Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Security Analytics CRITICAL 9.8
CVE-2021-30642

An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior to 8.2.1-NSR2 or 8.2.2 allow…

Fix: 7.2.7 / 8.1.3-nsr3+
Fix from $2,300 2021-04-27
Aterm Wg2600hs Firmware CRITICAL 9.8
CVE-2021-20711

Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

Fix: after 1.5.1
Fix from $2,300 2021-04-26
Dap 1880ac Firmware HIGH 8.8
CVE-2021-20696

DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to execute arbitrary OS commands by sending a specially crafted r…

Fix: after 1.21
Fix from $1,950 2021-04-26
Aterm Wf1200cr Firmware HIGH 7.2
CVE-2021-20708

NEC Aterm devices (Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm WG2600HS firmware Ver1.5.1 a…

Fix: after 1.5.1
Fix from $1,950 2021-04-26
Session Border Controller For Enterprise HIGH 8.8
CVE-2020-7034

A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially c…

Fix: 8.1.2.0+
Fix from $1,950 2021-04-23
Fedora HIGH 7.8
CVE-2021-31607

In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on…

Fix: after 3002.6
Fix from $1,950 2021-04-23
Appformix HIGH 8.1
CVE-2021-0265

An unvalidated REST API in the AppFormix Agent of Juniper Networks AppFormix allows an unauthenticated remote attacker to execute commands as root on…

Fix: 3.1.22 / 3.2.14+
Fix from $1,950 2021-04-22
Discord Recon CRITICAL 9.8
CVE-2021-29465

Discord-Recon is a bot for the Discord chat service. Versions of Discord-Recon 0.0.3 and prior contain a vulnerability in which a remote attacker is …

Fix: 0.0.4+
Fix from $2,300 2021-04-22
Wondercms CRITICAL 9.8
CVE-2020-35314EPSS 27%

A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to uplo…

No fix yet
Fix from $2,300 2021-04-20
Powerscale Onefs MEDIUM 6.7
CVE-2021-21526

Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmin to execute arbitrary comman…

Fix: after 9.1.0
Fix from $1,600 2021-04-20
Home Center 2 Firmware HIGH 8.8
CVE-2021-20991EPSS 5%

In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command in…

Fix: after 4.540
Fix from $1,950 2021-04-19
Killing CRITICAL 9.8
CVE-2021-23381

This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary command…

No fix yet
Fix from $2,300 2021-04-18
Ps Visitor CRITICAL 9.8
CVE-2021-23374

This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to e…

No fix yet
Fix from $2,300 2021-04-18
Psnode CRITICAL 9.8
CVE-2021-23375

This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execu…

No fix yet
Fix from $2,300 2021-04-18
Ffmpegdotjs CRITICAL 9.8
CVE-2021-23376

This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, it is possible for an attacke…

No fix yet
Fix from $2,300 2021-04-18
Onion Oled Js CRITICAL 9.8
CVE-2021-23377

This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker…

No fix yet
Fix from $2,300 2021-04-18
Picotts CRITICAL 9.8
CVE-2021-23378

This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is possible for an attacker to execu…

No fix yet
Fix from $2,300 2021-04-18
Portkiller CRITICAL 9.8
CVE-2021-23379

This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary co…

No fix yet
Fix from $2,300 2021-04-18
Roar Pidusage HIGH 7.3
CVE-2021-23380

This affects all versions of package roar-pidusage. If attacker-controlled user input is given to the stat function of this package on certain operat…

No fix yet
Fix from $1,950 2021-04-18
Qts CRITICAL 9.8
CVE-2020-2509 KEVEPSS 33%

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitra…

Fix: 4.2.6 / 4.3.6+
Fix from $2,300 2021-04-17
G0 Firmware CRITICAL 9.8
CVE-2021-27691EPSS 25%

Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware …

Mitigation only
Fix from $2,300 2021-04-16
G1 Firmware CRITICAL 9.8
CVE-2021-27692

Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute a…

Mitigation only
Fix from $2,300 2021-04-16
Pi Hole HIGH 7.8
CVE-2021-29449

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discover…

Fix: after 5.2.4
Fix from $1,950 2021-04-14
X5000r Firmware CRITICAL 9.8
CVE-2021-27710EPSS 8%

Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allo…

No fix yet
Fix from $2,300 2021-04-14
X5000r Firmware CRITICAL 9.8
CVE-2021-27708EPSS 8%

Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allo…

No fix yet
Fix from $2,300 2021-04-14
Dap 2020 Firmware HIGH 8.8
CVE-2021-27249EPSS 5%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi access p…

Patch available
Fix from $1,950 2021-04-14
Br200 Firmware HIGH 8.8
CVE-2021-27252

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. …

Fix: 1.0.0.134 / 1.0.1.60+
Fix from $1,950 2021-04-14
Dir 816 Firmware CRITICAL 9.8
CVE-2021-27113

An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fu…

No fix yet
Fix from $2,300 2021-04-14
Openclinic Ga CRITICAL 9.8
CVE-2020-27227

An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be execute…

No fix yet
Fix from $2,300 2021-04-13
Platinum 4410 Firmware CRITICAL 9.8
CVE-2021-29003EPSS 45%

Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as…

No fix yet
Fix from $2,300 2021-04-13