Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2021-34611 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aru… Clearpass Policy Manager 6.8.9 / 6.9.6+ Fix from $1,9502021-07-08 CRITICAL 9.8 CVE-2021-32534 QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary com… Sanos 2.1.0+ Fix from $2,3002021-07-07 HIGH 7.2 CVE-2021-32524 Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Suggest contacting with QSAN an… Storage Manager after 3.3.1 Fix from $1,9502021-07-07 CRITICAL 9.8 CVE-2021-32530 OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status pa… Xevo after 1.2.0 Fix from $2,3002021-07-07 CRITICAL 9.8 CVE-2021-32531 OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The refer… Xevo 2.1.0+ Fix from $2,3002021-07-07 CRITICAL 9.8 CVE-2021-32533 The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands … Sanos 2.1.0+ Fix from $2,3002021-07-07 CRITICAL 9.8 CVE-2021-32512 QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute a… Storage Manager 3.3.3+ Fix from $2,3002021-07-07 CRITICAL 9.8 CVE-2021-32513 QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute ar… Storage Manager 3.3.3+ Fix from $2,3002021-07-07 HIGH 8.8 CVE-2021-20739 WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all versions a… Wrc 300febk Firmware Mitigation only Fix from $1,9502021-07-07 CRITICAL 9.8 CVE-2021-28802 A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbi… Qts 4.5.1.1540+ Fix from $2,3002021-07-01 CRITICAL 9.8 CVE-2021-28804 A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbi… Qts after 4.5.1.1540 Fix from $2,3002021-07-01 CRITICAL 9.1 CVE-2021-31838 A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to exec… Mvision Edr 3.4.0+ Fix from $2,3002021-06-29 CRITICAL 9.8 CVE-2021-23399 This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, it is possible for an attacke… Wincred No fix yet Fix from $2,3002021-06-28 HIGH 8.8 CVE-2021-20740 Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Gateway Nh4a/Nh8a versions prio… Virtual File Platform 5.5.3-09 / 6.4.3-09+ Fix from $1,9502021-06-28 HIGH 7.8 CVE-2021-20745 Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet co… Inkdrop 5.3.1+ Fix from $1,9502021-06-28 HIGH 8.8 CVE-2021-33530 In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script func… Ie Wl Bl Ap Cl Eu Firmware after 1.16.18 Fix from $1,9502021-06-25 HIGH 8.8 CVE-2021-33532 In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A spe… Ie Wl Bl Ap Cl Eu Firmware after 1.16.18 Fix from $1,9502021-06-25 HIGH 8.8 CVE-2021-33533 In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A spe… Ie Wl Bl Ap Cl Eu Firmware after 1.16.18 Fix from $1,9502021-06-25 HIGH 7.2 CVE-2021-33534 In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A sp… Ie Wl Bl Ap Cl Eu Firmware after 1.16.18 Fix from $1,9502021-06-25 CRITICAL 9.8 CVE-2021-28958EPSS 73% Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password. Manageengine Adselfservice Plus Mitigation only Fix from $2,3002021-06-25 HIGH 8.8 CVE-2021-35047 Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the… Deception 9.3.7+ Fix from $1,9502021-06-25 HIGH 8.8 CVE-2021-35049 Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could… Deception 9.3.7+ Fix from $1,9502021-06-25 CRITICAL 9.8 CVE-2021-28800 A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attack… Qts 4.3.3.1624 / 4.3.6.1663+ Fix from $2,3002021-06-24 CRITICAL 9.1 CVE-2021-21809EPSS 24% A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can le… Moodle No fix yet Fix from $2,3002021-06-23 HIGH 8.8 CVE-2021-31769 MyQ Server in MyQ X Smart before 8.2 allows remote code execution by unprivileged users because administrative session data can be read in the %PROGR… Myq Server 8.2+ Fix from $1,9502021-06-21 HIGH 8.8 CVE-2020-25755 An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows rem… Envoy Firmware No fix yet Fix from $1,9502021-06-16 CRITICAL 9.8 CVE-2021-32682EPSS 70% elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnera… Elfinder 2.1.59+ Fix from $2,3002021-06-14 CRITICAL 9.8 CVE-2021-33357EPSS 17% A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value conta… Raspap after 2.6.5 Fix from $2,3002021-06-09 HIGH 8.8 CVE-2021-33358 Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in /hostapd, when the parameter… Raspap after 2.6.5 Fix from $1,9502021-06-09 CRITICAL 9.8 CVE-2021-33841 SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker to inject code into the opera… Sge Plc1000 Firmware Mitigation only Fix from $2,3002021-06-09