Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Io Link Master 4 Eip Firmware HIGH 8.8
CVE-2020-12513EPSS 31%

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.

Fix: after 1.5.48
Fix from $1,950 2021-01-22
Smart Software Manager Satellite CRITICAL 9.8
CVE-2021-1138

Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary…

Fix: after 5.1.0
Fix from $2,300 2021-01-20
Smart Software Manager Satellite HIGH 8.8
CVE-2021-1139

Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary…

Fix: after 5.1.0
Fix from $1,950 2021-01-20
Smart Software Manager Satellite CRITICAL 9.8
CVE-2021-1140

Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary…

Fix: after 5.1.0
Fix from $2,300 2021-01-20
Smart Software Manager Satellite HIGH 8.8
CVE-2021-1141

Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary…

Fix: after 5.1.0
Fix from $1,950 2021-01-20
Smart Software Manager Satellite CRITICAL 9.8
CVE-2021-1142

Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary…

Fix: after 5.1.0
Fix from $2,300 2021-01-20
Catalyst Center HIGH 8.8
CVE-2021-1264

A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack. T…

Fix: 1.3.1.0+
Fix from $1,950 2021-01-20
Graphql Tools HIGH 8.8
CVE-2021-23326

This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/src/load-git.ts allows arbitrar…

Fix: 6.2.6+
Fix from $1,950 2021-01-20
Junos HIGH 7.8
CVE-2021-0218

A command injection vulnerability in the license-check daemon of Juniper Networks Junos OS that may allow a locally authenticated attacker with low p…

Mitigation only
Fix from $1,950 2021-01-15
Junos MEDIUM 6.7
CVE-2021-0219

A command injection vulnerability in install package validation subsystem of Juniper Networks Junos OS that may allow a locally authenticated attacke…

Mitigation only
Fix from $1,600 2021-01-15
Emc Avamar Server CRITICAL 10.0
CVE-2020-29495EPSS 6%

DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attack…

Patch available
Fix from $2,300 2021-01-14
Fortideceptor HIGH 8.8
CVE-2020-29017

An OS command injection vulnerability in FortiDeceptor 3.1.0, 3.0.1, 3.0.0 may allow a remote authenticated attacker to execute arbitrary commands on…

Mitigation only
Fix from $1,950 2021-01-14
Rv110w Firmware HIGH 7.2
CVE-2021-1148

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authe…

Mitigation only
Fix from $1,950 2021-01-13
Rv110w Firmware HIGH 7.2
CVE-2021-1149

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authe…

Mitigation only
Fix from $1,950 2021-01-13
Rv110w Firmware HIGH 7.2
CVE-2021-1150

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authe…

Mitigation only
Fix from $1,950 2021-01-13
Rv110w Firmware HIGH 7.2
CVE-2021-1146

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authe…

Mitigation only
Fix from $1,950 2021-01-13
Rv110w Firmware HIGH 7.2
CVE-2021-1147

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authe…

Mitigation only
Fix from $1,950 2021-01-13
Nagios Xi HIGH 7.2
CVE-2020-35578EPSS 82%

An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugi…

Fix: 5.8.0+
Fix from $1,950 2021-01-13
Univerge Sv9500 Firmware CRITICAL 9.8
CVE-2020-5685

UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-of-service …

Mitigation only
Fix from $2,300 2021-01-13
Hawk CRITICAL 9.8
CVE-2020-35458EPSS 5%

An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in …

Patch available
Fix from $2,300 2021-01-12
Debian Linux HIGH 7.8
CVE-2020-35459

An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute comma…

Fix: after 4.2.1
Fix from $1,950 2021-01-12
Qts HIGH 7.2
CVE-2020-2508

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitra…

Fix: 4.5.1.1456+
Fix from $1,950 2021-01-11
Sma 100 Firmware HIGH 7.2
CVE-2020-5146

A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This…

Fix: after 10.2.0.2-20sv
Fix from $1,950 2021-01-09
Buns CRITICAL 9.8
CVE-2020-7794

This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the exported function install(req…

Mitigation only
Fix from $2,300 2021-01-08
Ts Process Promises CRITICAL 9.8
CVE-2020-7784

This affects all versions of package ts-process-promises. The injection point is located in line 45 in main entry of package in lib/process-promises.…

No fix yet
Fix from $2,300 2021-01-08
Ecs Imaging CRITICAL 9.8
CVE-2021-3029

EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters and an IFS manipulation. The…

Fix: after 6.21.5
Fix from $2,300 2021-01-07
Jabber CRITICAL 9.9
CVE-2020-26085

Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary …

Fix: 12.1.4 / 12.5.3+
Fix from $2,300 2021-01-07
Tl Wr840n Firmware CRITICAL 9.8
CVE-2020-36178EPSS 10%

oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web in…

No fix yet
Fix from $2,300 2021-01-06
Compiler MEDIUM 5.3
CVE-2020-26294

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela compiler before version 0.6.1 there is…

Fix: 0.6.1+
Fix from $1,600 2021-01-04
Msr45 Isherlock User CRITICAL 9.8
CVE-2020-35851

HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and …

Fix: 4.5-115+
Fix from $2,300 2020-12-31