-2021-3708EPSS 25%

D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local netwo…

Fix: after 1.16
Fix from $1,950 2021-08-16
Sureline CRITICAL 9.8
CVE-2021-36380 KEVEPSS 98%

Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.

Fix: 8.7.0.1.1+
Fix from $2,300 2021-08-13
Hg8045q Firmware MEDIUM 6.7
CVE-2021-37028

There is a command injection vulnerability in the HG8045Q product. When the command-line interface is enabled, which is disabled by default, attacker…

Mitigation only
Fix from $1,600 2021-08-13
Nagios Xi Switch Wizard CRITICAL 9.8
CVE-2021-37344EPSS 97%

Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS…

Fix: 2.5.7+
Fix from $2,300 2021-08-13
Nagios Xi Watchguard Wizard CRITICAL 9.8
CVE-2021-37346EPSS 74%

Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in a…

Fix: 1.4.8+
Fix from $2,300 2021-08-13
Eg25 G Firmware CRITICAL 9.8
CVE-2021-31698

Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_h…

Fix: after 202006130814
Fix from $2,300 2021-08-12
Pan Os HIGH 8.8
CVE-2021-3050

An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS c…

Fix: 9.0.15 / 9.1.11+
Fix from $1,950 2021-08-11
Sinec Network Management System HIGH 7.2
CVE-2021-33721

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when cr…

Fix: 1.0+
Fix from $1,950 2021-08-10
Rconfig CRITICAL 9.8
CVE-2020-23151EPSS 6%

rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed d…

No fix yet
Fix from $2,300 2021-08-09
Openmanage Enterprise HIGH 7.2
CVE-2021-21585

Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in RACADM and IPMI tools. A remote authenticated mal…

Fix: 3.6.1+
Fix from $1,950 2021-08-09
Prc2402m Firmware CRITICAL 9.8
CVE-2021-36705

In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter value of TR069 contains a trivi…

Fix: after 1.0.18
Fix from $2,300 2021-08-06
Prc2402m Firmware CRITICAL 9.8
CVE-2021-36706

In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a tr…

Fix: after 1.0.18
Fix from $2,300 2021-08-06