Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2021-26541EPSS 5% The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability. Gitlog 4.0.4+ Fix from $2,3002021-02-08 CRITICAL 9.8 CVE-2020-11920 An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in the HOST/IP section of the NFS… Siime Eye Firmware No fix yet Fix from $2,3002021-02-08 HIGH 8.8 CVE-2020-36243EPSS 64% The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, a… Openemr Patch available Fix from $1,9502021-02-07 CRITICAL 9.8 CVE-2021-3122EPSS 87% CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to p… Command Center Agent Mitigation only Fix from $2,3002021-02-07 HIGH 7.8 CVE-2021-1370 A vulnerability in a CLI command of Cisco IOS XR Software for the Cisco 8000 Series Routers and Network Convergence System 540 Series Routers running… Ios Xr 7.0.12 / 7.2.1+ Fix from $1,9502021-02-04 HIGH 7.2 CVE-2021-1315 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al… Rv016 Multi Wan Vpn Router Firmware after 4.2.3.14 Fix from $1,9502021-02-04 HIGH 7.2 CVE-2021-1316 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al… Rv016 Multi Wan Vpn Router Firmware after 4.2.3.14 Fix from $1,9502021-02-04 HIGH 7.2 CVE-2021-1317 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al… Rv016 Multi Wan Vpn Router Firmware after 4.2.3.14 Fix from $1,9502021-02-04 HIGH 7.2 CVE-2021-1318 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al… Rv016 Multi Wan Vpn Router Firmware after 4.2.3.14 Fix from $1,9502021-02-04 HIGH 7.2 CVE-2021-1314 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al… Rv016 Multi Wan Vpn Router Firmware after 4.2.3.14 Fix from $1,9502021-02-04 CRITICAL 9.8 CVE-2020-2507 The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attacke… Helpdesk 3.0.3+ Fix from $2,3002021-02-03 HIGH 8.3 CVE-2021-21289 Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is… Mechanize 2.7.7+ Fix from $1,9502021-02-02 CRITICAL 9.8 CVE-2020-7775 This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments in line 71 of freediskspace.… Freediskproject Mitigation only Fix from $2,3002021-02-02 HIGH 8.8 CVE-2021-25310 The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system co… Linksys Wrt160nl Firmware No fix yet Fix from $1,9502021-02-02 CRITICAL 9.8 CVE-2020-18568EPSS 15% The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution. Dsr 250 Firmware No fix yet Fix from $2,3002021-02-02 CRITICAL 9.8 CVE-2020-25506 KEVEPSS 100% D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code exec… Dns 320 Firmware Mitigation only Fix from $2,3002021-02-02 HIGH 8.6 CVE-2020-28494 This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build th… Total.js 3.4.7+ Fix from $1,9502021-02-02 HIGH 8.8 CVE-2020-25036 UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, and access a shell with admin u… Ucopia Wireless Appliance after 6.0.5 Fix from $1,9502021-02-02 HIGH 7.3 CVE-2020-28426 All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId. Kill Process On Port No fix yet Fix from $1,9502021-02-01 CRITICAL 9.8 CVE-2021-23330EPSS 5% All versions of package launchpad are vulnerable to Command Injection via stop. Launchpad Patch available Fix from $2,3002021-02-01 HIGH 8.8 CVE-2020-5626 Logstorage version 8.0.0 and earlier, and ELC Analytics version 3.0.0 and earlier allow remote attackers to execute arbitrary OS commands via a speci… Elc Analytics after 8.0.0 Fix from $1,9502021-01-28 HIGH 8.8 CVE-2021-3317EPSS 41% KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter. Klog Server after 2.4.1 Fix from $1,9502021-01-26 CRITICAL 9.8 CVE-2013-2512 The ftpd gem 0.2.1 for Ruby allows remote attackers to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command argument with… Ftpd No fix yet Fix from $2,3002021-01-26 HIGH 7.2 CVE-2021-3291EPSS 17% Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting… Zen Cart No fix yet Fix from $1,9502021-01-26 CRITICAL 9.8 CVE-2021-3190EPSS 5% The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag. Async Git 1.13.2+ Fix from $2,3002021-01-26 CRITICAL 9.8 CVE-2020-36199 TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places. Tinycheck 2020-12-18+ Fix from $2,3002021-01-26 HIGH 8.8 CVE-2020-35576EPSS 42% A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users t… Tl Wr841n Firmware 201216+ Fix from $1,9502021-01-26 MEDIUM 6.8 CVE-2020-27542 Rostelecom CS-C2SHW 5.0.082.1 is affected by: Bash command injection. The camera reads configuration from QR code (including network settings). The s… Cs C2shw Firmware No fix yet Fix from $1,6002021-01-26 MEDIUM 6.5 CVE-2020-27298 Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), V… Coronary Tools Mitigation only Fix from $1,6002021-01-26 HIGH 8.8 CVE-2020-23826EPSS 13% The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This ma… Yale Wipc 303w Firmware after 2.31 Fix from $1,9502021-01-26