Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Smart Camera C2e Firmware HIGH 7.2
CVE-2021-3617

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted network configu…

Fix: 01.03.29.16+
Fix from $1,950 2021-08-17
Emc Powerscale Onefs MEDIUM 6.7
CVE-2021-21595

Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability c…

Fix: 9.2.0+
Fix from $1,600 2021-08-16
Shopware CRITICAL 9.8
CVE-2021-37708

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.…

Fix: 6.4.3.1+
Fix from $2,300 2021-08-16
Connect Secure HIGH 7.2
CVE-2021-22935

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web …

Fix: 9.1+
Fix from $1,950 2021-08-16
Connect Secure HIGH 7.2
CVE-2021-22938

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web …

Fix: 9.1+
Fix from $1,950 2021-08-16
Mac1100 Plc Firmware CRITICAL 9.8
CVE-2020-18758

An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2021-08-13
Rbk40 Firmware CRITICAL 9.8
CVE-2021-38530

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, …

Fix: 2.5.1.16+
Fix from $2,300 2021-08-11
D7800 Firmware CRITICAL 9.8
CVE-2021-38529

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, …

Fix: 1.0.1.56 / 1.0.2.68+
Fix from $2,300 2021-08-11
D8500 Firmware CRITICAL 9.8
CVE-2021-38528

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6900P before 1.3.2.132…

Fix: 1.0.0.64 / 1.0.1.38+
Fix from $2,300 2021-08-11
Cbr40 Firmware CRITICAL 9.8
CVE-2021-38527

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.14, EX6100v2 before 1.0.1.9…

Fix: 1.0.0.132 / 1.0.1.98+
Fix from $2,300 2021-08-11
R6400 Firmware HIGH 7.2
CVE-2021-38521

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.50, R7900P before 1.4.1.50, R8000…

Fix: 1.0.1.50 / 1.0.1.62+
Fix from $1,950 2021-08-11
R6400 Firmware HIGH 7.2
CVE-2021-38520

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, R6400v2 before 1.0.4.84, R670…

Fix: 1.0.1.52 / 1.0.4.84+
Fix from $1,950 2021-08-11
R6250 Firmware HIGH 7.2
CVE-2021-38519

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, R6300v2 before 1.0.4.36, R640…

Fix: 1.0.1.50 / 1.0.2.8+
Fix from $1,950 2021-08-11
Rax200 Firmware HIGH 7.2
CVE-2021-38518

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120, RAX75 before 1.0.4.120, RAX…

Fix: 1.0.4.120 / 3.2.17.12+
Fix from $1,950 2021-08-11
Alpine MEDIUM 5.9
CVE-2021-38370

In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.

Fix: 2.25+
Fix from $1,600 2021-08-10
Kmail MEDIUM 5.3
CVE-2021-38373

In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" …

Mitigation only
Fix from $1,600 2021-08-10
Syncpool HIGH 8.1
CVE-2020-36462

An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send for Bucket2.

Fix: 0.1.6+
Fix from $1,950 2021-08-08
Multiqueue HIGH 8.1
CVE-2020-36463

An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of Send for InnerSend<RW, T>, In…

Fix: after 2020-12-25
Fix from $1,950 2021-08-08
Lettre CRITICAL 9.8
CVE-2021-38189

An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two <CR><LF> …

Fix: 0.9.6+
Fix from $2,300 2021-08-08
Cache HIGH 8.1
CVE-2020-36448

An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for Cache<K>.

Fix: after 2020-11-24
Fix from $1,950 2021-08-08
Kekbit HIGH 8.1
CVE-2020-36449

An issue was discovered in the kekbit crate before 0.3.4 for Rust. For ShmWriter<H>, Send is implemented without requiring H: Send.

Fix: 0.3.4+
Fix from $1,950 2021-08-08
Bunch HIGH 8.1
CVE-2020-36450

An issue was discovered in the bunch crate through 2020-11-12 for Rust. There are unconditional implementations of Send and Sync for Bunch<T>.

Fix: after 2020-11-12
Fix from $1,950 2021-08-08
Rcu Cell HIGH 8.1
CVE-2020-36451

An issue was discovered in the rcu_cell crate through 2020-11-14 for Rust. There are unconditional implementations of Send and Sync for RcuCell<T>.

Fix: after 2020-11-14
Fix from $1,950 2021-08-08
Slock HIGH 8.1
CVE-2020-36455

An issue was discovered in the slock crate through 2020-11-17 for Rust. Slock<T> unconditionally implements Send and Sync.

Fix: after 2020-11-17
Fix from $1,950 2021-08-08
Toolshed HIGH 8.1
CVE-2020-36456

An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell<T>, the Send trait lacks bounds on the contained type.

Fix: after 2020-11-15
Fix from $1,950 2021-08-08
Lever HIGH 8.1
CVE-2020-36457

An issue was discovered in the lever crate before 0.1.1 for Rust. AtomicBox<T> implements the Send and Sync traits for all types T.

Patch available
Fix from $1,950 2021-08-08
Dces HIGH 8.1
CVE-2020-36459

An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds on its EntityStore and Compo…

Fix: after 2020-12-09
Fix from $1,950 2021-08-08
Noise Search HIGH 8.1
CVE-2020-36461

An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync for MvccRwLoc…

Fix: after 2020-12-10
Fix from $1,950 2021-08-08
Debian Linux CRITICAL 9.8
CVE-2021-38173

Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorize…

Fix: 0.31.2+
Fix from $2,300 2021-08-07
Roxy Wi HIGH 8.8
CVE-2021-38169

Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.

Fix: after 5.2.2.0
Fix from $1,950 2021-08-07