Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
H8922 Firmware HIGH 8.8
CVE-2021-28151EPSS 28%

Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping co…

No fix yet
Fix from $1,950 2021-05-06
Git Parse HIGH 8.8
CVE-2021-26543

The "gitDiff" function in Wayfair git-parse <=1.0.4 has a command injection vulnerability. Clients of the git-parse library are unlikely to be aware …

Fix: 1.0.5+
Fix from $1,950 2021-05-06
Emc Powerscale Onefs MEDIUM 6.7
CVE-2021-21527

Dell PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may …

Mitigation only
Fix from $1,600 2021-05-06
Emc Powerscale Onefs MEDIUM 6.7
CVE-2021-21550

Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability …

Mitigation only
Fix from $1,600 2021-05-06
Wap125 Firmware HIGH 7.2
CVE-2021-1401

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-06
Enterprise Nfv Infrastructure Software HIGH 7.8
CVE-2021-1421

A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to perform a command injection a…

Fix: 4.5.1+
Fix from $1,950 2021-05-06
Hyperflex Hx Data Platform CRITICAL 9.8
CVE-2021-1497 KEVEPSS 100%

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform comma…

Fix: 4.0 / 4.5+
Fix from $2,300 2021-05-06
Hyperflex Hx Data Platform CRITICAL 9.8
CVE-2021-1498 KEVEPSS 100%

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform comma…

Fix: 4.0 / 4.5+
Fix from $2,300 2021-05-06
Catalyst Sd Wan Manager HIGH 7.8
CVE-2021-1514

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with Adm…

Fix: 18.3 / 20.1.1+
Fix from $1,950 2021-05-06
Facesentry Access Control System Firmware HIGH 8.8
CVE-2020-21999EPSS 5%

iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can b…

No fix yet
Fix from $1,950 2021-05-04
Gnuplot CRITICAL 9.8
CVE-2021-29369

The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands.

Fix: 0.1.0+
Fix from $2,300 2021-05-03
Openmanage Enterprise Modular HIGH 8.8
CVE-2021-21530

Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authenticated malicious user with lo…

Fix: 1.30.00+
Fix from $1,950 2021-04-30
Secure Firewall Threat Defense HIGH 7.8
CVE-2021-1448

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary command…

Fix: 6.4.0.10 / 6.5.0.5+
Fix from $1,950 2021-04-29
Secure Firewall Threat Defense MEDIUM 6.7
CVE-2021-1476

A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authe…

Fix: 6.6.4 / 6.7.0.2+
Fix from $1,600 2021-04-29
Secure Firewall Threat Defense MEDIUM 6.7
CVE-2021-1488

A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could al…

Fix: 6.6.4 / 6.7.0.2+
Fix from $1,600 2021-04-29
Systeminformation CRITICAL 9.8
CVE-2021-21388

systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions …

Fix: 5.6.4+
Fix from $2,300 2021-04-29
An Lianbao Wf 1 Firmware HIGH 8.8
CVE-2021-30229

The api/zrDm/set_zrDm interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metachar…

No fix yet
Fix from $1,950 2021-04-29
An Lianbao Wf 1 Firmware CRITICAL 9.8
CVE-2021-30230

The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via she…

No fix yet
Fix from $2,300 2021-04-29
An Lianbao Wf 1 Firmware CRITICAL 9.8
CVE-2021-30231

The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metac…

No fix yet
Fix from $2,300 2021-04-29
An Lianbao Wf 1 Firmware CRITICAL 9.8
CVE-2021-30232

The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell …

No fix yet
Fix from $2,300 2021-04-29
An Lianbao Wf 1 Firmware CRITICAL 9.8
CVE-2021-30233

The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell met…

No fix yet
Fix from $2,300 2021-04-29
An Lianbao Wf 1 Firmware CRITICAL 9.8
CVE-2021-30234

The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell m…

No fix yet
Fix from $2,300 2021-04-29
An Lianbao Wf 1 Firmware CRITICAL 9.8
CVE-2021-30228

The api/ZRAndlink/set_ZRAndlink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shel…

No fix yet
Fix from $2,300 2021-04-29
Smartliving 505 Firmware HIGH 8.8
CVE-2020-21992EPSS 5%

Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. The issue exist due to the 'pa…

Fix: after 6.0
Fix from $1,950 2021-04-29
Clearpass HIGH 8.8
CVE-2021-29147

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aru…

Fix: 6.7.14 / 6.8.8+
Fix from $1,950 2021-04-29
Airwave HIGH 8.8
CVE-2021-25166

A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patch…

Fix: 8.2.12.1+
Fix from $1,950 2021-04-29
Airwave HIGH 8.8
CVE-2021-25167

A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patch…

Fix: 8.2.12.1+
Fix from $1,950 2021-04-29
Prisma HIGH 7.2
CVE-2021-21414

Prisma is an open source ORM for Node.js & TypeScript. As of today, we are not aware of any Prisma users or external consumers of the `@prisma/sdk` p…

Fix: 2.20.0+
Fix from $1,950 2021-04-29
P2r8852e2 Firmware HIGH 7.2
CVE-2021-30166

The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injecti…

Fix: 7.1.94.8908+
Fix from $1,950 2021-04-28
Homeautomation HIGH 8.0
CVE-2020-22000

HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. This can be exploited with a …

No fix yet
Fix from $1,950 2021-04-27