Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Nc200 Firmware HIGH 8.8
CVE-2020-12109EPSS 74%

Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3…

No fix yet
Fix from $1,950 2020-05-04
Nc260 Firmware HIGH 8.8
CVE-2020-12111EPSS 8%

Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.

No fix yet
Fix from $1,950 2020-05-04
Webmail CRITICAL 9.8
CVE-2020-12641 KEVEPSS 84%

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for …

Fix: 1.2.10 / 1.3.11+
Fix from $2,300 2020-05-04
Chrome Launcher CRITICAL 9.8
CVE-2020-7645

All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.

Fix: 0.13.2+
Fix from $2,300 2020-05-02
Trixbox HIGH 8.8
CVE-2020-7351EPSS 65%

An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute com…

Fix: after 2.8.0.4
Fix from $1,950 2020-05-01
Intelmq Manager HIGH 8.8
CVE-2020-11016

IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled messages given by user-input in…

Fix: 2.1.1+
Fix from $1,950 2020-04-30
Control M\/agent HIGH 8.8
CVE-2019-19217

BMC Control-M/Agent 7.0.00.000 allows OS Command Injection.

Mitigation only
Fix from $1,950 2020-04-30
Control M\/agent HIGH 8.8
CVE-2019-19220

BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).

Mitigation only
Fix from $1,950 2020-04-30
File Transfer Appliance CRITICAL 9.8
CVE-2019-5623

Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Comma…

No fix yet
Fix from $2,300 2020-04-29
Workcentre 3655 Firmware CRITICAL 9.8
CVE-2016-11061

Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do no…

Fix: 073.060.086.15410 / 073.190.086.15410+
Fix from $2,300 2020-04-29
Groupware HIGH 7.2
CVE-2020-7804

ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShellExec met…

Mitigation only
Fix from $1,950 2020-04-29
Smart Box Firmware HIGH 8.8
CVE-2020-12246

Beeline Smart Box 2.0.38 routers allow "Advanced settings > Other > Diagnostics" OS command injection via the Ping ping_ipaddr parameter, the Nslooku…

No fix yet
Fix from $1,950 2020-04-29
D7800 Firmware MEDIUM 6.8
CVE-2018-21225

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000 before 1.0.1.60, D7800 before 1.0.1.34, D8500 …

Fix: 1.0.1.30 / 1.0.1.34+
Fix from $1,600 2020-04-28
M4200 10mg Poe\+ Firmware CRITICAL 9.8
CVE-2017-18858

Certain NETGEAR devices are affected by command execution. This affects M4200-10MG-POE+ 12.0.2.11 and earlier, M4300-28G 12.0.2.11 and earlier, M4300…

Fix: after 12.0.2.11
Fix from $2,300 2020-04-28
Dgn2200 Firmware HIGH 7.2
CVE-2016-11054

NETGEAR DGN2200v4 devices before 2017-01-06 are affected by command execution and an FTP insecure root directory.

Fix: 2017-01-06+
Fix from $1,950 2020-04-28
Open Audit HIGH 8.8
CVE-2020-12078EPSS 10%

An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker c…

Patch available
Fix from $1,950 2020-04-28
Pixl Class CRITICAL 9.8
CVE-2020-7640

pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any …

Fix: 1.0.3+
Fix from $2,300 2020-04-27
R7800 Firmware HIGH 8.0
CVE-2018-21100

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

Fix: 1.0.2.60+
Fix from $1,950 2020-04-27
D7800 Firmware MEDIUM 6.8
CVE-2018-21152

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, R7500v2 before 1.0.3.26, R780…

Fix: 1.0.0.54 / 1.0.1.34+
Fix from $1,600 2020-04-27
D7800 Firmware MEDIUM 6.8
CVE-2018-21154

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, DM200 before 1.0.0.50, R6100 …

Fix: 1.0.0.50 / 1.0.0.122+
Fix from $1,600 2020-04-27
D7800 Firmware MEDIUM 6.8
CVE-2018-21157

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.28, R6700 before 1.0.1.44, R6900 …

Fix: 1.0.0.50 / 1.0.1.28+
Fix from $1,600 2020-04-27
R7800 Firmware MEDIUM 6.8
CVE-2018-21098

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

Fix: 1.0.2.60+
Fix from $1,600 2020-04-27
R7800 Firmware HIGH 8.0
CVE-2018-21099

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

Fix: 1.0.2.60+
Fix from $1,950 2020-04-27
Open Audit HIGH 8.8
CVE-2020-11941

An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.

No fix yet
Fix from $1,950 2020-04-27
Source HIGH 7.8
CVE-2020-12242

Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different us…

No fix yet
Fix from $1,950 2020-04-27
Big Iq Centralized Management CRITICAL 9.8
CVE-2020-5868

In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell commands on affected systems u…

Fix: after 6.1.0
Fix from $2,300 2020-04-24
R6220 Firmware HIGH 7.2
CVE-2018-21164

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.64 and WNDR3700v5 before 1.1.0.54.

Fix: 1.1.0.54 / 1.1.0.64+
Fix from $1,950 2020-04-23
D6400 Firmware CRITICAL 9.8
CVE-2018-21162

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0.0.78, EX6200 before 1.0.3.86,…

Fix: 1.0.0.64 / 1.0.0.78+
Fix from $2,300 2020-04-23
R7800 Firmware MEDIUM 6.8
CVE-2018-21106

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

Fix: 1.0.2.60+
Fix from $1,600 2020-04-23
R7800 Firmware MEDIUM 6.8
CVE-2018-21107

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

Fix: 1.0.2.60+
Fix from $1,600 2020-04-23