Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-27944
Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthentic…
P65 F1 Firmware
No fix yet
MEDIUM 6.7
CVE-2021-1584
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attac…
Nx Os
Patch available
CRITICAL 9.8
CVE-2021-39159
BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments from code repositories. In a…
Binderhub
0.2.0-n653+
HIGH 8.8
CVE-2021-39160
nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted li…
Nbgitpuller
0.10.2+
CRITICAL 9.8
CVE-2021-38306EPSS 9%
Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/pl…
N1t1 Firmware
No fix yet
CRITICAL 9.8
CVE-2021-33191
From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. Th…
Nifi Minifi C\+\+
0.10.0+
HIGH 8.8
CVE-2021-39244
Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the getlogs.cg…
Nexto Nx3003 Firmware
No fix yet
HIGH 7.8
CVE-2021-36011
Adobe Illustrator version 25.2.3 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debuggi…
Illustrator
after 25.2.3
HIGH 8.2
CVE-2021-28634
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Improper Ne…
Acrobat Dc
after 21.005.20054
HIGH 8.8
CVE-2020-22345
/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RR…
Centreon
Patch available
HIGH 7.0
CVE-2021-32830
The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability. Clients of th…
Diez
No fix yet
MEDIUM 6.8
CVE-2021-3459
A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arb…
Mm1000 Firmware
No fix yet
HIGH 7.2
CVE-2021-3617
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted network configu…
Smart Camera C2e Firmware
01.03.29.16+
MEDIUM 6.7
CVE-2021-21599
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. This may allow a user with ISI_PRIV_LOGIN_SSH or IS…
Emc Powerscale Onefs
after 9.2.1
HIGH 8.1
CVE-2021-32826
Proxyee-Down is open source proxy software. An attacker being able to provide an extension script (eg: through a MiTM attack or by hosting a maliciou…
Proxyee Down
No fix yet
CRITICAL 9.8
CVE-2021-37708
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.…
Shopware
6.4.3.1+
CRITICAL 9.8
CVE-2021-35394 KEVEPSS 100%
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The bina…
Rtl819x Jungle Software Development Kit
after 3.4.14b
HIGH 7.8
CVE-2021-23422
This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. Whe…
Bikeshed
3.0.0+
HIGH 7.8
CVE-2021-3708EPSS 25%
D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local netwo…
Dsl 2750u Firmware
after 1.16
CRITICAL 9.8
CVE-2021-36380 KEVEPSS 98%
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.
Sureline
8.7.0.1.1+
MEDIUM 6.7
CVE-2021-37028
There is a command injection vulnerability in the HG8045Q product. When the command-line interface is enabled, which is disabled by default, attacker…
Hg8045q Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-37344EPSS 97%
Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS…
Nagios Xi Switch Wizard
2.5.7+
CRITICAL 9.8
CVE-2021-37346EPSS 74%
Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in a…
Nagios Xi Watchguard Wizard
1.4.8+
CRITICAL 9.8
CVE-2021-31698
Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_h…
Eg25 G Firmware
after 202006130814
HIGH 8.8
CVE-2021-3050
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS c…
Pan Os
9.0.15 / 9.1.11+
HIGH 7.2
CVE-2021-33721
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when cr…
Sinec Network Management System
1.0+
CRITICAL 9.8
CVE-2020-23151EPSS 6%
rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed d…
Rconfig
No fix yet
HIGH 7.2
CVE-2021-21585
Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in RACADM and IPMI tools. A remote authenticated mal…
Openmanage Enterprise
3.6.1+
CRITICAL 9.8
CVE-2021-36705
In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter value of TR069 contains a trivi…
Prc2402m Firmware
after 1.0.18
CRITICAL 9.8
CVE-2021-36706
In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a tr…
Prc2402m Firmware
after 1.0.18