Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
HIGH 8.8 CVE-2017-18762 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D3600 before 1.0.0.68, D6000 before 1.0.0.68, … D3600 Firmware 1.0.0.40 / 1.0.0.57+ Fix from $1,9502020-04-22 HIGH 8.8 CVE-2017-18764 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.55, D7000 before 1.0.1.50, … D6100 Firmware 1.0.0.18 / 1.0.0.55+ Fix from $1,9502020-04-22 MEDIUM 6.8 CVE-2017-18767 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, D8500 before 1.0.3.39, R6400 … D7800 Firmware 1.0.0.32 / 1.0.0.56+ Fix from $1,6002020-04-22 MEDIUM 6.8 CVE-2018-21119 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 5.0.5.4 and WAC510 before 5.0.5.4. Wac505 Firmware 5.0.5.4+ Fix from $1,6002020-04-22 HIGH 7.8 CVE-2017-18786 Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JW… D6200 Firmware 1.0.0.20 / 1.0.1.12+ Fix from $1,9502020-04-22 HIGH 7.8 CVE-2017-18787 Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JW… D6200 Firmware 1.0.0.20 / 1.0.1.12+ Fix from $1,9502020-04-22 MEDIUM 6.8 CVE-2018-21112 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44, R7500v2 before 1.0.3.38, R780… D7800 Firmware 1.0.1.44 / 1.0.2.52+ Fix from $1,6002020-04-22 HIGH 8.8 CVE-2018-21113 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.58, D7800 before 1.0.1.42, … D6100 Firmware 1.0.0.58 / 1.0.0.130+ Fix from $1,9502020-04-22 MEDIUM 6.8 CVE-2018-21114 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44, EX6150v2 before 1.0.1.70, EX6… D7800 Firmware 1.0.0.110 / 1.0.1.16+ Fix from $1,6002020-04-22 MEDIUM 6.7 CVE-2017-18773 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6100 before V1.0.0.55, D7800 before V1.0.1.24, EX61… D6100 Firmware 1.0.0.48 / 1.0.0.55+ Fix from $1,6002020-04-22 MEDIUM 6.7 CVE-2017-18788 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D6100 … D3600 Firmware 1.0.0.32 / 1.0.0.44+ Fix from $1,6002020-04-22 MEDIUM 6.8 CVE-2018-21146 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, R7800 before 1.0.2.42, R8900 … D7800 Firmware 1.0.0.54 / 1.0.1.34+ Fix from $1,6002020-04-21 MEDIUM 6.7 CVE-2017-18793 NETGEAR R7800 devices before 1.0.2.36 are affected by command injection. R7800 Firmware 1.0.2.36+ Fix from $1,6002020-04-21 HIGH 8.4 CVE-2017-18794 Certain NETGEAR devices are affected by command injection. This affects R6300v2 before 1.0.4.8_10.0.77, R6400 before 1.0.1.24, R6700 before 1.0.1.26,… R6300 Firmware 1.0.0.32 / 1.0.1.18+ Fix from $1,9502020-04-21 MEDIUM 6.7 CVE-2017-18795 Certain NETGEAR devices are affected by command injection. This affects D6220 before 1.0.0.28 and D6100 before 1.0.0.50_0.0.50. D6220 Firmware 1.0.0.28 / 1.0.0.50_0.0.50+ Fix from $1,6002020-04-21 MEDIUM 6.7 CVE-2017-18796 Certain NETGEAR devices are affected by command injection. This affects R6400 before 1.0.1.24, R6700 before 1.0.1.26, R6900 before 1.0.1.28, R7000 be… R6400 Firmware 1.0.1.16 / 1.0.1.24+ Fix from $1,6002020-04-21 MEDIUM 6.7 CVE-2017-18801 Certain NETGEAR devices are affected by command injection. This affects R6220 before 1.1.0.50, R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, WNDR37… R6220 Firmware 1.0.1.50 / 1.1.0.38+ Fix from $1,6002020-04-21 HIGH 8.4 CVE-2017-18792 NETGEAR D6100 devices before 1.0.0.50_0.0.50 are affected by command injection. D6100 Firmware 1.0.0.50_0.0.50+ Fix from $1,9502020-04-21 MEDIUM 6.7 CVE-2017-18802 Certain NETGEAR devices are affected by command injection. This affects R6100 before 1.0.1.14, R7500 before 1.0.0.110, R7500v2 before 1.0.3.16, R7800… R6100 Firmware 1.0.0.110 / 1.0.1.14+ Fix from $1,6002020-04-21 MEDIUM 6.7 CVE-2017-18804 Certain NETGEAR devices are affected by command injection. This affects R7800 before 1.0.2.16 and R9000 before 1.0.2.4. R7800 Firmware 1.0.2.4 / 1.0.2.16+ Fix from $1,6002020-04-21 MEDIUM 6.7 CVE-2017-18805 Certain NETGEAR devices are affected by command injection. This affects WAC510 before 1.3.0.10, WAC120 before 2.1.4, WNDAP620 before 2.1.3, WND930 be… Wac510 Firmware 1.3.0.10 / 2.1.2+ Fix from $1,6002020-04-21 MEDIUM 6.7 CVE-2017-18806 Certain NETGEAR devices are affected by command injection. This affects WAC510 before 1.3.0.10, WAC120 before 2.1.4, WNDAP620 before 2.1.3, WND930 be… Wac510 Firmware 1.3.0.10 / 2.1.2+ Fix from $1,6002020-04-21 MEDIUM 6.7 CVE-2017-18841 Certain NETGEAR devices are affected by command injection. This affects R6220 before 1.1.0.46, R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, WNDR37… R6220 Firmware 1.0.1.50 / 1.1.0.38+ Fix from $1,6002020-04-20 HIGH 7.8 CVE-2017-18849 Certain NETGEAR devices are affected by command injection. This affects D6220 before 1.0.0.26, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 be… D6220 Firmware 1.0.0.26 / 1.0.0.56+ Fix from $1,9502020-04-20 MEDIUM 6.7 CVE-2017-18851 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D8500 through 1.0.3.28, R6400 through 1.0.1.22, R640… D8500 Firmware 1.0.1.12 / 1.0.1.22+ Fix from $1,6002020-04-20 HIGH 7.2 CVE-2020-7111 A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Code Execution in ClearPass. Re… Clearpass 6.7.13 / 6.8.4+ Fix from $1,9502020-04-16 MEDIUM 5.4 CVE-2020-11814 A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious websites. Qdpm No fix yet Fix from $1,6002020-04-16 HIGH 7.5 CVE-2020-11709 cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for C… Cpp Httplib after 0.5.8 Fix from $1,9502020-04-12 HIGH 7.5 CVE-2020-11703 An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response Splitting via the language p… Provide Ftp Server after 13.1 Fix from $1,9502020-04-12 HIGH 8.8 CVE-2020-11002EPSS 5% dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in … Dropwizard Validation 1.3.21 / 2.0.3+ Fix from $1,9502020-04-10