Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Qts HIGH 7.2
CVE-2020-2508

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitra…

Fix: 4.5.1.1456+
Fix from $1,950 2021-01-11
Transform N HIGH 7.2
CVE-2020-17502

Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which is made available over https. …

Fix: 3.8+
Fix from $1,950 2021-01-08
Transform N HIGH 7.2
CVE-2020-17503

The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users…

Fix: 3.8+
Fix from $1,950 2021-01-08
Transform N HIGH 7.2
CVE-2020-17504

The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users…

Fix: 3.8+
Fix from $1,950 2021-01-08
Transform N CRITICAL 9.8
CVE-2020-17500

Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web ad…

Fix: 3.8+
Fix from $2,300 2021-01-07
Pdf Activex HIGH 7.8
CVE-2018-19418EPSS 8%

Foxit PDF ActiveX before 5.5.1 allows remote code execution via command injection because of the lack of a security permission control.

Fix: 5.5.1+
Fix from $1,950 2021-01-07
Dv 360 Firmware CRITICAL 9.8
CVE-2018-14067EPSS 7%

Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command execution, via a crafted payload to t…

No fix yet
Fix from $2,300 2020-12-31
Rbs40v Firmware MEDIUM 6.8
CVE-2020-35794

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBS40V before 2.6.1.4, RBK752 before 3.2.15.25, RBR7…

Fix: 2.6.1.4 / 3.2.15.25+
Fix from $1,600 2020-12-30
R6400v2 Firmware HIGH 7.8
CVE-2020-35798

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.…

Fix: 1.0.2.74 / 1.0.4.26+
Fix from $1,950 2020-12-30
D7800 Firmware MEDIUM 6.8
CVE-2020-35790

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 …

Fix: 1.0.1.56 / 1.0.2.68+
Fix from $1,600 2020-12-30
R7800 Firmware MEDIUM 6.7
CVE-2020-35791

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.68, R8900 before 1.0.5.2, and R90…

Fix: 1.0.2.68 / 1.0.5.2+
Fix from $1,600 2020-12-30
R7500 Firmware MEDIUM 6.8
CVE-2020-35792

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7500v2 before 1.0.3.48, R8900 before 1.0.5.2, R9000…

Fix: 1.0.2.68 / 1.0.3.48+
Fix from $1,600 2020-12-30
D7800 Firmware MEDIUM 6.7
CVE-2020-35793

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.58, R7500v2 before 1.0.3.46, R780…

Fix: 1.0.1.58 / 1.0.2.74+
Fix from $1,600 2020-12-30
Dgn2200v1 Firmware HIGH 8.4
CVE-2020-35777

NETGEAR DGN2200v1 devices before v1.0.0.58 are affected by command injection.

Fix: 1.0.0.58+
Fix from $1,950 2020-12-30
Qts HIGH 8.8
CVE-2020-25847

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulner…

Fix: 4.5.1.1495+
Fix from $1,950 2020-12-29
Vpn Orchestrator HIGH 7.2
CVE-2020-29299

Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-pr…

Fix: 1.33 / 4.39+
Fix from $1,950 2020-12-27
Osquery MEDIUM 5.2
CVE-2020-26273

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before version 4.6.0, by using sqlite's AT…

Fix: 4.6.0+
Fix from $1,600 2020-12-16
Arubaos CRITICAL 9.8
CVE-2020-24634

An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management pr…

Fix: 2.1.0.2 / 2.2.0.1+
Fix from $2,300 2020-12-11
Quts Hero CRITICAL 9.8
CVE-2019-7198

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulner…

Fix: 4.4.3.1354 / 4.5.1.1456+
Fix from $2,300 2020-12-10
Manageone HIGH 7.2
CVE-2020-9115

ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An …

Mitigation only
Fix from $1,950 2020-12-01
Fusioncompute HIGH 7.2
CVE-2020-9116

Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to…

Mitigation only
Fix from $1,950 2020-12-01
Industrial Automation Aprol CRITICAL 9.8
CVE-2019-19874

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution o…

Mitigation only
Fix from $2,300 2020-11-27
Industrial Automation Aprol CRITICAL 9.8
CVE-2019-19875

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (using Python scripts) via the Apr…

Mitigation only
Fix from $2,300 2020-11-27
Industrial Automation Aprol CRITICAL 9.8
CVE-2019-19872

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintende…

Mitigation only
Fix from $2,300 2020-11-27
Qts HIGH 7.2
CVE-2020-2492

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Q…

Fix: 4.4.3.1421+
Fix from $1,950 2020-11-16
Qts HIGH 7.2
CVE-2020-2490

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Q…

Fix: 4.4.3.1421+
Fix from $1,950 2020-11-16
Nip6300 Firmware MEDIUM 6.7
CVE-2020-9127

Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some ma…

Mitigation only
Fix from $1,600 2020-11-13
Vport 461 Firmware CRITICAL 9.8
CVE-2020-23639

A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a remote attacker to execute arb…

Fix: after 3.4
Fix from $2,300 2020-11-02
Music Station CRITICAL 9.8
CVE-2018-19950

If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. …

Fix: 5.1.13 / 5.2.9+
Fix from $2,300 2020-11-02
Metasploit HIGH 7.8
CVE-2020-7384EPSS 30%

Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arb…

Fix: 4.19.0+
Fix from $1,950 2020-10-29