Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2021-32849EPSS 8% Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is f… Gerapy 0.9.9+ Fix from $1,9502022-01-26 HIGH 7.2 CVE-2021-36295 Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with pri… Emc Unity Operating Environment after 8.1.21.266 Fix from $1,9502022-01-25 HIGH 7.2 CVE-2021-36296 Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with pri… Emc Unity Operating Environment after 8.1.21.266 Fix from $1,9502022-01-25 HIGH 7.8 CVE-2021-45845 The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted … Debian Linux Patch available Fix from $1,9502022-01-25 HIGH 7.8 CVE-2021-45844 Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename. Debian Linux Patch available Fix from $1,9502022-01-25 HIGH 7.8 CVE-2022-23935EPSS 8% lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection. Exiftool 12.38+ Fix from $1,9502022-01-25 MEDIUM 6.7 CVE-2021-43589 Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerabil… Emc Unity Operating Environment 5.1.2.0.5.007+ Fix from $1,6002022-01-24 HIGH 8.8 CVE-2021-44981 In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); function … Quickbox after 2.5.8 Fix from $1,9502022-01-24 HIGH 7.8 CVE-2021-31854 A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cle… Agent 5.7.5+ Fix from $1,9502022-01-19 HIGH 8.8 CVE-2021-38965 IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sendin… Filenet Content Manager Patch available Fix from $1,9502022-01-17 HIGH 7.2 CVE-2021-33827 The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings. Files Antivirus 1.0.0+ Fix from $1,9502022-01-15 CRITICAL 9.8 CVE-2021-33962 China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device compon… An Lianbao Wf Firmware 1 Mitigation only Fix from $2,3002022-01-14 HIGH 8.8 CVE-2022-22991 A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecure… My Cloud Os 5.19.117+ Fix from $1,9502022-01-13 HIGH 8.8 CVE-2022-20617 Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability ex… Docker Commons after 1.17 Fix from $1,9502022-01-12 HIGH 8.6 CVE-2022-21668 pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requiremen… Fedora 2022.1.8+ Fix from $1,9502022-01-10 HIGH 7.8 CVE-2021-23154 In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed… Lens after 5.3.3 Fix from $1,9502022-01-10 CRITICAL 9.9 CVE-2021-43779EPSS 9% GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers fro… Addressing 2.9.1+ Fix from $2,3002022-01-05 HIGH 7.8 CVE-2021-45912 An unauthenticated Named Pipe channel in Controlup Real-Time Agent (cuAgent.exe) before 8.5 potentially allows an attacker to run OS commands via the… Real Time Agent 8.5+ Fix from $1,9502022-01-04 HIGH 7.8 CVE-2021-45978 Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via xfa.host.gotoURL in the XFA API. Pdf Editor 11.1+ Fix from $1,9502022-01-04 HIGH 7.8 CVE-2021-45979 Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API. Pdf Editor 11.1+ Fix from $1,9502022-01-04 HIGH 8.8 CVE-2021-20159 Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmware allows for command inject… Tew 827dru Firmware No fix yet Fix from $1,9502021-12-30 HIGH 8.8 CVE-2021-20160 Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the device. The username parameter … Tew 827dru Firmware No fix yet Fix from $1,9502021-12-30 HIGH 8.8 CVE-2021-20173 Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system up… R6700 Firmware No fix yet Fix from $1,9502021-12-30 HIGH 8.0 CVE-2021-35031 A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authen… Gs1900 8 Firmware 2.70+ Fix from $1,9502021-12-28 HIGH 7.8 CVE-2021-35032 A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS c… Gs1900 8 Firmware 2.70+ Fix from $1,9502021-12-28 HIGH 8.8 CVE-2021-43857EPSS 55% Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched… Gerapy 0.9.8+ Fix from $1,9502021-12-27 HIGH 7.8 CVE-2021-45602 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.66, EX2700 before 1.0.1.68, WN300… D7800 Firmware 1.0.0.90 / 1.0.1.66+ Fix from $1,9502021-12-26 HIGH 8.8 CVE-2021-3621 A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This fl… Virtualization Patch available Fix from $1,9502021-12-23 HIGH 7.2 CVE-2021-3584 A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to … Satellite 2.4.1 / 2.5.1+ Fix from $1,9502021-12-23 CRITICAL 9.8 CVE-2021-43981 mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands thro… Mypro after 8.20.0 Fix from $2,3002021-12-23