Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2021-41315 The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows an authenticated attacker (w… Remote Collector 17.05.01+ Fix from $1,9502021-09-17 CRITICAL 9.8 CVE-2021-37913 The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interface card setting page. Remote … Oaklouds Portal after 3.0-2 Fix from $2,3002021-09-15 CRITICAL 9.8 CVE-2021-37912 The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network interface card setting page. Remo… Oaklouds Portal after 3.0-2 Fix from $2,3002021-09-15 HIGH 8.8 CVE-2021-23025 On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote com… Big Ip Access Policy Manager 13.1.3.5 / 14.1.3.1+ Fix from $1,9502021-09-14 CRITICAL 9.9 CVE-2021-23031 On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5… Big Ip Advanced Web Application Firewall after 16.0.1.1 Fix from $2,3002021-09-14 HIGH 8.8 CVE-2021-37531 SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerability which allows a non-adminis… Netweaver Knowledge Management Xml Forms No fix yet Fix from $1,9502021-09-14 CRITICAL 10.0 CVE-2021-31891 A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or … Desigo Cc Patch available Fix from $2,3002021-09-14 HIGH 7.2 CVE-2021-33550EPSS 57% Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely … G Cam Ebc 2110 Firmware after 1.12.0.27 Fix from $1,9502021-09-13 HIGH 7.2 CVE-2021-33551EPSS 49% Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely … G Cam Ebc 2110 Firmware after 1.12.0.27 Fix from $1,9502021-09-13 HIGH 7.2 CVE-2021-33552EPSS 49% Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely … G Cam Ebc 2110 Firmware after 1.12.0.27 Fix from $1,9502021-09-13 HIGH 7.2 CVE-2021-33553EPSS 49% Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely … G Cam Ebc 2110 Firmware after 1.12.0.27 Fix from $1,9502021-09-13 HIGH 7.2 CVE-2021-33554EPSS 57% Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely … G Cam Ebc 2110 Firmware after 1.12.0.27 Fix from $1,9502021-09-13 HIGH 7.2 CVE-2021-33548EPSS 57% Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely … G Cam Ebc 2110 Firmware after 1.12.0.27 Fix from $1,9502021-09-13 HIGH 7.2 CVE-2021-33544EPSS 95% Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely … G Cam Ebc 2110 Firmware after 1.12.0.27 Fix from $1,9502021-09-13 HIGH 7.2 CVE-2021-40222 Rittal CMC PU III Web management Version affected: V3.11.00_2. Version fixed: V3.17.10 is affected by a remote code execution vulnerablity. It is pos… Cmc Pu Iii 7030.000 Firmware 3.17.10+ Fix from $1,9502021-09-09 HIGH 7.2 CVE-2021-39459 Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the ho… Redaxo No fix yet Fix from $1,9502021-09-09 HIGH 7.8 CVE-2021-34719 Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate pr… Ios Xr 7.3.2 / 7.4.1+ Fix from $1,9502021-09-09 MEDIUM 6.7 CVE-2021-34721 Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell… Ios Xr 7.3.2 / 7.4.1+ Fix from $1,6002021-09-09 MEDIUM 6.7 CVE-2021-34722 Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell… Ios Xr 7.3.2 / 7.4.1+ Fix from $1,6002021-09-09 HIGH 7.8 CVE-2021-34728 Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate pr… Ios Xr 7.3.2 / 7.4.1+ Fix from $1,9502021-09-09 CRITICAL 9.8 CVE-2020-26300 systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is … Systeminformation 4.26.2+ Fix from $2,3002021-09-09 CRITICAL 9.8 CVE-2020-26772 Command Injection in PPGo_Jobs v2.8.0 allows remote attackers to execute arbitrary code via the 'AjaxRun()' function. Ppgo Jobs No fix yet Fix from $2,3002021-09-08 HIGH 8.8 CVE-2021-28571 Adobe After Effects version 18.1 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debuggi… After Effects after 18.1 Fix from $1,9502021-09-08 HIGH 8.8 CVE-2021-36182 A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker t… Fortiweb 6.3.14+ Fix from $1,9502021-09-08 HIGH 8.8 CVE-2021-39279 Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell… Wac 2004 Firmware No fix yet Fix from $1,9502021-09-07 HIGH 7.2 CVE-2021-36022 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the W… Adobe Commerce after 2.4.2 Fix from $1,9502021-09-01 HIGH 7.2 CVE-2021-36024 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special E… Adobe Commerce after 2.4.2 Fix from $1,9502021-09-01 HIGH 7.2 CVE-2021-27556 The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type parameter to… Zentao No fix yet Fix from $1,9502021-08-31 HIGH 8.1 CVE-2021-35062 A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attacker with a valid token of a C… Testerfassung No fix yet Fix from $1,9502021-08-30 CRITICAL 9.8 CVE-2021-33055EPSS 18% Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions. Manageengine Adselfservice Plus 6.1+ Fix from $2,3002021-08-30