Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2021-26724
OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated adm…
Central Management Control
19.0.12 / 20.0.7.4+
HIGH 7.2
CVE-2021-3149
On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authentication by the attacker) bec…
Nano 25 Firmware
Mitigation only
HIGH 7.8
CVE-2020-36246
Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link.
Amaze File Manager
3.5.1+
CRITICAL 9.8
CVE-2019-25024EPSS 28%
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service paramet…
Openrepeater
2.2+
CRITICAL 9.8
CVE-2021-26747EPSS 54%
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
Wf2780 Firmware
No fix yet
CRITICAL 9.8
CVE-2020-28490
The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKED…
Async Git
1.13.2+
HIGH 7.8
CVE-2020-29664
A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious fi…
Mavic 2 Firmware
01.00.0510+
HIGH 7.2
CVE-2021-20655
FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary OS commands via unspecified v…
Filezen
after 5.0.2
HIGH 7.8
CVE-2021-27102 KEV
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
Fta
after 9_12_411
CRITICAL 9.8
CVE-2021-27104 KEVEPSS 56%
Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FT…
Fta
after 9_12_370
HIGH 8.8
CVE-2021-20074
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and execute arbitrary OS commands.
M\!dge Firmware
Mitigation only
HIGH 7.8
CVE-2021-21315 KEVEPSS 91%
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,…
Cordova
5.3.1+
HIGH 8.8
CVE-2021-27201
Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup com…
Firewall Community
No fix yet
HIGH 8.8
CVE-2020-24899EPSS 17%
Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into normal webapp q…
Nagios Xi
No fix yet
HIGH 8.8
CVE-2021-25297 KEVEPSS 56%
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/…
Nagios Xi
after 5.7.5
HIGH 8.8
CVE-2021-25298 KEVEPSS 75%
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/…
Nagios Xi
after 5.7.5
HIGH 8.8
CVE-2021-26752
NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the …
Nedi
No fix yet
MEDIUM 6.8
CVE-2021-20648
ELECOM WRC-300FEBK-S allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
Wrc 300febk S Firmware
Mitigation only
MEDIUM 6.8
CVE-2021-20638
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.
Lan W300n\/pgrb Firmware
Mitigation only
MEDIUM 6.8
CVE-2021-20639
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.
Lan W300n\/pgrb Firmware
Mitigation only
HIGH 8.8
CVE-2020-27861
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi 2.5.1.16 routers. Authentica…
Cbk40 Firmware
1.0.0.210 / 1.0.1.82+
HIGH 7.2
CVE-2021-21976
vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication c…
Vsphere Replication
6.5.1.5 / 8.1.2.3+
CRITICAL 9.1
CVE-2021-21018
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the scheduled operati…
Magento
2.3.6+
HIGH 8.0
CVE-2021-21015
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attri…
Magento
2.3.6+
CRITICAL 9.1
CVE-2021-21016
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successfu…
Magento
2.3.6+
HIGH 7.8
CVE-2020-26193
Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability. A user with the ISI_PRIV_CLUSTER privilege may e…
Emc Powerscale Onefs
Mitigation only
CRITICAL 9.8
CVE-2021-22502 KEVEPSS 97%
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be explo…
Operation Bridge Reporter
Mitigation only
CRITICAL 9.8
CVE-2020-7785
This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js.
Node Ps
No fix yet
CRITICAL 9.8
CVE-2020-7786
This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js.
Macfromip
No fix yet
CRITICAL 9.8
CVE-2020-7782
This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 i…
Spritesheet Js
No fix yet