Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-78 · OS command injectionDefinition on MITRE ↗Clear

108 results·Page 3 / 3

CVE-2020-25506
2021-11-03
D-Link DNS-320 Device Command Injection Vulnerability
D-Link

D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-16846
2021-11-03
SaltStack Salt Shell Injection Vulnerability
SaltStack

SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-10987
2021-11-03
Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
Tenda

Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-10221
2021-11-03
rConfig OS Command Injection Vulnerability
rConfig

rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-19356
2021-11-03
Netis WF2419 Devices Remote Code Execution Vulnerability
Netis

Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-15949
2021-11-03
Nagios XI Remote Code Execution Vulnerability
Nagios

Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-11539
2021-11-03
Ivanti Pulse Connect Secure and Policy Secure Command Injection VulnerabilityRansomware
Ivanti / Pulse Connect Secure and Pulse Policy Secure

Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-14558
2021-11-03
Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
Tenda

Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
Prev3 / 3Next