Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Ios Xe HIGH 7.2
CVE-2021-1384EPSS 35%

A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remote attacker to inject command…

Fix: 16.6.9 / 16.9.7+
Fix from $1,950 2021-03-24
Activemq CRITICAL 9.9
CVE-2021-21345EPSS 72%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Killport HIGH 8.8
CVE-2021-23360

This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary com…

Fix: 1.0.2+
Fix from $1,950 2021-03-21
Openwrt HIGH 8.8
CVE-2021-28961

applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitra…

Patch available
Fix from $1,950 2021-03-21
Port Killer HIGH 8.8
CVE-2021-23359

This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary c…

No fix yet
Fix from $1,950 2021-03-18
Ps Kill CRITICAL 9.8
CVE-2021-23355

This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is possible for an attacker to ex…

No fix yet
Fix from $2,300 2021-03-15
Kill Process By Name CRITICAL 9.8
CVE-2021-23356

This affects all versions of package kill-process-by-name. If (attacker-controlled) user input is given, it is possible for an attacker to execute ar…

No fix yet
Fix from $2,300 2021-03-15
Sma100 Firmware HIGH 8.8
CVE-2021-20017

A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobody' user. …

Fix: after 10.2.0.5
Fix from $1,950 2021-03-13
Dir 841 Firmware HIGH 8.0
CVE-2021-28143EPSS 46%

/jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (under System Tools).

Patch available
Fix from $1,950 2021-03-11
Dir 3060 Firmware HIGH 8.8
CVE-2021-28144EPSS 6%

prog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context bec…

Fix: after 1.11b04
Fix from $1,950 2021-03-11
Security Awareness CRITICAL 9.8
CVE-2021-28132

LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allow…

Fix: after 4.7.8
Fix from $2,300 2021-03-11
React Dev Utils MEDIUM 5.6
CVE-2021-24033

react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to be executed.…

Fix: 11.0.4+
Fix from $1,600 2021-03-09
Rumpus HIGH 8.8
CVE-2020-27575

Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrator…

Mitigation only
Fix from $1,950 2021-03-08
Emc Powerscale Onefs HIGH 7.8
CVE-2021-21503

PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. The Compadmin user could potentially exploit this …

Mitigation only
Fix from $1,950 2021-03-08
Br200 Firmware HIGH 8.8
CVE-2021-27256

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. …

Fix: 1.0.0.134 / 1.0.1.60+
Fix from $1,950 2021-03-05
Airwave MEDIUM 6.3
CVE-2021-26970

A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. V…

Fix: 8.2.12.0+
Fix from $1,600 2021-03-05
Airwave HIGH 7.2
CVE-2021-26962

A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. V…

Fix: 8.2.12.0+
Fix from $1,950 2021-03-05
Docker Dashboard CRITICAL 9.8
CVE-2021-27886EPSS 46%

rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command paramete…

Fix: 2021-02-28+
Fix from $2,300 2021-03-02
Eprints CRITICAL 9.8
CVE-2021-26476

EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.

Patch available
Fix from $2,300 2021-03-01
Eprints HIGH 8.8
CVE-2021-26704

EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.

Patch available
Fix from $1,950 2021-03-01
Eprints CRITICAL 9.8
CVE-2021-3342

EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI.

Patch available
Fix from $2,300 2021-03-01
Secure Vote CRITICAL 9.8
CVE-2019-25022

An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over…

No fix yet
Fix from $2,300 2021-02-27
Prestashop HIGH 7.2
CVE-2021-21302

PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by…

Fix: 1.7.7.2+
Fix from $1,950 2021-02-26
Sv Cpt Mc310 Firmware CRITICAL 9.8
CVE-2021-20658

SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vec…

Fix: 6.5+
Fix from $2,300 2021-02-24
Clearpass Policy Manager HIGH 7.2
CVE-2021-26680

A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14…

Fix: 6.7.14 / 6.8.8+
Fix from $1,950 2021-02-23
Clearpass Policy Manager HIGH 7.2
CVE-2021-26679

A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14…

Fix: 6.7.14 / 6.8.8+
Fix from $1,950 2021-02-23
Clearpass Policy Manager HIGH 7.2
CVE-2021-26681

A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14…

Fix: 6.7.14 / 6.8.7+
Fix from $1,950 2021-02-23
Clearpass Policy Manager HIGH 7.2
CVE-2021-26683

A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14…

Fix: 6.9.5+
Fix from $1,950 2021-02-23
Clearpass Policy Manager HIGH 7.2
CVE-2021-26684

A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14…

Fix: 6.8.8 / 6.9.5+
Fix from $1,950 2021-02-23
Geojson2kml CRITICAL 9.8
CVE-2020-28429EPSS 63%

All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JH…

No fix yet
Fix from $2,300 2021-02-23