Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 7.2 CVE-2021-3617 A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted network configu… Smart Camera C2e Firmware 01.03.29.16+ Fix from $1,9502021-08-17 MEDIUM 6.7 CVE-2021-21595 Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability c… Emc Powerscale Onefs 9.2.0+ Fix from $1,6002021-08-16 CRITICAL 9.8 CVE-2021-37708 Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.… Shopware 6.4.3.1+ Fix from $2,3002021-08-16 HIGH 7.2 CVE-2021-22935 A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web … Connect Secure 9.1+ Fix from $1,9502021-08-16 HIGH 7.2 CVE-2021-22938 A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web … Connect Secure 9.1+ Fix from $1,9502021-08-16 CRITICAL 9.8 CVE-2020-18758 An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code. Mac1100 Plc Firmware No fix yet Fix from $2,3002021-08-13 CRITICAL 9.8 CVE-2021-38530 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, … Rbk40 Firmware 2.5.1.16+ Fix from $2,3002021-08-11 CRITICAL 9.8 CVE-2021-38529 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, … D7800 Firmware 1.0.1.56 / 1.0.2.68+ Fix from $2,3002021-08-11 CRITICAL 9.8 CVE-2021-38528 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6900P before 1.3.2.132… D8500 Firmware 1.0.0.64 / 1.0.1.38+ Fix from $2,3002021-08-11 CRITICAL 9.8 CVE-2021-38527 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.14, EX6100v2 before 1.0.1.9… Cbr40 Firmware 1.0.0.132 / 1.0.1.98+ Fix from $2,3002021-08-11 HIGH 7.2 CVE-2021-38521 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.50, R7900P before 1.4.1.50, R8000… R6400 Firmware 1.0.1.50 / 1.0.1.62+ Fix from $1,9502021-08-11 HIGH 7.2 CVE-2021-38520 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, R6400v2 before 1.0.4.84, R670… R6400 Firmware 1.0.1.52 / 1.0.4.84+ Fix from $1,9502021-08-11 HIGH 7.2 CVE-2021-38519 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, R6300v2 before 1.0.4.36, R640… R6250 Firmware 1.0.1.50 / 1.0.2.8+ Fix from $1,9502021-08-11 HIGH 7.2 CVE-2021-38518 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120, RAX75 before 1.0.4.120, RAX… Rax200 Firmware 1.0.4.120 / 3.2.17.12+ Fix from $1,9502021-08-11 MEDIUM 5.9 CVE-2021-38370 In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS. Alpine 2.25+ Fix from $1,6002021-08-10 MEDIUM 5.3 CVE-2021-38373 In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" … Kmail Mitigation only Fix from $1,6002021-08-10 HIGH 8.1 CVE-2020-36462 An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send for Bucket2. Syncpool 0.1.6+ Fix from $1,9502021-08-08 HIGH 8.1 CVE-2020-36463 An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of Send for InnerSend<RW, T>, In… Multiqueue after 2020-12-25 Fix from $1,9502021-08-08 CRITICAL 9.8 CVE-2021-38189 An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two <CR><LF> … Lettre 0.9.6+ Fix from $2,3002021-08-08 HIGH 8.1 CVE-2020-36448 An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for Cache<K>. Cache after 2020-11-24 Fix from $1,9502021-08-08 HIGH 8.1 CVE-2020-36449 An issue was discovered in the kekbit crate before 0.3.4 for Rust. For ShmWriter<H>, Send is implemented without requiring H: Send. Kekbit 0.3.4+ Fix from $1,9502021-08-08 HIGH 8.1 CVE-2020-36450 An issue was discovered in the bunch crate through 2020-11-12 for Rust. There are unconditional implementations of Send and Sync for Bunch<T>. Bunch after 2020-11-12 Fix from $1,9502021-08-08 HIGH 8.1 CVE-2020-36451 An issue was discovered in the rcu_cell crate through 2020-11-14 for Rust. There are unconditional implementations of Send and Sync for RcuCell<T>. Rcu Cell after 2020-11-14 Fix from $1,9502021-08-08 HIGH 8.1 CVE-2020-36455 An issue was discovered in the slock crate through 2020-11-17 for Rust. Slock<T> unconditionally implements Send and Sync. Slock after 2020-11-17 Fix from $1,9502021-08-08 HIGH 8.1 CVE-2020-36456 An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell<T>, the Send trait lacks bounds on the contained type. Toolshed after 2020-11-15 Fix from $1,9502021-08-08 HIGH 8.1 CVE-2020-36457 An issue was discovered in the lever crate before 0.1.1 for Rust. AtomicBox<T> implements the Send and Sync traits for all types T. Lever Patch available Fix from $1,9502021-08-08 HIGH 8.1 CVE-2020-36459 An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds on its EntityStore and Compo… Dces after 2020-12-09 Fix from $1,9502021-08-08 HIGH 8.1 CVE-2020-36461 An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync for MvccRwLoc… Noise Search after 2020-12-10 Fix from $1,9502021-08-08 CRITICAL 9.8 CVE-2021-38173 Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorize… Debian Linux 0.31.2+ Fix from $2,3002021-08-07 HIGH 8.8 CVE-2021-38169 Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py. Roxy Wi after 5.2.2.0 Fix from $1,9502021-08-07