systeminformation records
12 published records for vendor systeminformation.
Researcher profile
- Entered KEV
- 1 · 8.3%
- Weaponized
- 1 · 8.3%
- Pre-auth RCE
- 6
- With a fix record
- 100%
- Median publish → KEV
- 336 days
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')9
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
88Now | CVE-2021-21315Weaponized | Command Injection Vulnerabilitysysteminformation · systeminformation · CWE-78 | High7.8 | KEV | 90.7% | Feb 16, 2021 |
40Plan | CVE-2020-26245No exploit | Prototype Pollution leading to Command Injection in systeminformationsysteminformation · systeminformation · CWE-78 | Critical9.8 | — | 2.2% | Nov 27, 2020 |
40Plan | CVE-2023-42810No exploit | systeminformation SSID Command Injection Vulnerabilitysysteminformation · systeminformation · CWE-77 | Critical9.8 | — | 2.2% | Sep 21, 2023 |
40Plan | CVE-2021-21388No exploit | Command Injection Vulnerability in systeminformationsysteminformation · systeminformation · CWE-20 | Critical9.8 | — | 1.9% | Apr 29, 2021 |
39Monitor | CVE-2020-26300No exploit | Command injection in systeminformationsysteminformation · systeminformation · CWE-77 | Critical9.8 | — | 1.4% | Sep 8, 2021 |
37Monitor | CVE-2020-7752No exploit | This affects the package systeminformation before 4.27.11.systeminformation · systeminformation · CWE-78 | High8.8 | — | 6.7% | Oct 26, 2020 |
36Monitor | CVE-2025-68154No exploit | Command Injection in fsSize() on Windowssysteminformation · systeminformation · CWE-78 | High8.1 | — | 13.0% | Dec 16, 2025 |
36Monitor | CVE-2020-26274No exploit | Command Injection Vulnerability in systeminformationsysteminformation · systeminformation · CWE-78 | High8.8 | — | 2.7% | Dec 16, 2020 |
35Monitor | CVE-2026-50289No exploit | systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linuxsysteminformation · systeminformation · CWE-78 | High8.7 | — | 3.6% | Jul 17, 2026 |
35Monitor | CVE-2026-26318No exploit | systeminformation has Command Injection via Unsanitized `locate` Output in `versions()`systeminformation · systeminformation · CWE-78 | High8.8 | — | 1.3% | Feb 19, 2026 |
31Monitor | CVE-2026-26280No exploit | Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry pathsysteminformation · systeminformation · CWE-78 | High7.8 | — | 1.5% | Feb 19, 2026 |
30Monitor | CVE-2020-7778No exploit | This affects the package systeminformation before 4.30.2.systeminformation · systeminformation · CWE-78 | High7.3 | — | 2.4% | Nov 26, 2020 |
- CVE-2021-2131588Now
Command Injection Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 91%systeminformation · systeminformationFeb 16, 2021
- CVE-2020-2624540Plan
Prototype Pollution leading to Command Injection in systeminformation
CriticalCVSS 9.8No exploitEPSS 2%systeminformation · systeminformationNov 27, 2020
- CVE-2023-4281040Plan
systeminformation SSID Command Injection Vulnerability
CriticalCVSS 9.8No exploitEPSS 2%systeminformation · systeminformationSep 21, 2023
- CVE-2021-2138840Plan
Command Injection Vulnerability in systeminformation
CriticalCVSS 9.8No exploitEPSS 2%systeminformation · systeminformationApr 29, 2021
- CVE-2020-2630039Monitor
Command injection in systeminformation
CriticalCVSS 9.8No exploitEPSS 1%systeminformation · systeminformationSep 8, 2021
- CVE-2020-775237Monitor
This affects the package systeminformation before 4.27.11.
HighCVSS 8.8No exploitEPSS 7%systeminformation · systeminformationOct 26, 2020
- CVE-2025-6815436Monitor
Command Injection in fsSize() on Windows
HighCVSS 8.1No exploitEPSS 13%systeminformation · systeminformationDec 16, 2025
- CVE-2020-2627436Monitor
Command Injection Vulnerability in systeminformation
HighCVSS 8.8No exploitEPSS 3%systeminformation · systeminformationDec 16, 2020
- CVE-2026-5028935Monitor
systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux
HighCVSS 8.7No exploitEPSS 4%systeminformation · systeminformationJul 17, 2026
- CVE-2026-2631835Monitor
systeminformation has Command Injection via Unsanitized `locate` Output in `versions()`
HighCVSS 8.8No exploitEPSS 1%systeminformation · systeminformationFeb 19, 2026
- CVE-2026-2628031Monitor
Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry path
HighCVSS 7.8No exploitEPSS 1%systeminformation · systeminformationFeb 19, 2026
- CVE-2020-777830Monitor
This affects the package systeminformation before 4.30.2.
HighCVSS 7.3No exploitEPSS 2%systeminformation · systeminformationNov 26, 2020