Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Rv016 Firmware HIGH 7.2
CVE-2020-3278

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,…

Fix: after 4.2.3.10
Fix from $1,950 2020-06-18
Rv016 Firmware HIGH 7.2
CVE-2020-3279

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,…

Fix: after 4.2.3.10
Fix from $1,950 2020-06-18
Aspera Application Platform On Demand HIGH 7.5
CVE-2020-4432

Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge…

Fix: after 3.9.10
Fix from $1,950 2020-06-10
October MEDIUM 5.1
CVE-2020-5299

In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could e…

Fix: 1.0.466+
Fix from $1,600 2020-06-03
Ios Xe HIGH 8.8
CVE-2020-3224

A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privil…

Patch available
Fix from $1,950 2020-06-03
iOS MEDIUM 6.7
CVE-2020-3210

A vulnerability in the CLI parsers of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 100…

Patch available
Fix from $1,600 2020-06-03
Ios Xe HIGH 7.2
CVE-2020-3211

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileg…

Patch available
Fix from $1,950 2020-06-03
Ios Xe HIGH 7.2
CVE-2020-3212

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileg…

Patch available
Fix from $1,950 2020-06-03
Ios Xe HIGH 8.8
CVE-2020-3219

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject and execute arbitrary commands with ad…

Patch available
Fix from $1,950 2020-06-03
Ios Xe MEDIUM 6.7
CVE-2020-3207

A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root s…

Mitigation only
Fix from $1,600 2020-06-03
Node Dns Sync CRITICAL 9.8
CVE-2020-11079

node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote code execution if a client o…

Fix: 0.2.1+
Fix from $2,300 2020-05-28
Airos CRITICAL 9.8
CVE-2020-8171

We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.…

Fix: after 6.2.0
Fix from $2,300 2020-05-26
Autoswitch Python Virtualenv HIGH 7.8
CVE-2020-11073

In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without a…

Fix: 1.16.0+
Fix from $1,950 2020-05-13
File Transfer Appliance CRITICAL 9.8
CVE-2019-5623

Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Comma…

No fix yet
Fix from $2,300 2020-04-29
Ios Xe HIGH 7.8
CVE-2019-16011

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands that are execute…

Fix: 17.2.1r+
Fix from $1,950 2020-04-29
Smart Indoor Camera Firmware MEDIUM 6.7
CVE-2019-17101

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in firmware versions prior to x.xx of Netatmo Smart…

Fix: 4.2.5+
Fix from $1,600 2020-04-23
R7800 Firmware MEDIUM 6.8
CVE-2019-20757

NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.

Fix: 1.0.2.62+
Fix from $1,600 2020-04-16
R7800 Firmware HIGH 8.0
CVE-2019-20761

NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.

Fix: 1.0.2.62+
Fix from $1,950 2020-04-16
Wac505 Firmware MEDIUM 6.8
CVE-2019-20745

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 5.0.10.2 and WAC510 before 5.0.10.2.

Fix: 5.0.10.2+
Fix from $1,600 2020-04-16
D6220 Firmware MEDIUM 6.7
CVE-2019-20732

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.40, D7000v2 before 1.0.0.74, D850…

Fix: 1.0.0.30 / 1.0.0.40+
Fix from $1,600 2020-04-16
D7800 Firmware MEDIUM 6.8
CVE-2019-20722

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44, DM200 before 1.0.0.58, R7500v…

Fix: 1.0.0.58 / 1.0.1.44+
Fix from $1,600 2020-04-16
D3600 Firmware MEDIUM 6.8
CVE-2019-20724

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 …

Fix: 1.0.0.63 / 1.0.0.75+
Fix from $1,600 2020-04-16
D3600 Firmware MEDIUM 6.8
CVE-2019-20726

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 …

Fix: 1.0.0.58 / 1.0.0.63+
Fix from $1,600 2020-04-16
D6100 Firmware MEDIUM 6.8
CVE-2019-20727

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6100 before 1.0.0.63, R7800 before 1.0.2.52, R8900 …

Fix: 1.0.0.58 / 1.0.0.63+
Fix from $1,600 2020-04-16
Xr500 Firmware HIGH 8.0
CVE-2019-20701

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR…

Fix: 1.0.0.76 / 2.3.2.32+
Fix from $1,950 2020-04-16
Xr500 Firmware HIGH 8.0
CVE-2019-20702

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR…

Fix: 1.0.0.76 / 2.3.2.32+
Fix from $1,950 2020-04-16
Xr500 Firmware HIGH 8.0
CVE-2019-20703

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR…

Fix: 1.0.0.76 / 2.3.2.32+
Fix from $1,950 2020-04-16
Xr500 Firmware HIGH 8.0
CVE-2019-20704

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR…

Fix: 1.0.0.76 / 2.3.2.32+
Fix from $1,950 2020-04-16
Xr500 Firmware HIGH 8.0
CVE-2019-20705

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR…

Fix: 1.0.0.76 / 2.3.2.32+
Fix from $1,950 2020-04-16
R7800 Firmware HIGH 8.0
CVE-2019-20706

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.

Fix: 1.0.2.60 / 2.3.2.32+
Fix from $1,950 2020-04-16