Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Gitlog CRITICAL 9.8
CVE-2021-26541EPSS 5%

The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability.

Fix: 4.0.4+
Fix from $2,300 2021-02-08
Siime Eye Firmware CRITICAL 9.8
CVE-2020-11920

An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in the HOST/IP section of the NFS…

No fix yet
Fix from $2,300 2021-02-08
Openemr HIGH 8.8
CVE-2020-36243EPSS 64%

The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, a…

Patch available
Fix from $1,950 2021-02-07
Command Center Agent CRITICAL 9.8
CVE-2021-3122EPSS 87%

CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to p…

Mitigation only
Fix from $2,300 2021-02-07
Ios Xr HIGH 7.8
CVE-2021-1370

A vulnerability in a CLI command of Cisco IOS XR Software for the Cisco 8000 Series Routers and Network Convergence System 540 Series Routers running…

Fix: 7.0.12 / 7.2.1+
Fix from $1,950 2021-02-04
Rv016 Multi Wan Vpn Router Firmware HIGH 7.2
CVE-2021-1315

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…

Fix: after 4.2.3.14
Fix from $1,950 2021-02-04
Rv016 Multi Wan Vpn Router Firmware HIGH 7.2
CVE-2021-1316

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…

Fix: after 4.2.3.14
Fix from $1,950 2021-02-04
Rv016 Multi Wan Vpn Router Firmware HIGH 7.2
CVE-2021-1317

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…

Fix: after 4.2.3.14
Fix from $1,950 2021-02-04
Rv016 Multi Wan Vpn Router Firmware HIGH 7.2
CVE-2021-1318

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…

Fix: after 4.2.3.14
Fix from $1,950 2021-02-04
Rv016 Multi Wan Vpn Router Firmware HIGH 7.2
CVE-2021-1314

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…

Fix: after 4.2.3.14
Fix from $1,950 2021-02-04
Helpdesk CRITICAL 9.8
CVE-2020-2507

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attacke…

Fix: 3.0.3+
Fix from $2,300 2021-02-03
Mechanize HIGH 8.3
CVE-2021-21289

Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is…

Fix: 2.7.7+
Fix from $1,950 2021-02-02
Freediskproject CRITICAL 9.8
CVE-2020-7775

This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments in line 71 of freediskspace.…

Mitigation only
Fix from $2,300 2021-02-02
Linksys Wrt160nl Firmware HIGH 8.8
CVE-2021-25310

The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system co…

No fix yet
Fix from $1,950 2021-02-02
Dsr 250 Firmware CRITICAL 9.8
CVE-2020-18568EPSS 15%

The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution.

No fix yet
Fix from $2,300 2021-02-02
Dns 320 Firmware CRITICAL 9.8
CVE-2020-25506 KEVEPSS 100%

D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code exec…

Mitigation only
Fix from $2,300 2021-02-02
Total.js HIGH 8.6
CVE-2020-28494

This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build th…

Fix: 3.4.7+
Fix from $1,950 2021-02-02
Ucopia Wireless Appliance HIGH 8.8
CVE-2020-25036

UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, and access a shell with admin u…

Fix: after 6.0.5
Fix from $1,950 2021-02-02
Kill Process On Port HIGH 7.3
CVE-2020-28426

All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId.

No fix yet
Fix from $1,950 2021-02-01
Launchpad CRITICAL 9.8
CVE-2021-23330EPSS 5%

All versions of package launchpad are vulnerable to Command Injection via stop.

Patch available
Fix from $2,300 2021-02-01
Elc Analytics HIGH 8.8
CVE-2020-5626

Logstorage version 8.0.0 and earlier, and ELC Analytics version 3.0.0 and earlier allow remote attackers to execute arbitrary OS commands via a speci…

Fix: after 8.0.0
Fix from $1,950 2021-01-28
Klog Server HIGH 8.8
CVE-2021-3317EPSS 41%

KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter.

Fix: after 2.4.1
Fix from $1,950 2021-01-26
Ftpd CRITICAL 9.8
CVE-2013-2512

The ftpd gem 0.2.1 for Ruby allows remote attackers to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command argument with…

No fix yet
Fix from $2,300 2021-01-26
Zen Cart HIGH 7.2
CVE-2021-3291EPSS 17%

Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting…

No fix yet
Fix from $1,950 2021-01-26
Async Git CRITICAL 9.8
CVE-2021-3190EPSS 5%

The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.

Fix: 1.13.2+
Fix from $2,300 2021-01-26
Tinycheck CRITICAL 9.8
CVE-2020-36199

TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.

Fix: 2020-12-18+
Fix from $2,300 2021-01-26
Tl Wr841n Firmware HIGH 8.8
CVE-2020-35576EPSS 42%

A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users t…

Fix: 201216+
Fix from $1,950 2021-01-26
Cs C2shw Firmware MEDIUM 6.8
CVE-2020-27542

Rostelecom CS-C2SHW 5.0.082.1 is affected by: Bash command injection. The camera reads configuration from QR code (including network settings). The s…

No fix yet
Fix from $1,600 2021-01-26
Coronary Tools MEDIUM 6.5
CVE-2020-27298

Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), V…

Mitigation only
Fix from $1,600 2021-01-26
Yale Wipc 303w Firmware HIGH 8.8
CVE-2020-23826EPSS 13%

The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This ma…

Fix: after 2.31
Fix from $1,950 2021-01-26