Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2018-19949 KEVEPSS 24% If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the fo… Qts 4.2.6 / 4.3.3.1161+ Fix from $2,3002020-10-28 HIGH 7.8 CVE-2019-14719 Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager. Mx900 Firmware Mitigation only Fix from $1,9502020-10-23 MEDIUM 6.7 CVE-2020-11496 Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitrary code. This firmware lacks … Sprecon E 8.64b+ Fix from $1,6002020-10-19 HIGH 7.8 CVE-2020-9862 A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6,… Safari 6.2.8 / 7.20+ Fix from $1,9502020-10-16 HIGH 7.2 CVE-2020-4636 IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503. Resilient Security Orchestration Automation And Response Mitigation only Fix from $1,9502020-10-16 HIGH 8.0 CVE-2020-26929 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100. R6230 Firmware 1.1.0.100+ Fix from $1,9502020-10-09 HIGH 7.1 CVE-2020-26914 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR615… D6200 Firmware 1.0.0.42 / 1.0.0.66+ Fix from $1,9502020-10-09 HIGH 8.8 CVE-2020-26920 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.3.110, SRR60 before 2.5.3.110… Srk60 Firmware 2.5.3.110+ Fix from $1,9502020-10-09 MEDIUM 6.7 CVE-2020-26922 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC76… Wc7500 Firmware 6.5.5.24+ Fix from $1,6002020-10-09 HIGH 8.8 CVE-2020-26907 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.16.6, RBR850 before 3.2.16.6… Rbk852 Firmware 3.2.16.6+ Fix from $1,9502020-10-09 HIGH 8.8 CVE-2020-26909 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.58 and R7500v2 before 1.0.3… D7800 Firmware 1.0.1.58 / 1.0.3.48+ Fix from $1,9502020-10-09 MEDIUM 6.8 CVE-2020-26910 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR7… Cbr40 Firmware 2.5.0.10 / 3.2.15.25+ Fix from $1,6002020-10-09 HIGH 8.8 CVE-2020-26902 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBR750 before 3.2.15.… Rbk752 Firmware 3.2.15.25+ Fix from $1,9502020-10-09 MEDIUM 5.0 CVE-2020-15228 In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Actions Runner over stdout by ge… Toolkit 1.2.6+ Fix from $1,6002020-10-01 HIGH 7.8 CVE-2020-0130 In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system pr… Android Mitigation only Fix from $1,9502020-09-17 CRITICAL 9.8 CVE-2020-11698EPSS 74% An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote a… Spamtitan No fix yet Fix from $2,3002020-09-17 CRITICAL 9.1 CVE-2020-24561EPSS 5% A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system.… Serverprotect Mitigation only Fix from $2,3002020-09-15 CRITICAL 9.8 CVE-2020-14100EPSS 5% In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator… R3600 Firmware 1.0.66+ Fix from $2,3002020-09-11 HIGH 7.0 CVE-2020-14342 It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. A… Fedora after 6.10 Fix from $1,9502020-09-09 CRITICAL 9.8 CVE-2020-11117EPSS 20% u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in r… Ipq4019 Firmware No fix yet Fix from $2,3002020-09-08 MEDIUM 6.8 CVE-2020-9199 B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with high privileges may exploit t… B2368 22 Firmware Mitigation only Fix from $1,6002020-09-03 HIGH 8.8 CVE-2020-25079 KEVEPSS 53% An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated comma… Dcs 4703e Firmware 1.03.02 / 1.03.04+ Fix from $1,9502020-09-02 HIGH 8.8 CVE-2020-25067 NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker. R8300 Firmware 1.0.2.134+ Fix from $1,9502020-09-01 HIGH 8.8 CVE-2020-10518 A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-cont… GitHub 2.19.21 / 2.20.15+ Fix from $1,9502020-08-27 HIGH 8.8 CVE-2020-15642EPSS 7% This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marvell QConvergeConsole 5.5.0.64.… Qconvergeconsole 5.5.00.73+ Fix from $1,9502020-08-25 HIGH 7.2 CVE-2019-11853 Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4. Aleos 4.9.4 / 4.11.0+ Fix from $1,9502020-08-21 CRITICAL 9.8 CVE-2020-8211 Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 an… Xenmobile Server after 10.8.0 Fix from $2,3002020-08-17 HIGH 8.8 CVE-2020-8233 A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell comma… Edgeswitch Firmware 1.9.0+ Fix from $1,9502020-08-17 HIGH 8.8 CVE-2020-9242 FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain parameters post from user, successful… Fusioncompute Mitigation only Fix from $1,9502020-08-17 CRITICAL 9.8 CVE-2020-7697 This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affected Area require('../server/g… Mock2easy No fix yet Fix from $2,3002020-07-29