Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Clearpass Policy Manager HIGH 7.2
CVE-2021-34611

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aru…

Fix: 6.8.9 / 6.9.6+
Fix from $1,950 2021-07-08
Sanos CRITICAL 9.8
CVE-2021-32534

QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary com…

Fix: 2.1.0+
Fix from $2,300 2021-07-07
Storage Manager HIGH 7.2
CVE-2021-32524

Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Suggest contacting with QSAN an…

Fix: after 3.3.1
Fix from $1,950 2021-07-07
Xevo CRITICAL 9.8
CVE-2021-32530

OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status pa…

Fix: after 1.2.0
Fix from $2,300 2021-07-07
Xevo CRITICAL 9.8
CVE-2021-32531

OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The refer…

Fix: 2.1.0+
Fix from $2,300 2021-07-07
Sanos CRITICAL 9.8
CVE-2021-32533

The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands …

Fix: 2.1.0+
Fix from $2,300 2021-07-07
Storage Manager CRITICAL 9.8
CVE-2021-32512

QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute a…

Fix: 3.3.3+
Fix from $2,300 2021-07-07
Storage Manager CRITICAL 9.8
CVE-2021-32513

QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute ar…

Fix: 3.3.3+
Fix from $2,300 2021-07-07
Wrc 300febk Firmware HIGH 8.8
CVE-2021-20739

WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all versions a…

Mitigation only
Fix from $1,950 2021-07-07
Qts CRITICAL 9.8
CVE-2021-28802

A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbi…

Fix: 4.5.1.1540+
Fix from $2,300 2021-07-01
Qts CRITICAL 9.8
CVE-2021-28804

A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbi…

Fix: after 4.5.1.1540
Fix from $2,300 2021-07-01
Mvision Edr CRITICAL 9.1
CVE-2021-31838

A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to exec…

Fix: 3.4.0+
Fix from $2,300 2021-06-29
Wincred CRITICAL 9.8
CVE-2021-23399

This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, it is possible for an attacke…

No fix yet
Fix from $2,300 2021-06-28
Virtual File Platform HIGH 8.8
CVE-2021-20740

Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Gateway Nh4a/Nh8a versions prio…

Fix: 5.5.3-09 / 6.4.3-09+
Fix from $1,950 2021-06-28
Inkdrop HIGH 7.8
CVE-2021-20745

Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet co…

Fix: 5.3.1+
Fix from $1,950 2021-06-28
Ie Wl Bl Ap Cl Eu Firmware HIGH 8.8
CVE-2021-33530

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script func…

Fix: after 1.16.18
Fix from $1,950 2021-06-25
Ie Wl Bl Ap Cl Eu Firmware HIGH 8.8
CVE-2021-33532

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A spe…

Fix: after 1.16.18
Fix from $1,950 2021-06-25
Ie Wl Bl Ap Cl Eu Firmware HIGH 8.8
CVE-2021-33533

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A spe…

Fix: after 1.16.18
Fix from $1,950 2021-06-25
Ie Wl Bl Ap Cl Eu Firmware HIGH 7.2
CVE-2021-33534

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A sp…

Fix: after 1.16.18
Fix from $1,950 2021-06-25
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2021-28958EPSS 73%

Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.

Mitigation only
Fix from $2,300 2021-06-25
Deception HIGH 8.8
CVE-2021-35047

Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the…

Fix: 9.3.7+
Fix from $1,950 2021-06-25
Deception HIGH 8.8
CVE-2021-35049

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could…

Fix: 9.3.7+
Fix from $1,950 2021-06-25
Qts CRITICAL 9.8
CVE-2021-28800

A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attack…

Fix: 4.3.3.1624 / 4.3.6.1663+
Fix from $2,300 2021-06-24
Moodle CRITICAL 9.1
CVE-2021-21809EPSS 24%

A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can le…

No fix yet
Fix from $2,300 2021-06-23
Myq Server HIGH 8.8
CVE-2021-31769

MyQ Server in MyQ X Smart before 8.2 allows remote code execution by unprivileged users because administrative session data can be read in the %PROGR…

Fix: 8.2+
Fix from $1,950 2021-06-21
Envoy Firmware HIGH 8.8
CVE-2020-25755

An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows rem…

No fix yet
Fix from $1,950 2021-06-16
Elfinder CRITICAL 9.8
CVE-2021-32682EPSS 70%

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnera…

Fix: 2.1.59+
Fix from $2,300 2021-06-14
Raspap CRITICAL 9.8
CVE-2021-33357EPSS 17%

A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value conta…

Fix: after 2.6.5
Fix from $2,300 2021-06-09
Raspap HIGH 8.8
CVE-2021-33358

Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in /hostapd, when the parameter…

Fix: after 2.6.5
Fix from $1,950 2021-06-09
Sge Plc1000 Firmware CRITICAL 9.8
CVE-2021-33841

SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker to inject code into the opera…

Mitigation only
Fix from $2,300 2021-06-09