Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2021-1384EPSS 35%
A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remote attacker to inject command…
Ios Xe
16.6.9 / 16.9.7+
CRITICAL 9.9
CVE-2021-21345EPSS 72%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
HIGH 8.8
CVE-2021-23360
This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary com…
Killport
1.0.2+
HIGH 8.8
CVE-2021-28961
applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitra…
Openwrt
Patch available
HIGH 8.8
CVE-2021-23359
This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary c…
Port Killer
No fix yet
CRITICAL 9.8
CVE-2021-23355
This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is possible for an attacker to ex…
Ps Kill
No fix yet
CRITICAL 9.8
CVE-2021-23356
This affects all versions of package kill-process-by-name. If (attacker-controlled) user input is given, it is possible for an attacker to execute ar…
Kill Process By Name
No fix yet
HIGH 8.8
CVE-2021-20017
A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobody' user. …
Sma100 Firmware
after 10.2.0.5
HIGH 8.0
CVE-2021-28143EPSS 46%
/jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (under System Tools).
Dir 841 Firmware
Patch available
HIGH 8.8
CVE-2021-28144EPSS 6%
prog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context bec…
Dir 3060 Firmware
after 1.11b04
CRITICAL 9.8
CVE-2021-28132
LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allow…
Security Awareness
after 4.7.8
MEDIUM 5.6
CVE-2021-24033
react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to be executed.…
React Dev Utils
11.0.4+
HIGH 8.8
CVE-2020-27575
Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrator…
Rumpus
Mitigation only
HIGH 7.8
CVE-2021-21503
PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. The Compadmin user could potentially exploit this …
Emc Powerscale Onefs
Mitigation only
HIGH 8.8
CVE-2021-27256
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. …
Br200 Firmware
1.0.0.134 / 1.0.1.60+
MEDIUM 6.3
CVE-2021-26970
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. V…
Airwave
8.2.12.0+
HIGH 7.2
CVE-2021-26962
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. V…
Airwave
8.2.12.0+
CRITICAL 9.8
CVE-2021-27886EPSS 46%
rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command paramete…
Docker Dashboard
2021-02-28+
CRITICAL 9.8
CVE-2021-26476
EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.
Eprints
Patch available
HIGH 8.8
CVE-2021-26704
EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.
Eprints
Patch available
CRITICAL 9.8
CVE-2021-3342
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI.
Eprints
Patch available
CRITICAL 9.8
CVE-2019-25022
An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over…
Secure Vote
No fix yet
HIGH 7.2
CVE-2021-21302
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by…
Prestashop
1.7.7.2+
CRITICAL 9.8
CVE-2021-20658
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vec…
Sv Cpt Mc310 Firmware
6.5+
HIGH 7.2
CVE-2021-26680
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14…
Clearpass Policy Manager
6.7.14 / 6.8.8+
HIGH 7.2
CVE-2021-26679
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14…
Clearpass Policy Manager
6.7.14 / 6.8.8+
HIGH 7.2
CVE-2021-26681
A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14…
Clearpass Policy Manager
6.7.14 / 6.8.7+
HIGH 7.2
CVE-2021-26683
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14…
Clearpass Policy Manager
6.9.5+
HIGH 7.2
CVE-2021-26684
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14…
Clearpass Policy Manager
6.8.8 / 6.9.5+
CRITICAL 9.8
CVE-2020-28429EPSS 63%
All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JH…
Geojson2kml
No fix yet