Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2021-27944 Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthentic… P65 F1 Firmware No fix yet Fix from $2,3002021-08-26 MEDIUM 6.7 CVE-2021-1584 A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attac… Nx Os Patch available Fix from $1,6002021-08-25 CRITICAL 9.8 CVE-2021-39159 BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments from code repositories. In a… Binderhub 0.2.0-n653+ Fix from $2,3002021-08-25 HIGH 8.8 CVE-2021-39160 nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted li… Nbgitpuller 0.10.2+ Fix from $1,9502021-08-25 CRITICAL 9.8 CVE-2021-38306EPSS 9% Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/pl… N1t1 Firmware No fix yet Fix from $2,3002021-08-24 CRITICAL 9.8 CVE-2021-33191 From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. Th… Nifi Minifi C\+\+ 0.10.0+ Fix from $2,3002021-08-24 HIGH 8.8 CVE-2021-39244 Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the getlogs.cg… Nexto Nx3003 Firmware No fix yet Fix from $1,9502021-08-23 HIGH 7.8 CVE-2021-36011 Adobe Illustrator version 25.2.3 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debuggi… Illustrator after 25.2.3 Fix from $1,9502021-08-20 HIGH 8.2 CVE-2021-28634 Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Improper Ne… Acrobat Dc after 21.005.20054 Fix from $1,9502021-08-20 HIGH 8.8 CVE-2020-22345 /graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RR… Centreon Patch available Fix from $1,9502021-08-18 HIGH 7.0 CVE-2021-32830 The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability. Clients of th… Diez No fix yet Fix from $1,9502021-08-17 MEDIUM 6.8 CVE-2021-3459 A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arb… Mm1000 Firmware No fix yet Fix from $1,6002021-08-17 HIGH 7.2 CVE-2021-3617 A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted network configu… Smart Camera C2e Firmware 01.03.29.16+ Fix from $1,9502021-08-17 MEDIUM 6.7 CVE-2021-21599 Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. This may allow a user with ISI_PRIV_LOGIN_SSH or IS… Emc Powerscale Onefs after 9.2.1 Fix from $1,6002021-08-16 HIGH 8.1 CVE-2021-32826 Proxyee-Down is open source proxy software. An attacker being able to provide an extension script (eg: through a MiTM attack or by hosting a maliciou… Proxyee Down No fix yet Fix from $1,9502021-08-16 CRITICAL 9.8 CVE-2021-37708 Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.… Shopware 6.4.3.1+ Fix from $2,3002021-08-16 CRITICAL 9.8 CVE-2021-35394 KEVEPSS 100% Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The bina… Rtl819x Jungle Software Development Kit after 3.4.14b Fix from $2,3002021-08-16 HIGH 7.8 CVE-2021-23422 This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. Whe… Bikeshed 3.0.0+ Fix from $1,9502021-08-16 HIGH 7.8 CVE-2021-3708EPSS 25% D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local netwo… Dsl 2750u Firmware after 1.16 Fix from $1,9502021-08-16 CRITICAL 9.8 CVE-2021-36380 KEVEPSS 98% Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi. Sureline 8.7.0.1.1+ Fix from $2,3002021-08-13 MEDIUM 6.7 CVE-2021-37028 There is a command injection vulnerability in the HG8045Q product. When the command-line interface is enabled, which is disabled by default, attacker… Hg8045q Firmware Mitigation only Fix from $1,6002021-08-13 CRITICAL 9.8 CVE-2021-37344EPSS 97% Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS… Nagios Xi Switch Wizard 2.5.7+ Fix from $2,3002021-08-13 CRITICAL 9.8 CVE-2021-37346EPSS 74% Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in a… Nagios Xi Watchguard Wizard 1.4.8+ Fix from $2,3002021-08-13 CRITICAL 9.8 CVE-2021-31698 Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_h… Eg25 G Firmware after 202006130814 Fix from $2,3002021-08-12 HIGH 8.8 CVE-2021-3050 An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS c… Pan Os 9.0.15 / 9.1.11+ Fix from $1,9502021-08-11 HIGH 7.2 CVE-2021-33721 A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when cr… Sinec Network Management System 1.0+ Fix from $1,9502021-08-10 CRITICAL 9.8 CVE-2020-23151EPSS 6% rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed d… Rconfig No fix yet Fix from $2,3002021-08-09 HIGH 7.2 CVE-2021-21585 Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in RACADM and IPMI tools. A remote authenticated mal… Openmanage Enterprise 3.6.1+ Fix from $1,9502021-08-09 CRITICAL 9.8 CVE-2021-36705 In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter value of TR069 contains a trivi… Prc2402m Firmware after 1.0.18 Fix from $2,3002021-08-06 CRITICAL 9.8 CVE-2021-36706 In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a tr… Prc2402m Firmware after 1.0.18 Fix from $2,3002021-08-06