Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
R7800 Firmware MEDIUM 6.8
CVE-2018-21108

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

Fix: 1.0.2.60+
Fix from $1,600 2020-04-23
R7800 Firmware MEDIUM 6.8
CVE-2018-21109

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

Fix: 1.0.2.60+
Fix from $1,600 2020-04-23
R7800 Firmware MEDIUM 6.8
CVE-2018-21110

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

Fix: 1.0.2.60+
Fix from $1,600 2020-04-23
R7800 Firmware MEDIUM 6.8
CVE-2018-21103

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

Fix: 1.0.2.60+
Fix from $1,600 2020-04-23
R7800 Firmware MEDIUM 6.8
CVE-2018-21104

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

Fix: 1.0.2.60+
Fix from $1,600 2020-04-23
R7800 Firmware MEDIUM 6.8
CVE-2018-21105

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

Fix: 1.0.2.60+
Fix from $1,600 2020-04-23
R7800 Firmware HIGH 8.0
CVE-2018-21101

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

Fix: 1.0.2.60+
Fix from $1,950 2020-04-23
Rx4 1500 Firmware MEDIUM 6.7
CVE-2020-8797

Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection),…

No fix yet
Fix from $1,600 2020-04-23
Metasploit HIGH 7.8
CVE-2020-7350

Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the libnotify plugin accepts unt…

Fix: 5.0.85+
Fix from $1,950 2020-04-22
Wac505 Firmware HIGH 8.8
CVE-2018-21127

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0…

Fix: 5.0.0.17+
Fix from $1,950 2020-04-22
Wac505 Firmware HIGH 8.8
CVE-2018-21130

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0…

Fix: 5.0.0.17+
Fix from $1,950 2020-04-22
Wac505 Firmware HIGH 8.8
CVE-2018-21126

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0…

Fix: 5.0.0.17+
Fix from $1,950 2020-04-22
Iqrouter Firmware CRITICAL 9.8
CVE-2020-11963

IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter In…

Fix: after 3.3.1
Fix from $2,300 2020-04-21
Emc Integrated Data Protection Appliance HIGH 7.2
CVE-2020-5350

Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remo…

Mitigation only
Fix from $1,950 2020-04-15
Oaklouds Ccm\@il CRITICAL 9.8
CVE-2020-10511

HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure configurations. Attackers can…

No fix yet
Fix from $2,300 2020-04-15
Cdm HIGH 8.8
CVE-2020-9478

An issue was discovered in Rubrik 5.0.3-2296. An OS command injection vulnerability allows an authenticated attacker to remotely execute arbitrary co…

Fix: 5.1.2+
Fix from $1,950 2020-04-13
Dsl Gs225 Firmware HIGH 7.2
CVE-2020-6765

D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after a supported CLI command, as demonstr…

Patch available
Fix from $1,950 2020-04-10
Webaccess\/nms HIGH 8.8
CVE-2020-10603

WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely.

Fix: 3.0.2+
Fix from $1,950 2020-04-09
Clamscan HIGH 8.1
CVE-2020-7613

clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_is_clamav_binary` function lo…

Fix: after 1.2.0
Fix from $1,950 2020-04-07
Npm Programmatic CRITICAL 9.8
CVE-2020-7614

npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validatio…

Fix: after 0.0.12
Fix from $2,300 2020-04-07
Fsa HIGH 7.8
CVE-2020-7615

fsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep.js#63' can be controlled by u…

Fix: after 0.5.1
Fix from $1,950 2020-04-07
Pulse Connect Secure HIGH 8.1
CVE-2020-11581EPSS 10%

An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris …

Fix: after 2020-04-06
Fix from $1,950 2020-04-06
Diskusage Ng CRITICAL 9.8
CVE-2020-7631

diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.

Fix: after 0.2.4
Fix from $2,300 2020-04-06
Node Mpv CRITICAL 9.8
CVE-2020-7632

node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.

Fix: after 1.4.3
Fix from $2,300 2020-04-06
Apiconnect Cli Plugins CRITICAL 9.8
CVE-2020-7633

apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.

Fix: after 6.0.1
Fix from $2,300 2020-04-06
Heroku Addonpool CRITICAL 9.8
CVE-2020-7634

heroku-addonpool through 0.1.15 is vulnerable to Command Injection.

Fix: after 0.1.15
Fix from $2,300 2020-04-06
Compass Compile CRITICAL 9.8
CVE-2020-7635

compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.

Fix: after 0.0.1
Fix from $2,300 2020-04-06
Adb Driver CRITICAL 9.8
CVE-2020-7636

adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function.

Fix: after 0.1.8
Fix from $2,300 2020-04-06
Install Package CRITICAL 9.8
CVE-2020-7628

umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.

Fix: after 1.1.6
Fix from $2,300 2020-04-02
Install Package CRITICAL 9.8
CVE-2020-7629

install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.

Fix: after 0.4.0
Fix from $2,300 2020-04-02