Vulnerabilities (CVE)

Filtered by CWE-78
Total 3597 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-20160 1 Trendnet 2 Tew-827dru, Tew-827dru Firmware 2022-07-12 9.0 HIGH 8.8 HIGH
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the device. The username parameter used when configuring smb functionality for the device is vulnerable to command injection as root.
CVE-2021-45979 2 Apple, Foxit 3 Macos, Pdf Editor, Pdf Reader 2022-07-12 6.8 MEDIUM 7.8 HIGH
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.
CVE-2021-24023 1 Fortinet 2 Fortiai 3500f, Fortiai Firmware 2022-07-12 9.0 HIGH 8.8 HIGH
An improper input validation in FortiAI v1.4.0 and earlier may allow an authenticated user to gain system shell access via a malicious payload in the "diagnose" command.
CVE-2021-20173 1 Netgear 2 R6700, R6700 Firmware 2022-07-12 6.5 MEDIUM 8.8 HIGH
Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system update check via the SOAP interface, the device is susceptible to command injection via preconfigured values.
CVE-2020-8816 1 Pi-hole 1 Pi-hole 2022-07-12 6.5 MEDIUM 7.2 HIGH
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
CVE-2021-28958 1 Zohocorp 1 Manageengine Adselfservice Plus 2022-07-12 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
CVE-2021-42324 1 Dcnglobal 2 S4600-10p-si, S4600-10p-si Firmware 2022-07-12 7.2 HIGH 7.4 HIGH
An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authenticated attacker to escape the sandbox environment and execute system commands as root via shell metacharacters in the capture command parameters. Command output will be shown on the Serial interface of the device. Exploitation requires both credentials and physical access.
CVE-2021-26810 1 Dlink 2 Dir-816, Dir-816 Firmware 2022-07-12 10.0 HIGH 9.8 CRITICAL
D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter.
CVE-2021-43164 1 Ruijienetworks 6 Reyeeos, Rg-ew1200, Rg-ew1200g Pro and 3 more 2022-07-12 6.5 MEDIUM 8.8 HIGH
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.
CVE-2014-0156 1 Manageiq 1 Awesomespawn 2022-07-12 7.5 HIGH 9.8 CRITICAL
Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If untrusted input was included in command arguments, attacker could use this flaw to execute arbitrary command.
CVE-2022-31885 1 Marvalglobal 1 Marval Msm 2022-07-08 7.5 HIGH 9.8 CRITICAL
Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
CVE-2022-31767 2 Ibm, Linux 2 Cics Tx, Linux Kernel 2022-07-05 10.0 HIGH 9.8 CRITICAL
IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 227980.
CVE-2022-26147 1 Quectel 2 Rg502q-ea, Rg502q-ea Firmware 2022-06-29 10.0 HIGH 9.8 CRITICAL
The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.
CVE-2021-26541 1 Gitlog Project 1 Gitlog 2022-06-28 7.5 HIGH 9.8 CRITICAL
The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability.
CVE-2021-23374 1 Ps-visitor Project 1 Ps-visitor 2022-06-28 7.5 HIGH 9.8 CRITICAL
This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
CVE-2021-25166 1 Arubanetworks 1 Airwave 2022-06-28 6.5 MEDIUM 8.8 HIGH
A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
CVE-2021-36706 1 Prolink 2 Prc2402m, Prc2402m Firmware 2022-06-28 7.5 HIGH 9.8 CRITICAL
In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a trivial command injection where the value of the command parameter is passed directly to system.
CVE-2021-28927 2 Libretro, Microsoft 2 Retroarch, Windows 2022-06-28 4.6 MEDIUM 7.8 HIGH
The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the accessibility_speak_windows function, which allows attackers who have write access on filesystems that are used by RetroArch to execute code via command injection using specially a crafted file and directory names.
CVE-2021-23378 1 Picotts Project 1 Picotts 2022-06-28 7.5 HIGH 9.8 CRITICAL
This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
CVE-2021-28144 1 Dlink 2 Dir-3060, Dir-3060 Firmware 2022-06-28 9.0 HIGH 8.8 HIGH
prog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context because SetVirtualServerSettings calls CheckArpTables, which calls popen unsafely.