Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Unleashed Firmware CRITICAL 9.8
CVE-2020-13917

rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI…

Fix: after 200.7.10.102.92
Fix from $2,300 2020-07-28
Unleashed Firmware CRITICAL 9.8
CVE-2020-13919

emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to achieve command injection via a crafted HTTP request. Th…

Fix: after 200.7.10.102.92
Fix from $2,300 2020-07-28
Download Manager HIGH 7.8
CVE-2020-9688

Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

Mitigation only
Fix from $1,950 2020-07-17
Iview CRITICAL 9.8
CVE-2020-14505EPSS 7%

Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Su…

Fix: after 5.6
Fix from $2,300 2020-07-15
Ipear MEDIUM 5.4
CVE-2020-11084

In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developer…

Mitigation only
Fix from $1,600 2020-07-14
Devcert CRITICAL 9.8
CVE-2020-8186

A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `cer…

No fix yet
Fix from $2,300 2020-07-10
Unifi Protect Firmware HIGH 8.8
CVE-2020-8188

We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR r…

Fix: after 1.14.9
Fix from $1,950 2020-07-02
E Tax Reception System HIGH 8.8
CVE-2020-5601

Chrome Extension for e-Tax Reception System Ver1.0.0.0 allows remote attackers to execute an arbitrary command via unspecified vectors.

No fix yet
Fix from $1,950 2020-06-30
Magento CRITICAL 9.8
CVE-2020-9583EPSS 6%

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabili…

Fix: after 2.3.4
Fix from $2,300 2020-06-26
Magento CRITICAL 9.8
CVE-2020-9576EPSS 6%

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabili…

Fix: after 2.3.4
Fix from $2,300 2020-06-26
Magento CRITICAL 9.8
CVE-2020-9578EPSS 6%

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabili…

Fix: after 2.3.4
Fix from $2,300 2020-06-26
Magento CRITICAL 9.8
CVE-2020-9582EPSS 6%

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabili…

Fix: after 2.3.4
Fix from $2,300 2020-06-26
Vigor300b Firmware CRITICAL 9.8
CVE-2020-14472

On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.

Fix: 1.5.1.1+
Fix from $2,300 2020-06-24
Mijia Inkjet Printer Firmware CRITICAL 9.8
CVE-2020-10561

An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web management background, resul…

Fix: 3.4.6_0138+
Fix from $2,300 2020-06-24
Mailaudit CRITICAL 9.8
CVE-2020-12782

Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be trigg…

Mitigation only
Fix from $2,300 2020-06-23
Mversion HIGH 7.3
CVE-2020-4059

In mversion before 2.0.0, there is a command injection vulnerability. This issue may lead to remote code execution if a client of the library calls t…

Fix: 2.0.0+
Fix from $1,950 2020-06-18
Rbk752 Firmware HIGH 8.8
CVE-2020-14439

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.…

Fix: 3.2.15.25+
Fix from $1,950 2020-06-18
Rbk752 Firmware HIGH 8.8
CVE-2020-14440

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.…

Fix: 3.2.15.25+
Fix from $1,950 2020-06-18
Rbk752 Firmware HIGH 8.8
CVE-2020-14441

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.…

Fix: 3.2.15.25+
Fix from $1,950 2020-06-18
Rbk752 Firmware HIGH 8.8
CVE-2020-14442

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.…

Fix: 3.2.15.25+
Fix from $1,950 2020-06-18
Rbk852 Firmware MEDIUM 6.8
CVE-2020-14433

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RB…

Fix: 3.2.15.25+
Fix from $1,600 2020-06-18
Rbk752 Firmware MEDIUM 6.8
CVE-2020-14434

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RB…

Fix: 3.2.15.25+
Fix from $1,600 2020-06-18
Srk60 Firmware HIGH 8.8
CVE-2020-14435

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.2.104, SRS60 before 2.5.2.104…

Fix: 2.5.2.104+
Fix from $1,950 2020-06-18
Rbk752 Firmware HIGH 8.8
CVE-2020-14436

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.…

Fix: 3.2.15.25+
Fix from $1,950 2020-06-18
Rbk752 Firmware HIGH 8.8
CVE-2020-14437

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.…

Fix: 3.2.15.25+
Fix from $1,950 2020-06-18
Rbk752 Firmware HIGH 8.8
CVE-2020-14438

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.…

Fix: 3.2.15.25+
Fix from $1,950 2020-06-18
Rv016 Firmware HIGH 7.2
CVE-2020-3274

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,…

Fix: after 4.2.3.10
Fix from $1,950 2020-06-18
Rv016 Firmware HIGH 7.2
CVE-2020-3275

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,…

Fix: after 4.2.3.10
Fix from $1,950 2020-06-18
Rv016 Firmware HIGH 7.2
CVE-2020-3276

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,…

Fix: after 4.2.3.10
Fix from $1,950 2020-06-18
Rv016 Firmware HIGH 7.2
CVE-2020-3277

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,…

Fix: after 4.2.3.10
Fix from $1,950 2020-06-18