Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Central Management Control HIGH 7.2
CVE-2021-26724

OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated adm…

Fix: 19.0.12 / 20.0.7.4+
Fix from $1,950 2021-02-22
Nano 25 Firmware HIGH 7.2
CVE-2021-3149

On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authentication by the attacker) bec…

Mitigation only
Fix from $1,950 2021-02-22
Amaze File Manager HIGH 7.8
CVE-2020-36246

Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link.

Fix: 3.5.1+
Fix from $1,950 2021-02-19
Openrepeater CRITICAL 9.8
CVE-2019-25024EPSS 28%

OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service paramet…

Fix: 2.2+
Fix from $2,300 2021-02-19
Wf2780 Firmware CRITICAL 9.8
CVE-2021-26747EPSS 54%

Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.

No fix yet
Fix from $2,300 2021-02-18
Async Git CRITICAL 9.8
CVE-2020-28490

The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKED…

Fix: 1.13.2+
Fix from $2,300 2021-02-18
Mavic 2 Firmware HIGH 7.8
CVE-2020-29664

A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious fi…

Fix: 01.00.0510+
Fix from $1,950 2021-02-18
Filezen HIGH 7.2
CVE-2021-20655

FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary OS commands via unspecified v…

Fix: after 5.0.2
Fix from $1,950 2021-02-17
Fta HIGH 7.8
CVE-2021-27102 KEV

Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.

Fix: after 9_12_411
Fix from $1,950 2021-02-16
Fta CRITICAL 9.8
CVE-2021-27104 KEVEPSS 56%

Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FT…

Fix: after 9_12_370
Fix from $2,300 2021-02-16
M\!dge Firmware HIGH 8.8
CVE-2021-20074

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and execute arbitrary OS commands.

Mitigation only
Fix from $1,950 2021-02-16
Cordova HIGH 7.8
CVE-2021-21315 KEVEPSS 91%

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,…

Fix: 5.3.1+
Fix from $1,950 2021-02-16
Firewall Community HIGH 8.8
CVE-2021-27201

Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup com…

No fix yet
Fix from $1,950 2021-02-15
Nagios Xi HIGH 8.8
CVE-2020-24899EPSS 17%

Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into normal webapp q…

No fix yet
Fix from $1,950 2021-02-15
Nagios Xi HIGH 8.8
CVE-2021-25297 KEVEPSS 56%

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/…

Fix: after 5.7.5
Fix from $1,950 2021-02-15
Nagios Xi HIGH 8.8
CVE-2021-25298 KEVEPSS 75%

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/…

Fix: after 5.7.5
Fix from $1,950 2021-02-15
Nedi HIGH 8.8
CVE-2021-26752

NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the …

No fix yet
Fix from $1,950 2021-02-12
Wrc 300febk S Firmware MEDIUM 6.8
CVE-2021-20648

ELECOM WRC-300FEBK-S allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.

Mitigation only
Fix from $1,600 2021-02-12
Lan W300n\/pgrb Firmware MEDIUM 6.8
CVE-2021-20638

LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

Mitigation only
Fix from $1,600 2021-02-12
Lan W300n\/pgrb Firmware MEDIUM 6.8
CVE-2021-20639

LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

Mitigation only
Fix from $1,600 2021-02-12
Cbk40 Firmware HIGH 8.8
CVE-2020-27861

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi 2.5.1.16 routers. Authentica…

Fix: 1.0.0.210 / 1.0.1.82+
Fix from $1,950 2021-02-12
Vsphere Replication HIGH 7.2
CVE-2021-21976

vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication c…

Fix: 6.5.1.5 / 8.1.2.3+
Fix from $1,950 2021-02-11
Magento CRITICAL 9.1
CVE-2021-21018

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the scheduled operati…

Fix: 2.3.6+
Fix from $2,300 2021-02-11
Magento HIGH 8.0
CVE-2021-21015

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attri…

Fix: 2.3.6+
Fix from $1,950 2021-02-11
Magento CRITICAL 9.1
CVE-2021-21016

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successfu…

Fix: 2.3.6+
Fix from $2,300 2021-02-11
Emc Powerscale Onefs HIGH 7.8
CVE-2020-26193

Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability. A user with the ISI_PRIV_CLUSTER privilege may e…

Mitigation only
Fix from $1,950 2021-02-09
Operation Bridge Reporter CRITICAL 9.8
CVE-2021-22502 KEVEPSS 97%

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be explo…

Mitigation only
Fix from $2,300 2021-02-08
Node Ps CRITICAL 9.8
CVE-2020-7785

This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js.

No fix yet
Fix from $2,300 2021-02-08
Macfromip CRITICAL 9.8
CVE-2020-7786

This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js.

No fix yet
Fix from $2,300 2021-02-08
Spritesheet Js CRITICAL 9.8
CVE-2020-7782

This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 i…

No fix yet
Fix from $2,300 2021-02-08