Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 7.2 CVE-2020-3278 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,… Rv016 Firmware after 4.2.3.10 Fix from $1,9502020-06-18 HIGH 7.2 CVE-2020-3279 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,… Rv016 Firmware after 4.2.3.10 Fix from $1,9502020-06-18 HIGH 7.5 CVE-2020-4432 Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge… Aspera Application Platform On Demand after 3.9.10 Fix from $1,9502020-06-10 MEDIUM 5.1 CVE-2020-5299 In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could e… October 1.0.466+ Fix from $1,6002020-06-03 HIGH 8.8 CVE-2020-3224 A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privil… Ios Xe Patch available Fix from $1,9502020-06-03 MEDIUM 6.7 CVE-2020-3210 A vulnerability in the CLI parsers of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 100… iOS Patch available Fix from $1,6002020-06-03 HIGH 7.2 CVE-2020-3211 A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileg… Ios Xe Patch available Fix from $1,9502020-06-03 HIGH 7.2 CVE-2020-3212 A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileg… Ios Xe Patch available Fix from $1,9502020-06-03 HIGH 8.8 CVE-2020-3219 A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject and execute arbitrary commands with ad… Ios Xe Patch available Fix from $1,9502020-06-03 MEDIUM 6.7 CVE-2020-3207 A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root s… Ios Xe Mitigation only Fix from $1,6002020-06-03 CRITICAL 9.8 CVE-2020-11079 node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote code execution if a client o… Node Dns Sync 0.2.1+ Fix from $2,3002020-05-28 CRITICAL 9.8 CVE-2020-8171 We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.… Airos after 6.2.0 Fix from $2,3002020-05-26 HIGH 7.8 CVE-2020-11073 In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without a… Autoswitch Python Virtualenv 1.16.0+ Fix from $1,9502020-05-13 CRITICAL 9.8 CVE-2019-5623 Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Comma… File Transfer Appliance No fix yet Fix from $2,3002020-04-29 HIGH 7.8 CVE-2019-16011 A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands that are execute… Ios Xe 17.2.1r+ Fix from $1,9502020-04-29 MEDIUM 6.7 CVE-2019-17101 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in firmware versions prior to x.xx of Netatmo Smart… Smart Indoor Camera Firmware 4.2.5+ Fix from $1,6002020-04-23 MEDIUM 6.8 CVE-2019-20757 NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user. R7800 Firmware 1.0.2.62+ Fix from $1,6002020-04-16 HIGH 8.0 CVE-2019-20761 NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user. R7800 Firmware 1.0.2.62+ Fix from $1,9502020-04-16 MEDIUM 6.8 CVE-2019-20745 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 5.0.10.2 and WAC510 before 5.0.10.2. Wac505 Firmware 5.0.10.2+ Fix from $1,6002020-04-16 MEDIUM 6.7 CVE-2019-20732 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.40, D7000v2 before 1.0.0.74, D850… D6220 Firmware 1.0.0.30 / 1.0.0.40+ Fix from $1,6002020-04-16 MEDIUM 6.8 CVE-2019-20722 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44, DM200 before 1.0.0.58, R7500v… D7800 Firmware 1.0.0.58 / 1.0.1.44+ Fix from $1,6002020-04-16 MEDIUM 6.8 CVE-2019-20724 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 … D3600 Firmware 1.0.0.63 / 1.0.0.75+ Fix from $1,6002020-04-16 MEDIUM 6.8 CVE-2019-20726 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 … D3600 Firmware 1.0.0.58 / 1.0.0.63+ Fix from $1,6002020-04-16 MEDIUM 6.8 CVE-2019-20727 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6100 before 1.0.0.63, R7800 before 1.0.2.52, R8900 … D6100 Firmware 1.0.0.58 / 1.0.0.63+ Fix from $1,6002020-04-16 HIGH 8.0 CVE-2019-20701 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR… Xr500 Firmware 1.0.0.76 / 2.3.2.32+ Fix from $1,9502020-04-16 HIGH 8.0 CVE-2019-20702 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR… Xr500 Firmware 1.0.0.76 / 2.3.2.32+ Fix from $1,9502020-04-16 HIGH 8.0 CVE-2019-20703 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR… Xr500 Firmware 1.0.0.76 / 2.3.2.32+ Fix from $1,9502020-04-16 HIGH 8.0 CVE-2019-20704 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR… Xr500 Firmware 1.0.0.76 / 2.3.2.32+ Fix from $1,9502020-04-16 HIGH 8.0 CVE-2019-20705 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR… Xr500 Firmware 1.0.0.76 / 2.3.2.32+ Fix from $1,9502020-04-16 HIGH 8.0 CVE-2019-20706 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32. R7800 Firmware 1.0.2.60 / 2.3.2.32+ Fix from $1,9502020-04-16