Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2021-23862 A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue a… Bosch Video Management System 10.0.2+ Fix from $1,9502021-12-08 HIGH 8.8 CVE-2021-36195 Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2… Fortiweb after 6.3.15 Fix from $1,9502021-12-08 HIGH 8.8 CVE-2021-36180 Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3… Fortiweb after 6.3.15 Fix from $1,9502021-12-08 HIGH 8.8 CVE-2021-20044EPSS 40% A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands… Sma 200 Firmware Mitigation only Fix from $1,9502021-12-08 HIGH 8.8 CVE-2021-20039EPSS 78% Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated att… Sma 200 Firmware No fix yet Fix from $1,9502021-12-08 CRITICAL 9.8 CVE-2021-44685 Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verification process, it attempts t… Git It after 4.4.0 Fix from $2,3002021-12-07 CRITICAL 9.8 CVE-2021-44684 naholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenated without any validation, an… Github Todos after 3.1.0 Fix from $2,3002021-12-07 CRITICAL 9.8 CVE-2021-43033EPSS 6% An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary r… Unitrends Backup 10.5.5+ Fix from $2,3002021-12-06 HIGH 8.0 CVE-2021-20859 ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS… Wrc 1167gst2 Firmware after 2.11 Fix from $1,9502021-12-01 HIGH 8.0 CVE-2021-20863 OS command injection vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H fi… Wrc 1167gst2 Firmware after 2.11 Fix from $1,9502021-12-01 MEDIUM 6.8 CVE-2021-20853 ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an admin… Wrh 733gbk Firmware after 1.02.9 Fix from $1,6002021-12-01 MEDIUM 6.8 CVE-2021-20854 ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an admin… Wrh 733gbk Firmware after 1.02.9 Fix from $1,6002021-12-01 HIGH 8.8 CVE-2021-43283 An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the web interface of the device, … Wr1200 Firmware after 1.0.3 Fix from $1,9502021-11-30 CRITICAL 9.8 CVE-2020-7879 This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera … C200 Firmware after 1.0.16 Fix from $2,3002021-11-30 CRITICAL 9.8 CVE-2021-3769 # Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to … Oh My Zsh 2021-11-11+ Fix from $2,3002021-11-30 HIGH 8.8 CVE-2021-3725 Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt… Oh My Zsh 11-11-2021+ Fix from $1,9502021-11-30 CRITICAL 9.8 CVE-2021-3726 # Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` to set the terminal title to … Oh My Zsh 2021-11-11+ Fix from $2,3002021-11-30 CRITICAL 9.8 CVE-2021-3727 # Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hito… Oh My Zsh 72928432+ Fix from $2,3002021-11-30 HIGH 8.8 CVE-2021-41243 There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to up… Basercms 4.5.4+ Fix from $1,9502021-11-26 CRITICAL 9.8 CVE-2021-38685 A command injection vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability allows remote attackers to run a… Qvr 5.1.6+ Fix from $2,3002021-11-26 CRITICAL 9.8 CVE-2021-20850 PowerCMS XMLRPC API of PowerCMS 5.19 and earlier, PowerCMS 4.49 and earlier, PowerCMS 3.295 and earlier, and PowerCMS 2 Series (End-of-Life, EOL) all… Powercms after 5.19 Fix from $2,3002021-11-24 CRITICAL 9.8 CVE-2021-42784EPSS 7% OS Command Injection vulnerability in debug_fcgi of D-Link DWR-932C E1 firmware allows a remote attacker to perform command injection via a crafted H… Dwr 932c E1 Firmware after 1.0.0.4 Fix from $2,3002021-11-23 HIGH 7.2 CVE-2021-36313 Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged attacker, may potentially explo… Cloudlink 7.1.1+ Fix from $1,9502021-11-23 CRITICAL 9.0 CVE-2021-23732 This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least be partially controlled by a u… Docker Cli Js No fix yet Fix from $2,3002021-11-22 CRITICAL 9.8 CVE-2021-41280 Sharetribe Go is a source available marketplace software. In affected versions operating system command injection is possible on installations of Sha… Sharetribe 10.2.1+ Fix from $2,3002021-11-19 HIGH 8.8 CVE-2021-3723 A command injection vulnerability was reported in the Integrated Management Module (IMM) of legacy IBM System x 3550 M3 and IBM System x 3650 M3 serv… System X3550 M3 Firmware Mitigation only Fix from $1,9502021-11-12 HIGH 8.8 CVE-2021-3577EPSS 60% An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on … Halo\+ Camera Firmware 03.40.00 / 03.40.02+ Fix from $1,9502021-11-12 HIGH 8.8 CVE-2021-41254 kustomize-controller is a Kubernetes operator, specialized in running continuous delivery pipelines for infrastructure and workloads defined with Kub… Kustomize Controller 0.15.0+ Fix from $1,9502021-11-12 HIGH 7.5 CVE-2021-3934 ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command Oh My Zsh 2021-11-11+ Fix from $1,9502021-11-12 HIGH 8.1 CVE-2021-3059 An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerabilit… Pan Os 10.0.8 / 10.1.3+ Fix from $1,9502021-11-10