Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2021-30642 An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior to 8.2.1-NSR2 or 8.2.2 allow… Security Analytics 7.2.7 / 8.1.3-nsr3+ Fix from $2,3002021-04-27 CRITICAL 9.8 CVE-2021-20711 Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. Aterm Wg2600hs Firmware after 1.5.1 Fix from $2,3002021-04-26 HIGH 8.8 CVE-2021-20696 DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to execute arbitrary OS commands by sending a specially crafted r… Dap 1880ac Firmware after 1.21 Fix from $1,9502021-04-26 HIGH 7.2 CVE-2021-20708 NEC Aterm devices (Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm WG2600HS firmware Ver1.5.1 a… Aterm Wf1200cr Firmware after 1.5.1 Fix from $1,9502021-04-26 HIGH 8.8 CVE-2020-7034 A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially c… Session Border Controller For Enterprise 8.1.2.0+ Fix from $1,9502021-04-23 HIGH 7.8 CVE-2021-31607 In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on… Fedora after 3002.6 Fix from $1,9502021-04-23 HIGH 8.1 CVE-2021-0265 An unvalidated REST API in the AppFormix Agent of Juniper Networks AppFormix allows an unauthenticated remote attacker to execute commands as root on… Appformix 3.1.22 / 3.2.14+ Fix from $1,9502021-04-22 CRITICAL 9.8 CVE-2021-29465 Discord-Recon is a bot for the Discord chat service. Versions of Discord-Recon 0.0.3 and prior contain a vulnerability in which a remote attacker is … Discord Recon 0.0.4+ Fix from $2,3002021-04-22 CRITICAL 9.8 CVE-2020-35314EPSS 27% A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to uplo… Wondercms No fix yet Fix from $2,3002021-04-20 MEDIUM 6.7 CVE-2021-21526 Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmin to execute arbitrary comman… Powerscale Onefs after 9.1.0 Fix from $1,6002021-04-20 HIGH 8.8 CVE-2021-20991EPSS 5% In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command in… Home Center 2 Firmware after 4.540 Fix from $1,9502021-04-19 CRITICAL 9.8 CVE-2021-23381 This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary command… Killing No fix yet Fix from $2,3002021-04-18 CRITICAL 9.8 CVE-2021-23374 This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to e… Ps Visitor No fix yet Fix from $2,3002021-04-18 CRITICAL 9.8 CVE-2021-23375 This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execu… Psnode No fix yet Fix from $2,3002021-04-18 CRITICAL 9.8 CVE-2021-23376 This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, it is possible for an attacke… Ffmpegdotjs No fix yet Fix from $2,3002021-04-18 CRITICAL 9.8 CVE-2021-23377 This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker… Onion Oled Js No fix yet Fix from $2,3002021-04-18 CRITICAL 9.8 CVE-2021-23378 This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is possible for an attacker to execu… Picotts No fix yet Fix from $2,3002021-04-18 CRITICAL 9.8 CVE-2021-23379 This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary co… Portkiller No fix yet Fix from $2,3002021-04-18 HIGH 7.3 CVE-2021-23380 This affects all versions of package roar-pidusage. If attacker-controlled user input is given to the stat function of this package on certain operat… Roar Pidusage No fix yet Fix from $1,9502021-04-18 CRITICAL 9.8 CVE-2020-2509 KEVEPSS 33% A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitra… Qts 4.2.6 / 4.3.6+ Fix from $2,3002021-04-17 CRITICAL 9.8 CVE-2021-27691EPSS 25% Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware … G0 Firmware Mitigation only Fix from $2,3002021-04-16 CRITICAL 9.8 CVE-2021-27692 Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute a… G1 Firmware Mitigation only Fix from $2,3002021-04-16 HIGH 7.8 CVE-2021-29449 Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discover… Pi Hole after 5.2.4 Fix from $1,9502021-04-14 CRITICAL 9.8 CVE-2021-27710EPSS 8% Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allo… X5000r Firmware No fix yet Fix from $2,3002021-04-14 CRITICAL 9.8 CVE-2021-27708EPSS 8% Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allo… X5000r Firmware No fix yet Fix from $2,3002021-04-14 HIGH 8.8 CVE-2021-27249EPSS 5% This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi access p… Dap 2020 Firmware Patch available Fix from $1,9502021-04-14 HIGH 8.8 CVE-2021-27252 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. … Br200 Firmware 1.0.0.134 / 1.0.1.60+ Fix from $1,9502021-04-14 CRITICAL 9.8 CVE-2021-27113 An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fu… Dir 816 Firmware No fix yet Fix from $2,3002021-04-14 CRITICAL 9.8 CVE-2020-27227 An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be execute… Openclinic Ga No fix yet Fix from $2,3002021-04-13 CRITICAL 9.8 CVE-2021-29003EPSS 45% Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as… Platinum 4410 Firmware No fix yet Fix from $2,3002021-04-13