Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Dir 802 Firmware HIGH 8.8
CVE-2021-29379

An issue was discovered on D-Link DIR-802 A1 devices through 1.00b05. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker …

Fix: after 1.00b05
Fix from $1,950 2021-04-12
Discord Recon HIGH 8.8
CVE-2021-21433

Discord Recon Server is a bot that allows you to do your reconnaissance process from your Discord. Remote code execution in version 0.0.1 would allow…

Fix: 0.0.2+
Fix from $1,950 2021-04-09
Unibox U50 Firmware HIGH 8.8
CVE-2020-21883

Unibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerability in /tools/ping, which can …

Mitigation only
Fix from $1,950 2021-04-09
Rv340 Firmware CRITICAL 9.8
CVE-2021-1473EPSS 64%

Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbit…

Fix: 1.0.03.21+
Fix from $2,300 2021-04-08
Retroarch HIGH 7.8
CVE-2021-28927

The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the accessibili…

Fix: after 1.9.4
Fix from $1,950 2021-04-07
Z10pr D16 Firmware HIGH 7.2
CVE-2021-28204

The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obta…

Mitigation only
Fix from $1,950 2021-04-06
Z10pr D16 Firmware HIGH 7.2
CVE-2021-28203

The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator pe…

Mitigation only
Fix from $1,950 2021-04-06
Dir 846 Firmware CRITICAL 9.8
CVE-2020-27600EPSS 14%

HNAP1/control/SetMasterWLanSettings.php in D-Link D-Link Router DIR-846 DIR-846 A1_100.26 allows remote attackers to execute arbitrary commands via s…

No fix yet
Fix from $2,300 2021-04-02
Access Gateway MEDIUM 6.7
CVE-2021-28113EPSS 22%

A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin …

Fix: after 2020.8.4
Fix from $1,600 2021-04-02
Diskstation Manager HIGH 7.2
CVE-2021-29083

Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426…

Fix: 6.2.3-25426-3+
Fix from $1,950 2021-04-01
Portprocesses HIGH 8.8
CVE-2021-23348

This affects the package portprocesses before 1.0.5. If (attacker-controlled) user input is given to the killProcess function, it is possible for an …

Fix: 1.0.5+
Fix from $1,950 2021-03-31
\@thi.ng\/egf HIGH 8.8
CVE-2021-21412

Potential for arbitrary code execution in npm package @thi.ng/egf `#gpg`-tagged property values (only if `decrypt: true` option is enabled). PR with …

Fix: 0.4.0+
Fix from $1,950 2021-03-30
Kill By Port HIGH 8.8
CVE-2021-23363

This affects the package kill-by-port before 0.0.2. If (attacker-controlled) user input is given to the killByPort function, it is possible for an at…

Fix: 0.0.2+
Fix from $1,950 2021-03-30
Dir 816 Firmware CRITICAL 9.8
CVE-2021-26810

D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in…

No fix yet
Fix from $2,300 2021-03-30
Instant HIGH 8.1
CVE-2021-25162EPSS 26%

A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant …

Fix: 6.5.4.19 / 8.3.0.15+
Fix from $1,950 2021-03-30
Instant HIGH 7.2
CVE-2021-25146

A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant …

Fix: 6.5.4.18 / 8.3.0.14+
Fix from $1,950 2021-03-30
Instant HIGH 8.8
CVE-2021-25150

A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant …

Fix: 6.5.4.18 / 8.3.0.14+
Fix from $1,950 2021-03-30
Prosafe Network Management System HIGH 8.8
CVE-2021-27273EPSS 65%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.…

Mitigation only
Fix from $1,950 2021-03-29
Instant HIGH 7.2
CVE-2020-24635

A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant …

Fix: 6.5.4.18 / 8.3.0.14+
Fix from $1,950 2021-03-29
Instant CRITICAL 9.8
CVE-2020-24636

A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant …

Fix: 6.5.4.18 / 8.3.0.14+
Fix from $2,300 2021-03-29
Nim HIGH 8.8
CVE-2021-21372

Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in differ…

Fix: 1.2.10 / 1.4.4+
Fix from $1,950 2021-03-26
Rtf3505vw N1 Br Sv G000 R3505vwn1001 S32 7 Firmware HIGH 8.8
CVE-2020-28695

Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7 devices allow Remote Code Execution and retrieval of admin credentials to log into the …

No fix yet
Fix from $1,950 2021-03-26
Basercms HIGH 7.2
CVE-2021-20682

baserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.

Fix: 4.4.5+
Fix from $1,950 2021-03-26
Automatic Device Management HIGH 8.8
CVE-2020-10583

The /admin/admapi.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary OS co…

Fix: after 5.0
Fix from $1,950 2021-03-25
Spamassassin CRITICAL 9.8
CVE-2020-1946EPSS 6%

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. …

Fix: 3.4.5+
Fix from $2,300 2021-03-25
Apkleaks CRITICAL 9.8
CVE-2021-21386

APKLeaks is an open-source project for scanning APK file for URIs, endpoints & secrets. APKLeaks prior to v2.0.3 allows remote attackers to execute a…

Fix: 2.0.3+
Fix from $2,300 2021-03-24
Ios Xe MEDIUM 6.7
CVE-2021-1441

A vulnerability in the hardware initialization routines of Cisco IOS XE Software for Cisco 1100 Series Industrial Integrated Services Routers and Cis…

Mitigation only
Fix from $1,600 2021-03-24
Ios Xe HIGH 7.2
CVE-2021-1443

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges o…

Mitigation only
Fix from $1,950 2021-03-24
Ios Xe Rom Monitor MEDIUM 6.8
CVE-2021-1452

A vulnerability in the ROM Monitor (ROMMON) of Cisco IOS XE Software for Cisco Catalyst IE3200, IE3300, and IE3400 Rugged Series Switches, Cisco Cata…

Fix: after 7.0
Fix from $1,600 2021-03-24
Ios Xe MEDIUM 6.7
CVE-2021-1382

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed w…

Fix: 17.3.3 / 17.5.1a+
Fix from $1,600 2021-03-24