Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.0 CVE-2019-20707 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32. R7800 Firmware 1.0.2.60 / 2.3.2.32+ Fix from $1,9502020-04-16 HIGH 8.0 CVE-2019-20708 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR… Xr500 Firmware 1.0.0.76 / 2.3.2.32+ Fix from $1,9502020-04-16 HIGH 8.0 CVE-2019-20709 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR… Xr500 Firmware 1.0.0.76 / 2.3.2.32+ Fix from $1,9502020-04-16 HIGH 8.0 CVE-2019-20710 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR… Xr500 Firmware 1.0.0.76 / 2.3.2.32+ Fix from $1,9502020-04-16 HIGH 8.0 CVE-2019-20711 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR… Xr500 Firmware 1.0.0.76 / 2.3.2.32+ Fix from $1,9502020-04-16 MEDIUM 6.8 CVE-2019-20718 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.48, D6400 before 1.0.0.82, D7000v… D6220 Firmware Mitigation only Fix from $1,6002020-04-16 MEDIUM 6.8 CVE-2019-20688 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 … D3600 Firmware 1.0.0.63 / 1.0.0.75+ Fix from $1,6002020-04-16 MEDIUM 6.8 CVE-2019-20689 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6000 before 1.0.0.75, D6100 before 1.0.0.63, EX2700… D6000 Firmware 1.0.0.63 / 1.0.0.75+ Fix from $1,6002020-04-16 HIGH 8.0 CVE-2019-20680 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000v2 before 1.0.0.53, R6220 before 1.1.0.80, R626… D7000 Firmware 1.0.0.53 / 1.0.2.4+ Fix from $1,9502020-04-15 HIGH 7.8 CVE-2019-20655 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 and XR700 before 1.0.1.20. Xr500 Firmware 1.0.1.20 / 2.3.2.56+ Fix from $1,9502020-04-15 HIGH 7.2 CVE-2019-20659 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700… R6400 Firmware 1.0.2.8 / 1.0.3.10+ Fix from $1,9502020-04-15 MEDIUM 6.7 CVE-2019-20651 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 8.2.1.16 and WAC510 before 8.2.1.16. Wac505 Firmware 8.2.1.16+ Fix from $1,6002020-04-15 CRITICAL 9.8 CVE-2020-11789 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8,… R6400 Firmware 1.0.2.8 / 1.0.3.10+ Fix from $2,3002020-04-15 HIGH 8.8 CVE-2020-11770 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v… D6220 Firmware 1.0.0.52 / 1.0.0.86+ Fix from $1,9502020-04-15 HIGH 8.8 CVE-2020-10514 iCatch DVR firmware before 20200103 do not validate function parameter properly, resulting attackers executing arbitrary command. Dvr Firmware 20200103+ Fix from $1,9502020-04-15 HIGH 7.8 CVE-2019-14868 In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypas… Debian Linux 10.15.5+ Fix from $1,9502020-04-02 CRITICAL 9.8 CVE-2018-11106 NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: … Wc7500 Firmware 2.5.0.46 / 6.5.3.5+ Fix from $2,3002020-04-01 HIGH 7.2 CVE-2019-9507 The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the application incorrectly neutralizes … Avocent Umg 4000 Firmware Mitigation only Fix from $1,9502020-03-30 CRITICAL 9.8 CVE-2020-10826EPSS 39% /cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a … Vigor300b Firmware 1.5.1+ Fix from $2,3002020-03-26 HIGH 8.8 CVE-2020-6811 The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If … Firefox 68.6.0 / 74.0+ Fix from $1,9502020-03-25 HIGH 7.8 CVE-2020-3266 A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbitrary commands that are execu… Sd Wan Firmware 19.2.2+ Fix from $1,9502020-03-19 HIGH 8.1 CVE-2019-16012EPSS 54% A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attack… Sd Wan Firmware 19.2.2+ Fix from $1,9502020-03-19 MEDIUM 6.5 CVE-2019-12921EPSS 8% In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of Translate… Debian Linux 1.3.32+ Fix from $1,6002020-03-18 HIGH 7.8 CVE-2020-1980 A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. T… Pan Os 8.1.13+ Fix from $1,9502020-03-11 HIGH 8.8 CVE-2019-12430 An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to … GitLab Mitigation only Fix from $1,9502020-03-10 MEDIUM 6.7 CVE-2020-3176 A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of… Remote Phy 120 Firmware 7.7+ Fix from $1,6002020-03-04 CRITICAL 9.8 CVE-2019-15609 The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability. Kill Port Process 2.2.0+ Fix from $2,3002020-02-28 HIGH 7.2 CVE-2019-5323 There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not pro… Airwave 8.2.10.1+ Fix from $1,9502020-02-27 CRITICAL 9.8 CVE-2020-3924 DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command … Tat 77104g1 Firmware after 20181221_76216g3 Fix from $2,3002020-02-27 HIGH 8.8 CVE-2020-1790 GaussDB 200 with version of 6.5.1 have a command injection vulnerability. The software constructs part of a command using external input from users, … Gaussdb 200 Mitigation only Fix from $1,9502020-02-18