Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2021-1384EPSS 35% A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remote attacker to inject command… Ios Xe 16.6.9 / 16.9.7+ Fix from $1,9502021-03-24 CRITICAL 9.9 CVE-2021-21345EPSS 72% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 HIGH 8.8 CVE-2021-23360 This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary com… Killport 1.0.2+ Fix from $1,9502021-03-21 HIGH 8.8 CVE-2021-28961 applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitra… Openwrt Patch available Fix from $1,9502021-03-21 HIGH 8.8 CVE-2021-23359 This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary c… Port Killer No fix yet Fix from $1,9502021-03-18 CRITICAL 9.8 CVE-2021-23355 This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is possible for an attacker to ex… Ps Kill No fix yet Fix from $2,3002021-03-15 CRITICAL 9.8 CVE-2021-23356 This affects all versions of package kill-process-by-name. If (attacker-controlled) user input is given, it is possible for an attacker to execute ar… Kill Process By Name No fix yet Fix from $2,3002021-03-15 HIGH 8.8 CVE-2021-20017 A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobody' user. … Sma100 Firmware after 10.2.0.5 Fix from $1,9502021-03-13 HIGH 8.0 CVE-2021-28143EPSS 46% /jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (under System Tools). Dir 841 Firmware Patch available Fix from $1,9502021-03-11 HIGH 8.8 CVE-2021-28144EPSS 6% prog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context bec… Dir 3060 Firmware after 1.11b04 Fix from $1,9502021-03-11 CRITICAL 9.8 CVE-2021-28132 LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allow… Security Awareness after 4.7.8 Fix from $2,3002021-03-11 MEDIUM 5.6 CVE-2021-24033 react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to be executed.… React Dev Utils 11.0.4+ Fix from $1,6002021-03-09 HIGH 8.8 CVE-2020-27575 Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrator… Rumpus Mitigation only Fix from $1,9502021-03-08 HIGH 7.8 CVE-2021-21503 PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. The Compadmin user could potentially exploit this … Emc Powerscale Onefs Mitigation only Fix from $1,9502021-03-08 HIGH 8.8 CVE-2021-27256 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. … Br200 Firmware 1.0.0.134 / 1.0.1.60+ Fix from $1,9502021-03-05 MEDIUM 6.3 CVE-2021-26970 A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. V… Airwave 8.2.12.0+ Fix from $1,6002021-03-05 HIGH 7.2 CVE-2021-26962 A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. V… Airwave 8.2.12.0+ Fix from $1,9502021-03-05 CRITICAL 9.8 CVE-2021-27886EPSS 46% rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command paramete… Docker Dashboard 2021-02-28+ Fix from $2,3002021-03-02 CRITICAL 9.8 CVE-2021-26476 EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI. Eprints Patch available Fix from $2,3002021-03-01 HIGH 8.8 CVE-2021-26704 EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI. Eprints Patch available Fix from $1,9502021-03-01 CRITICAL 9.8 CVE-2021-3342 EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI. Eprints Patch available Fix from $2,3002021-03-01 CRITICAL 9.8 CVE-2019-25022 An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over… Secure Vote No fix yet Fix from $2,3002021-02-27 HIGH 7.2 CVE-2021-21302 PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by… Prestashop 1.7.7.2+ Fix from $1,9502021-02-26 CRITICAL 9.8 CVE-2021-20658 SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vec… Sv Cpt Mc310 Firmware 6.5+ Fix from $2,3002021-02-24 HIGH 7.2 CVE-2021-26680 A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14… Clearpass Policy Manager 6.7.14 / 6.8.8+ Fix from $1,9502021-02-23 HIGH 7.2 CVE-2021-26679 A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14… Clearpass Policy Manager 6.7.14 / 6.8.8+ Fix from $1,9502021-02-23 HIGH 7.2 CVE-2021-26681 A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14… Clearpass Policy Manager 6.7.14 / 6.8.7+ Fix from $1,9502021-02-23 HIGH 7.2 CVE-2021-26683 A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14… Clearpass Policy Manager 6.9.5+ Fix from $1,9502021-02-23 HIGH 7.2 CVE-2021-26684 A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14… Clearpass Policy Manager 6.8.8 / 6.9.5+ Fix from $1,9502021-02-23 CRITICAL 9.8 CVE-2020-28429EPSS 63% All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JH… Geojson2kml No fix yet Fix from $2,3002021-02-23