Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-26541EPSS 5%
The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability.
Gitlog
4.0.4+
CRITICAL 9.8
CVE-2020-11920
An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in the HOST/IP section of the NFS…
Siime Eye Firmware
No fix yet
HIGH 8.8
CVE-2020-36243EPSS 64%
The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, a…
Openemr
Patch available
CRITICAL 9.8
CVE-2021-3122EPSS 87%
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to p…
Command Center Agent
Mitigation only
HIGH 7.8
CVE-2021-1370
A vulnerability in a CLI command of Cisco IOS XR Software for the Cisco 8000 Series Routers and Network Convergence System 540 Series Routers running…
Ios Xr
7.0.12 / 7.2.1+
HIGH 7.2
CVE-2021-1315
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…
Rv016 Multi Wan Vpn Router Firmware
after 4.2.3.14
HIGH 7.2
CVE-2021-1316
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…
Rv016 Multi Wan Vpn Router Firmware
after 4.2.3.14
HIGH 7.2
CVE-2021-1317
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…
Rv016 Multi Wan Vpn Router Firmware
after 4.2.3.14
HIGH 7.2
CVE-2021-1318
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…
Rv016 Multi Wan Vpn Router Firmware
after 4.2.3.14
HIGH 7.2
CVE-2021-1314
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…
Rv016 Multi Wan Vpn Router Firmware
after 4.2.3.14
CRITICAL 9.8
CVE-2020-2507
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attacke…
Helpdesk
3.0.3+
HIGH 8.3
CVE-2021-21289
Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is…
Mechanize
2.7.7+
CRITICAL 9.8
CVE-2020-7775
This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments in line 71 of freediskspace.…
Freediskproject
Mitigation only
HIGH 8.8
CVE-2021-25310
The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system co…
Linksys Wrt160nl Firmware
No fix yet
CRITICAL 9.8
CVE-2020-18568EPSS 15%
The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution.
Dsr 250 Firmware
No fix yet
CRITICAL 9.8
CVE-2020-25506 KEVEPSS 100%
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code exec…
Dns 320 Firmware
Mitigation only
HIGH 8.6
CVE-2020-28494
This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build th…
Total.js
3.4.7+
HIGH 8.8
CVE-2020-25036
UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, and access a shell with admin u…
Ucopia Wireless Appliance
after 6.0.5
HIGH 7.3
CVE-2020-28426
All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId.
Kill Process On Port
No fix yet
CRITICAL 9.8
CVE-2021-23330EPSS 5%
All versions of package launchpad are vulnerable to Command Injection via stop.
Launchpad
Patch available
HIGH 8.8
CVE-2020-5626
Logstorage version 8.0.0 and earlier, and ELC Analytics version 3.0.0 and earlier allow remote attackers to execute arbitrary OS commands via a speci…
Elc Analytics
after 8.0.0
HIGH 8.8
CVE-2021-3317EPSS 41%
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter.
Klog Server
after 2.4.1
CRITICAL 9.8
CVE-2013-2512
The ftpd gem 0.2.1 for Ruby allows remote attackers to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command argument with…
Ftpd
No fix yet
HIGH 7.2
CVE-2021-3291EPSS 17%
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting…
Zen Cart
No fix yet
CRITICAL 9.8
CVE-2021-3190EPSS 5%
The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.
Async Git
1.13.2+
CRITICAL 9.8
CVE-2020-36199
TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.
Tinycheck
2020-12-18+
HIGH 8.8
CVE-2020-35576EPSS 42%
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users t…
Tl Wr841n Firmware
201216+
MEDIUM 6.8
CVE-2020-27542
Rostelecom CS-C2SHW 5.0.082.1 is affected by: Bash command injection. The camera reads configuration from QR code (including network settings). The s…
Cs C2shw Firmware
No fix yet
MEDIUM 6.5
CVE-2020-27298
Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), V…
Coronary Tools
Mitigation only
HIGH 8.8
CVE-2020-23826EPSS 13%
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This ma…
Yale Wipc 303w Firmware
after 2.31