Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.8 CVE-2021-31357 A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access… Junos Os Evolved after 20.3 Fix from $1,9502021-10-19 HIGH 7.2 CVE-2021-30358EPSS 27% Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from other locati… Mobile Access Portal Agent Patch available Fix from $1,9502021-10-19 CRITICAL 9.1 CVE-2021-38470 InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a ping tool to inject commands into the devic… Ir615 Firmware Mitigation only Fix from $2,3002021-10-19 CRITICAL 9.1 CVE-2021-38478 InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a traceroute tool to inject commands into the… Ir615 Firmware Mitigation only Fix from $2,3002021-10-19 HIGH 8.8 CVE-2021-24684 The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary OS command on the server via… Pdf Light Viewer 1.4.12+ Fix from $1,9502021-10-18 CRITICAL 9.8 CVE-2021-27561 KEVEPSS 83% Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication. Device Management after 3.6.0.20 Fix from $2,3002021-10-15 CRITICAL 9.8 CVE-2020-22724EPSS 6% A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.… Mer1200 Firmware No fix yet Fix from $2,3002021-10-14 HIGH 7.2 CVE-2021-37732 A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 6.4.x.x: 6.4.4.8-4.2.4.17 and … Aruba Instant 6.4.4.8-4.2.4.18 / 6.5.4.19+ Fix from $1,9502021-10-12 HIGH 7.2 CVE-2021-37727 A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): 6.4.x.x: 6.4.4.8-4.2.4.18 and below; Aruba I… Aruba Instant 6.4.4.8-4.2.4.19 / 6.5.4.20+ Fix from $1,9502021-10-12 HIGH 7.2 CVE-2021-37730 A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 6.4.x.x: 6.4.4.8-4.2.4.18 and … Aruba Instant 6.4.4.8-4.2.4.19 / 6.5.4.20+ Fix from $1,9502021-10-12 HIGH 7.2 CVE-2021-20122EPSS 7% The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in multiple param… Prv65b444a S Ts Firmware No fix yet Fix from $1,9502021-10-11 CRITICAL 9.8 CVE-2021-42071EPSS 70% In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/lo… Dvr Vx16 Firmware No fix yet Fix from $2,3002021-10-07 HIGH 8.8 CVE-2021-34748 A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform … Intersight Virtual Appliance after 1.0.9-292 Fix from $1,9502021-10-06 HIGH 8.8 CVE-2021-34710 Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack … Ata 190 Firmware Mitigation only Fix from $1,9502021-10-06 HIGH 8.1 CVE-2021-1594 A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injectio… Identity Services Engine 2.6.0+ Fix from $1,9502021-10-06 HIGH 7.8 CVE-2021-22557 SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Genera… Slo Generator 2.0.1+ Fix from $1,9502021-10-04 CRITICAL 9.8 CVE-2021-34352 A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers … Qvr 5.1.5+ Fix from $2,3002021-10-01 HIGH 7.8 CVE-2021-35028 A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arb… Zywall Vpn2s Firmware Patch available Fix from $1,9502021-09-29 MEDIUM 6.5 CVE-2021-20035 KEV Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as… Sma 200 Firmware 9.0.0.11-31sv / 10.2.0.8-37sv+ Fix from $1,6002021-09-27 HIGH 8.6 CVE-2021-39826 Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by an arbitrary command execution vulnerability. An authenticated attacker could leve… Digital Editions after 4.5.11.187646 Fix from $1,9502021-09-27 HIGH 7.5 CVE-2021-31605 furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via si… Openvpn Monitor after 1.1.3 Fix from $1,9502021-09-27 CRITICAL 9.8 CVE-2021-34348 A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers … Qvr 5.1.5+ Fix from $2,3002021-09-27 HIGH 7.2 CVE-2021-34349 A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers … Qvr 5.1.5+ Fix from $1,9502021-09-27 CRITICAL 9.8 CVE-2021-34351 A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers … Qvr 5.1.5+ Fix from $2,3002021-09-27 MEDIUM 6.7 CVE-2021-34725 A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed w… Ios Xe Sd Wan after 17.2.1r Fix from $1,6002021-09-23 MEDIUM 6.7 CVE-2021-34726 A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with roo… Sd Wan 18.4.6 / 19.2.3+ Fix from $1,6002021-09-23 MEDIUM 6.7 CVE-2021-34729 A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrar… Ios Xe after 17.3.1a Fix from $1,6002021-09-23 CRITICAL 9.8 CVE-2021-37925EPSS 10% Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-09-22 CRITICAL 9.8 CVE-2021-36260 KEVEPSS 100% A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vul… Ds 2cd2026g2 Iu\/sl Firmware Mitigation only Fix from $2,3002021-09-22 CRITICAL 10.0 CVE-2020-26301 ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. Th… Ssh2 1.4.0+ Fix from $2,3002021-09-20