Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
R7800 Firmware HIGH 8.0
CVE-2019-20707

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.

Fix: 1.0.2.60 / 2.3.2.32+
Fix from $1,950 2020-04-16
Xr500 Firmware HIGH 8.0
CVE-2019-20708

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR…

Fix: 1.0.0.76 / 2.3.2.32+
Fix from $1,950 2020-04-16
Xr500 Firmware HIGH 8.0
CVE-2019-20709

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR…

Fix: 1.0.0.76 / 2.3.2.32+
Fix from $1,950 2020-04-16
Xr500 Firmware HIGH 8.0
CVE-2019-20710

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR…

Fix: 1.0.0.76 / 2.3.2.32+
Fix from $1,950 2020-04-16
Xr500 Firmware HIGH 8.0
CVE-2019-20711

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR…

Fix: 1.0.0.76 / 2.3.2.32+
Fix from $1,950 2020-04-16
D6220 Firmware MEDIUM 6.8
CVE-2019-20718

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.48, D6400 before 1.0.0.82, D7000v…

Mitigation only
Fix from $1,600 2020-04-16
D3600 Firmware MEDIUM 6.8
CVE-2019-20688

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 …

Fix: 1.0.0.63 / 1.0.0.75+
Fix from $1,600 2020-04-16
D6000 Firmware MEDIUM 6.8
CVE-2019-20689

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6000 before 1.0.0.75, D6100 before 1.0.0.63, EX2700…

Fix: 1.0.0.63 / 1.0.0.75+
Fix from $1,600 2020-04-16
D7000 Firmware HIGH 8.0
CVE-2019-20680

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000v2 before 1.0.0.53, R6220 before 1.1.0.80, R626…

Fix: 1.0.0.53 / 1.0.2.4+
Fix from $1,950 2020-04-15
Xr500 Firmware HIGH 7.8
CVE-2019-20655

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 and XR700 before 1.0.1.20.

Fix: 1.0.1.20 / 2.3.2.56+
Fix from $1,950 2020-04-15
R6400 Firmware HIGH 7.2
CVE-2019-20659

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700…

Fix: 1.0.2.8 / 1.0.3.10+
Fix from $1,950 2020-04-15
Wac505 Firmware MEDIUM 6.7
CVE-2019-20651

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 8.2.1.16 and WAC510 before 8.2.1.16.

Fix: 8.2.1.16+
Fix from $1,600 2020-04-15
R6400 Firmware CRITICAL 9.8
CVE-2020-11789

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8,…

Fix: 1.0.2.8 / 1.0.3.10+
Fix from $2,300 2020-04-15
D6220 Firmware HIGH 8.8
CVE-2020-11770

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v…

Fix: 1.0.0.52 / 1.0.0.86+
Fix from $1,950 2020-04-15
Dvr Firmware HIGH 8.8
CVE-2020-10514

iCatch DVR firmware before 20200103 do not validate function parameter properly, resulting attackers executing arbitrary command.

Fix: 20200103+
Fix from $1,950 2020-04-15
Debian Linux HIGH 7.8
CVE-2019-14868

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypas…

Fix: 10.15.5+
Fix from $1,950 2020-04-02
Wc7500 Firmware CRITICAL 9.8
CVE-2018-11106

NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: …

Fix: 2.5.0.46 / 6.5.3.5+
Fix from $2,300 2020-04-01
Avocent Umg 4000 Firmware HIGH 7.2
CVE-2019-9507

The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the application incorrectly neutralizes …

Mitigation only
Fix from $1,950 2020-03-30
Vigor300b Firmware CRITICAL 9.8
CVE-2020-10826EPSS 39%

/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a …

Fix: 1.5.1+
Fix from $2,300 2020-03-26
Firefox HIGH 8.8
CVE-2020-6811

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If …

Fix: 68.6.0 / 74.0+
Fix from $1,950 2020-03-25
Sd Wan Firmware HIGH 7.8
CVE-2020-3266

A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbitrary commands that are execu…

Fix: 19.2.2+
Fix from $1,950 2020-03-19
Sd Wan Firmware HIGH 8.1
CVE-2019-16012EPSS 54%

A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attack…

Fix: 19.2.2+
Fix from $1,950 2020-03-19
Debian Linux MEDIUM 6.5
CVE-2019-12921EPSS 8%

In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of Translate…

Fix: 1.3.32+
Fix from $1,600 2020-03-18
Pan Os HIGH 7.8
CVE-2020-1980

A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. T…

Fix: 8.1.13+
Fix from $1,950 2020-03-11
GitLab HIGH 8.8
CVE-2019-12430

An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to …

Mitigation only
Fix from $1,950 2020-03-10
Remote Phy 120 Firmware MEDIUM 6.7
CVE-2020-3176

A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of…

Fix: 7.7+
Fix from $1,600 2020-03-04
Kill Port Process CRITICAL 9.8
CVE-2019-15609

The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.

Fix: 2.2.0+
Fix from $2,300 2020-02-28
Airwave HIGH 7.2
CVE-2019-5323

There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not pro…

Fix: 8.2.10.1+
Fix from $1,950 2020-02-27
Tat 77104g1 Firmware CRITICAL 9.8
CVE-2020-3924

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command …

Fix: after 20181221_76216g3
Fix from $2,300 2020-02-27
Gaussdb 200 HIGH 8.8
CVE-2020-1790

GaussDB 200 with version of 6.5.1 have a command injection vulnerability. The software constructs part of a command using external input from users, …

Mitigation only
Fix from $1,950 2020-02-18