Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Qts CRITICAL 9.8
CVE-2018-19949 KEVEPSS 24%

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the fo…

Fix: 4.2.6 / 4.3.3.1161+
Fix from $2,300 2020-10-28
Mx900 Firmware HIGH 7.8
CVE-2019-14719

Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager.

Mitigation only
Fix from $1,950 2020-10-23
Sprecon E MEDIUM 6.7
CVE-2020-11496

Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitrary code. This firmware lacks …

Fix: 8.64b+
Fix from $1,600 2020-10-19
Safari HIGH 7.8
CVE-2020-9862

A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6,…

Fix: 6.2.8 / 7.20+
Fix from $1,950 2020-10-16
Resilient Security Orchestration Automation And Response HIGH 7.2
CVE-2020-4636

IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503.

Mitigation only
Fix from $1,950 2020-10-16
R6230 Firmware HIGH 8.0
CVE-2020-26929

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.

Fix: 1.1.0.100+
Fix from $1,950 2020-10-09
D6200 Firmware HIGH 7.1
CVE-2020-26914

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR615…

Fix: 1.0.0.42 / 1.0.0.66+
Fix from $1,950 2020-10-09
Srk60 Firmware HIGH 8.8
CVE-2020-26920

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.3.110, SRR60 before 2.5.3.110…

Fix: 2.5.3.110+
Fix from $1,950 2020-10-09
Wc7500 Firmware MEDIUM 6.7
CVE-2020-26922

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC76…

Fix: 6.5.5.24+
Fix from $1,600 2020-10-09
Rbk852 Firmware HIGH 8.8
CVE-2020-26907

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.16.6, RBR850 before 3.2.16.6…

Fix: 3.2.16.6+
Fix from $1,950 2020-10-09
D7800 Firmware HIGH 8.8
CVE-2020-26909

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.58 and R7500v2 before 1.0.3…

Fix: 1.0.1.58 / 1.0.3.48+
Fix from $1,950 2020-10-09
Cbr40 Firmware MEDIUM 6.8
CVE-2020-26910

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR7…

Fix: 2.5.0.10 / 3.2.15.25+
Fix from $1,600 2020-10-09
Rbk752 Firmware HIGH 8.8
CVE-2020-26902

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBR750 before 3.2.15.…

Fix: 3.2.15.25+
Fix from $1,950 2020-10-09
Toolkit MEDIUM 5.0
CVE-2020-15228

In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Actions Runner over stdout by ge…

Fix: 1.2.6+
Fix from $1,600 2020-10-01
Android HIGH 7.8
CVE-2020-0130

In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system pr…

Mitigation only
Fix from $1,950 2020-09-17
Spamtitan CRITICAL 9.8
CVE-2020-11698EPSS 74%

An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote a…

No fix yet
Fix from $2,300 2020-09-17
Serverprotect CRITICAL 9.1
CVE-2020-24561EPSS 5%

A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system.…

Mitigation only
Fix from $2,300 2020-09-15
R3600 Firmware CRITICAL 9.8
CVE-2020-14100EPSS 5%

In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator…

Fix: 1.0.66+
Fix from $2,300 2020-09-11
Fedora HIGH 7.0
CVE-2020-14342

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. A…

Fix: after 6.10
Fix from $1,950 2020-09-09
Ipq4019 Firmware CRITICAL 9.8
CVE-2020-11117EPSS 20%

u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in r…

No fix yet
Fix from $2,300 2020-09-08
B2368 22 Firmware MEDIUM 6.8
CVE-2020-9199

B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with high privileges may exploit t…

Mitigation only
Fix from $1,600 2020-09-03
Dcs 4703e Firmware HIGH 8.8
CVE-2020-25079 KEVEPSS 53%

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated comma…

Fix: 1.03.02 / 1.03.04+
Fix from $1,950 2020-09-02
R8300 Firmware HIGH 8.8
CVE-2020-25067

NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker.

Fix: 1.0.2.134+
Fix from $1,950 2020-09-01
GitHub HIGH 8.8
CVE-2020-10518

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-cont…

Fix: 2.19.21 / 2.20.15+
Fix from $1,950 2020-08-27
Qconvergeconsole HIGH 8.8
CVE-2020-15642EPSS 7%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marvell QConvergeConsole 5.5.0.64.…

Fix: 5.5.00.73+
Fix from $1,950 2020-08-25
Aleos HIGH 7.2
CVE-2019-11853

Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.

Fix: 4.9.4 / 4.11.0+
Fix from $1,950 2020-08-21
Xenmobile Server CRITICAL 9.8
CVE-2020-8211

Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 an…

Fix: after 10.8.0
Fix from $2,300 2020-08-17
Edgeswitch Firmware HIGH 8.8
CVE-2020-8233

A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell comma…

Fix: 1.9.0+
Fix from $1,950 2020-08-17
Fusioncompute HIGH 8.8
CVE-2020-9242

FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain parameters post from user, successful…

Mitigation only
Fix from $1,950 2020-08-17
Mock2easy CRITICAL 9.8
CVE-2020-7697

This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affected Area require('../server/g…

No fix yet
Fix from $2,300 2020-07-29