Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Rbk852 Firmware CRITICAL 9.0
CVE-2021-29071

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RB…

Fix: 3.2.17.12+
Fix from $2,300 2021-03-23
Rbk852 Firmware HIGH 8.4
CVE-2021-29072

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RB…

Fix: 3.2.17.12+
Fix from $1,950 2021-03-23
Rbk852 Firmware CRITICAL 9.6
CVE-2021-29076

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.…

Fix: 3.2.17.12+
Fix from $2,300 2021-03-23
Eslint Fixer CRITICAL 9.8
CVE-2021-26275

The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability on…

Fix: after 0.1.5
Fix from $2,300 2021-03-19
Fs Path CRITICAL 9.8
CVE-2020-8298EPSS 11%

fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `remove…

Fix: 0.0.25+
Fix from $2,300 2021-03-04
GitHub HIGH 8.8
CVE-2020-10519

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-cont…

Fix: 2.20.24 / 2.21.15+
Fix from $1,950 2021-03-03
Fedora CRITICAL 9.8
CVE-2021-3148EPSS 8%

An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() comman…

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2021-02-27
Fedora HIGH 7.8
CVE-2020-28243

An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. Thi…

Fix: 2015.8.10 / 2015.8.13+
Fix from $1,950 2021-02-27
C200 Firmware HIGH 8.0
CVE-2020-7848

The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attac…

Mitigation only
Fix from $1,950 2021-02-17
Dva 2800 Firmware HIGH 8.8
CVE-2020-27862

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2800 and DSL-2888A routers. Au…

Mitigation only
Fix from $1,950 2021-02-12
Dap 1860 Firmware HIGH 8.8
CVE-2020-27864EPSS 10%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 …

Fix: after 1.04b03
Fix from $1,950 2021-02-12
Ac2100 Firmware MEDIUM 6.8
CVE-2020-27867

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260…

Fix: 1.2.0.76+
Fix from $1,600 2021-02-12
Samba Client CRITICAL 9.8
CVE-2021-27185

The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.

Fix: 4.0.0+
Fix from $2,300 2021-02-10
Wn575a4 Firmware CRITICAL 9.8
CVE-2020-13117EPSS 69%

Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a lo…

Fix: after 2020-05-15
Fix from $2,300 2021-02-09
Baseboard Management Controller HIGH 7.8
CVE-2021-26576

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.…

Fix: 3.0.14.0+
Fix from $1,950 2021-02-08
Baseboard Management Controller HIGH 7.8
CVE-2021-25172

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.…

Fix: 3.0.14.0+
Fix from $1,950 2021-02-08
Helpdesk CRITICAL 9.8
CVE-2020-2507

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attacke…

Fix: 3.0.3+
Fix from $2,300 2021-02-03
Android MEDIUM 6.7
CVE-2021-0363

In mobile_log_d, there is a possible command injection due to a missing bounds check. This could lead to local escalation of privilege with System ex…

Mitigation only
Fix from $1,600 2021-02-03
Android MEDIUM 6.7
CVE-2021-0364

In mobile_log_d, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System…

Mitigation only
Fix from $1,600 2021-02-03
Android MEDIUM 6.7
CVE-2021-0356

In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System exec…

Mitigation only
Fix from $1,600 2021-02-03
Android MEDIUM 6.7
CVE-2021-0358

In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System exec…

Mitigation only
Fix from $1,600 2021-02-03
Lifeshield Diy Hd Video Doorbell Firmware HIGH 8.8
CVE-2020-8101

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of ADT LifeShield DIY HD Video Do…

Fix: after 1.0.02r09
Fix from $1,950 2021-02-02
Sd Wan Firmware HIGH 8.8
CVE-2021-1298

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected devi…

Mitigation only
Fix from $1,950 2021-01-20
Sd Wan Firmware HIGH 8.8
CVE-2021-1299

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected devi…

Mitigation only
Fix from $1,950 2021-01-20
Sd Wan Firmware HIGH 7.8
CVE-2021-1263

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected devi…

Mitigation only
Fix from $1,950 2021-01-20
Sd Wan Firmware HIGH 7.8
CVE-2021-1260

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected devi…

Mitigation only
Fix from $1,950 2021-01-20
Sd Wan Firmware HIGH 7.8
CVE-2021-1261

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected devi…

Mitigation only
Fix from $1,950 2021-01-20
Sd Wan Firmware HIGH 7.8
CVE-2021-1262

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected devi…

Fix: 19.2.4 / 20.1.2+
Fix from $1,950 2021-01-20
Security Guardium HIGH 7.8
CVE-2020-4688

IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by comma…

Mitigation only
Fix from $1,950 2021-01-20
Ax1800 Firmware HIGH 7.2
CVE-2020-14102

There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This aff…

Fix: 1.0.26 / 1.0.336+
Fix from $1,950 2021-01-13