Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2021-20731 WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allow an attacker to execute arbitrary OS commands with root pr… Wsr 1166dhp4 Firmware after 1.16 Fix from $1,9502021-06-09 CRITICAL 9.8 CVE-2021-26472 In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using th… Bdr Suite 4.2.0.1+ Fix from $2,3002021-06-08 CRITICAL 9.8 CVE-2021-32673 reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg-keygen-git-hash-plugin throu… Reg Keygen Git Hash after 0.10.15 Fix from $2,3002021-06-08 HIGH 7.2 CVE-2021-28811 If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. Roon Labs has already fixed this vulnerabi… Roon Server 2021-05-18+ Fix from $1,9502021-06-08 HIGH 7.2 CVE-2021-1538 A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to ex… Common Services Platform Collector 2.9.1+ Fix from $1,9502021-06-04 HIGH 8.8 CVE-2021-24023 An improper input validation in FortiAI v1.4.0 and earlier may allow an authenticated user to gain system shell access via a malicious payload in the… Fortiai Firmware after 1.4.0 Fix from $1,9502021-06-03 HIGH 8.8 CVE-2021-28812 A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attac… Video Station 5.5.4+ Fix from $1,9502021-06-03 HIGH 8.8 CVE-2021-22123EPSS 77% An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote aut… Fortiweb 6.2.4 / 6.3.8+ Fix from $1,9502021-06-01 HIGH 8.8 CVE-2020-26670 A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands through a … Bigtree Cms after 4.4.10 Fix from $1,9502021-06-01 MEDIUM 6.7 CVE-2021-3515 A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server… Pglogical 2.3.4 / 3.6.26+ Fix from $1,6002021-06-01 HIGH 7.2 CVE-2021-24312 The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of … Wp Super Cache 1.7.3+ Fix from $1,9502021-06-01 HIGH 8.8 CVE-2021-20026EPSS 12% A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. T… Network Security Manager 2.2.0+ Fix from $1,9502021-05-27 MEDIUM 5.3 CVE-2021-30187 CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command. 750 893 Firmware Mitigation only Fix from $1,6002021-05-25 HIGH 8.8 CVE-2021-33525EPSS 8% EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in the nagios_path parameter to… Eyesofnetwork after 5.3-11 Fix from $1,9502021-05-24 CRITICAL 9.8 CVE-2021-29300 The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote attacker to execute commands o… Opened 1.5.2+ Fix from $2,3002021-05-24 HIGH 7.2 CVE-2021-20557 IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted req… Security Guardium Patch available Fix from $1,9502021-05-24 HIGH 8.8 CVE-2021-1487 A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an aut… Evolved Programmable Network Manager 3.9 / 5.1+ Fix from $1,9502021-05-22 MEDIUM 6.7 CVE-2021-1557 Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary comma… Dna Spaces\ 2.3.1+ Fix from $1,6002021-05-22 MEDIUM 6.7 CVE-2021-1558 Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary comma… Dna Spaces\ 2.3.1+ Fix from $1,6002021-05-22 HIGH 7.2 CVE-2021-1559 Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affe… Dna Spaces\ 2.0.519+ Fix from $1,9502021-05-22 HIGH 7.2 CVE-2021-1560 Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affe… Dna Spaces\ 2.0.519+ Fix from $1,9502021-05-22 CRITICAL 9.8 CVE-2021-33514EPSS 8% Certain NETGEAR devices are affected by command injection by an unauthenticated attacker via the vulnerable /sqfs/lib/libsal.so.0.0 library used by a… Gc108p Firmware 1.0.2.3 / 1.0.4.3+ Fix from $2,3002021-05-21 MEDIUM 6.8 CVE-2021-20719 RFNTPS firmware versions System_01000004 and earlier, and Web_01000004 and earlier allow an attacker on the same network segment to execute arbitrary… Rfntps Firmware Mitigation only Fix from $1,6002021-05-20 CRITICAL 9.8 CVE-2021-31324EPSS 34% The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution. Webpanel No fix yet Fix from $2,3002021-05-18 CRITICAL 9.8 CVE-2021-32305EPSS 87% WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter. Websvn 2.6.1+ Fix from $2,3002021-05-18 MEDIUM 6.7 CVE-2020-36198 A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote att… Malware Remover 4.6.1.0+ Fix from $1,6002021-05-13 CRITICAL 9.8 CVE-2021-32605 zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, … Zzzphp 2.0.4+ Fix from $2,3002021-05-11 CRITICAL 9.8 CVE-2021-31915 In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible. Teamcity 2020.2.4+ Fix from $2,3002021-05-11 HIGH 8.2 CVE-2021-23012 On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items u… Big Ip Access Policy Manager 13.1.4 / 14.1.4+ Fix from $1,9502021-05-10 CRITICAL 9.8 CVE-2021-32090 The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter. Localstack No fix yet Fix from $2,3002021-05-07