Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2021-26724 OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated adm… Central Management Control 19.0.12 / 20.0.7.4+ Fix from $1,9502021-02-22 HIGH 7.2 CVE-2021-3149 On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authentication by the attacker) bec… Nano 25 Firmware Mitigation only Fix from $1,9502021-02-22 HIGH 7.8 CVE-2020-36246 Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link. Amaze File Manager 3.5.1+ Fix from $1,9502021-02-19 CRITICAL 9.8 CVE-2019-25024EPSS 28% OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service paramet… Openrepeater 2.2+ Fix from $2,3002021-02-19 CRITICAL 9.8 CVE-2021-26747EPSS 54% Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution. Wf2780 Firmware No fix yet Fix from $2,3002021-02-18 CRITICAL 9.8 CVE-2020-28490 The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKED… Async Git 1.13.2+ Fix from $2,3002021-02-18 HIGH 7.8 CVE-2020-29664 A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious fi… Mavic 2 Firmware 01.00.0510+ Fix from $1,9502021-02-18 HIGH 7.2 CVE-2021-20655 FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary OS commands via unspecified v… Filezen after 5.0.2 Fix from $1,9502021-02-17 HIGH 7.8 CVE-2021-27102 KEV Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later. Fta after 9_12_411 Fix from $1,9502021-02-16 CRITICAL 9.8 CVE-2021-27104 KEVEPSS 56% Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FT… Fta after 9_12_370 Fix from $2,3002021-02-16 HIGH 8.8 CVE-2021-20074 Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and execute arbitrary OS commands. M\!dge Firmware Mitigation only Fix from $1,9502021-02-16 HIGH 7.8 CVE-2021-21315 KEVEPSS 91% The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,… Cordova 5.3.1+ Fix from $1,9502021-02-16 HIGH 8.8 CVE-2021-27201 Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup com… Firewall Community No fix yet Fix from $1,9502021-02-15 HIGH 8.8 CVE-2020-24899EPSS 17% Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into normal webapp q… Nagios Xi No fix yet Fix from $1,9502021-02-15 HIGH 8.8 CVE-2021-25297 KEVEPSS 56% Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/… Nagios Xi after 5.7.5 Fix from $1,9502021-02-15 HIGH 8.8 CVE-2021-25298 KEVEPSS 75% Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/… Nagios Xi after 5.7.5 Fix from $1,9502021-02-15 HIGH 8.8 CVE-2021-26752 NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the … Nedi No fix yet Fix from $1,9502021-02-12 MEDIUM 6.8 CVE-2021-20648 ELECOM WRC-300FEBK-S allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors. Wrc 300febk S Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.8 CVE-2021-20638 LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors. Lan W300n\/pgrb Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.8 CVE-2021-20639 LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors. Lan W300n\/pgrb Firmware Mitigation only Fix from $1,6002021-02-12 HIGH 8.8 CVE-2020-27861 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi 2.5.1.16 routers. Authentica… Cbk40 Firmware 1.0.0.210 / 1.0.1.82+ Fix from $1,9502021-02-12 HIGH 7.2 CVE-2021-21976 vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication c… Vsphere Replication 6.5.1.5 / 8.1.2.3+ Fix from $1,9502021-02-11 CRITICAL 9.1 CVE-2021-21018 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the scheduled operati… Magento 2.3.6+ Fix from $2,3002021-02-11 HIGH 8.0 CVE-2021-21015 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attri… Magento 2.3.6+ Fix from $1,9502021-02-11 CRITICAL 9.1 CVE-2021-21016 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successfu… Magento 2.3.6+ Fix from $2,3002021-02-11 HIGH 7.8 CVE-2020-26193 Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability. A user with the ISI_PRIV_CLUSTER privilege may e… Emc Powerscale Onefs Mitigation only Fix from $1,9502021-02-09 CRITICAL 9.8 CVE-2021-22502 KEVEPSS 97% Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be explo… Operation Bridge Reporter Mitigation only Fix from $2,3002021-02-08 CRITICAL 9.8 CVE-2020-7785 This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js. Node Ps No fix yet Fix from $2,3002021-02-08 CRITICAL 9.8 CVE-2020-7786 This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js. Macfromip No fix yet Fix from $2,3002021-02-08 CRITICAL 9.8 CVE-2020-7782 This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 i… Spritesheet Js No fix yet Fix from $2,3002021-02-08