Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2021-34611
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aru…
Clearpass Policy Manager
6.8.9 / 6.9.6+
CRITICAL 9.8
CVE-2021-32534
QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary com…
Sanos
2.1.0+
HIGH 7.2
CVE-2021-32524
Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Suggest contacting with QSAN an…
Storage Manager
after 3.3.1
CRITICAL 9.8
CVE-2021-32530
OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status pa…
Xevo
after 1.2.0
CRITICAL 9.8
CVE-2021-32531
OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The refer…
Xevo
2.1.0+
CRITICAL 9.8
CVE-2021-32533
The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands …
Sanos
2.1.0+
CRITICAL 9.8
CVE-2021-32512
QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute a…
Storage Manager
3.3.3+
CRITICAL 9.8
CVE-2021-32513
QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute ar…
Storage Manager
3.3.3+
HIGH 8.8
CVE-2021-20739
WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all versions a…
Wrc 300febk Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-28802
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbi…
Qts
4.5.1.1540+
CRITICAL 9.8
CVE-2021-28804
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbi…
Qts
after 4.5.1.1540
CRITICAL 9.1
CVE-2021-31838
A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to exec…
Mvision Edr
3.4.0+
CRITICAL 9.8
CVE-2021-23399
This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, it is possible for an attacke…
Wincred
No fix yet
HIGH 8.8
CVE-2021-20740
Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Gateway Nh4a/Nh8a versions prio…
Virtual File Platform
5.5.3-09 / 6.4.3-09+
HIGH 7.8
CVE-2021-20745
Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet co…
Inkdrop
5.3.1+
HIGH 8.8
CVE-2021-33530
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script func…
Ie Wl Bl Ap Cl Eu Firmware
after 1.16.18
HIGH 8.8
CVE-2021-33532
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A spe…
Ie Wl Bl Ap Cl Eu Firmware
after 1.16.18
HIGH 8.8
CVE-2021-33533
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A spe…
Ie Wl Bl Ap Cl Eu Firmware
after 1.16.18
HIGH 7.2
CVE-2021-33534
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A sp…
Ie Wl Bl Ap Cl Eu Firmware
after 1.16.18
CRITICAL 9.8
CVE-2021-28958EPSS 73%
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
Manageengine Adselfservice Plus
Mitigation only
HIGH 8.8
CVE-2021-35047
Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the…
Deception
9.3.7+
HIGH 8.8
CVE-2021-35049
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could…
Deception
9.3.7+
CRITICAL 9.8
CVE-2021-28800
A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attack…
Qts
4.3.3.1624 / 4.3.6.1663+
CRITICAL 9.1
CVE-2021-21809EPSS 24%
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can le…
Moodle
No fix yet
HIGH 8.8
CVE-2021-31769
MyQ Server in MyQ X Smart before 8.2 allows remote code execution by unprivileged users because administrative session data can be read in the %PROGR…
Myq Server
8.2+
HIGH 8.8
CVE-2020-25755
An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows rem…
Envoy Firmware
No fix yet
CRITICAL 9.8
CVE-2021-32682EPSS 70%
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnera…
Elfinder
2.1.59+
CRITICAL 9.8
CVE-2021-33357EPSS 17%
A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value conta…
Raspap
after 2.6.5
HIGH 8.8
CVE-2021-33358
Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in /hostapd, when the parameter…
Raspap
after 2.6.5
CRITICAL 9.8
CVE-2021-33841
SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker to inject code into the opera…
Sge Plc1000 Firmware
Mitigation only