Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
R Seenet CRITICAL 9.8
CVE-2021-21805EPSS 70%

An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HT…

No fix yet
Fix from $2,300 2021-08-05
Small Business Rv Series Router Firmware CRITICAL 9.8
CVE-2021-1602

A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an una…

Fix: 1.0.01.04+
Fix from $2,300 2021-08-04
Fortisandbox HIGH 8.8
CVE-2021-26097

An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.…

Fix: 3.0.7 / 3.1.5+
Fix from $1,950 2021-08-04
Poddycast HIGH 8.8
CVE-2021-32772

Poddycast is a podcast app made with Electron. Prior to version 0.8.1, an attacker can create a podcast or episode with malicious characters and exec…

Mitigation only
Fix from $1,950 2021-08-03
Debian Linux HIGH 7.0
CVE-2021-31799

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.

Fix: 6.3.1 / 9.2.6.1+
Fix from $1,950 2021-07-30
Gitlogplus CRITICAL 9.8
CVE-2021-23412

All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command …

No fix yet
Fix from $2,300 2021-07-23
Mobileiron HIGH 7.2
CVE-2021-3198

By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issu…

Fix: 11.1.0.0+
Fix from $1,950 2021-07-22
Syracuse HIGH 7.2
CVE-2020-7389

Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by t…

Fix: 9.22.7.2 / 11.25.2.6+
Fix from $1,950 2021-07-22
Ova Appliance CRITICAL 9.8
CVE-2021-31580

The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH channel from `shell` to `exec` a…

Fix: 3.0 / 3.3.0.314-4a349e0+
Fix from $2,300 2021-07-22
Homematic Ccu2 Firmware CRITICAL 10.0
CVE-2021-33032EPSS 52%

A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5 and CCU3 fi…

Fix: after 3.57.5
Fix from $2,300 2021-07-22
Intersight Virtual Appliance HIGH 7.2
CVE-2021-1618

Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to…

Fix: 1.0.9-292+
Fix from $1,950 2021-07-22
Aos Cx Firmware HIGH 7.2
CVE-2021-29143

A remote execution of arbitrary commands vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Se…

Fix: 10.04.3070 / 10.05.0070+
Fix from $1,950 2021-07-22
Cx2 Firmware CRITICAL 9.8
CVE-2020-21935

A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to…

No fix yet
Fix from $2,300 2021-07-21
Cx2 Firmware CRITICAL 9.8
CVE-2020-21937

An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execut…

No fix yet
Fix from $2,300 2021-07-21
Gradle HIGH 7.5
CVE-2021-32751

Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradl…

Fix: 7.2+
Fix from $1,950 2021-07-20
B5 Firmware HIGH 7.2
CVE-2020-25206EPSS 5%

The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, an…

Fix: 2.8.1.0+
Fix from $1,950 2021-07-20
Fortisandbox HIGH 7.2
CVE-2021-22125

An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrato…

Fix: 3.2.2+
Fix from $1,950 2021-07-20
Emc Openmanage Enterprise Modular CRITICAL 9.1
CVE-2020-5322

Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a command injection vulnerability. A remote authenticated malicious …

Fix: 1.10.00+
Fix from $2,300 2021-07-19
Emc Powerstore MEDIUM 6.7
CVE-2020-29499

Dell EMC PowerStore versions prior to 1.0.3.0.5.006 contain an OS Command Injection vulnerability in PowerStore X environment . A locally authenticat…

Fix: 1.0.3.0.5.007+
Fix from $1,600 2021-07-19
Fedora HIGH 8.1
CVE-2021-32749

fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0…

Fix: 0.10.7 / 0.11.3+
Fix from $1,950 2021-07-16
Dir 3040 Firmware HIGH 7.2
CVE-2021-21819

A code execution vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request ca…

No fix yet
Fix from $1,950 2021-07-16
Caldera HIGH 8.8
CVE-2020-19907

A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.

Fix: after 2.3.1
Fix from $1,950 2021-07-12
Fortimail HIGH 8.8
CVE-2021-24015

An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allo…

Fix: 6.0.11 / 6.2.7+
Fix from $1,950 2021-07-12
Fortiap HIGH 7.8
CVE-2021-26106

An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5 m…

Fix: 6.2.6 / 6.4.6+
Fix from $1,950 2021-07-09
Clearpass Policy Manager MEDIUM 6.3
CVE-2021-34616

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aru…

Fix: 6.8.9 / 6.9.6+
Fix from $1,600 2021-07-08
Clearpass Policy Manager MEDIUM 6.3
CVE-2021-34612

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aru…

Fix: 6.8.9 / 6.9.6+
Fix from $1,600 2021-07-08
Clearpass Policy Manager MEDIUM 6.3
CVE-2021-34613

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aru…

Fix: 6.8.9 / 6.9.6+
Fix from $1,600 2021-07-08
Clearpass Policy Manager MEDIUM 6.3
CVE-2021-34615

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aru…

Fix: 6.8.9 / 6.9.6+
Fix from $1,600 2021-07-08
Clearpass Policy Manager MEDIUM 6.3
CVE-2021-34614

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aru…

Fix: 6.8.9 / 6.9.6+
Fix from $1,600 2021-07-08
Clearpass Policy Manager HIGH 7.2
CVE-2021-34610

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aru…

Fix: 6.8.9 / 6.9.6+
Fix from $1,950 2021-07-08