Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
MEDIUM 6.8 CVE-2018-21108 NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user. R7800 Firmware 1.0.2.60+ Fix from $1,6002020-04-23 MEDIUM 6.8 CVE-2018-21109 NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user. R7800 Firmware 1.0.2.60+ Fix from $1,6002020-04-23 MEDIUM 6.8 CVE-2018-21110 NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user. R7800 Firmware 1.0.2.60+ Fix from $1,6002020-04-23 MEDIUM 6.8 CVE-2018-21103 NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user. R7800 Firmware 1.0.2.60+ Fix from $1,6002020-04-23 MEDIUM 6.8 CVE-2018-21104 NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user. R7800 Firmware 1.0.2.60+ Fix from $1,6002020-04-23 MEDIUM 6.8 CVE-2018-21105 NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user. R7800 Firmware 1.0.2.60+ Fix from $1,6002020-04-23 HIGH 8.0 CVE-2018-21101 NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user. R7800 Firmware 1.0.2.60+ Fix from $1,9502020-04-23 MEDIUM 6.7 CVE-2020-8797 Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection),… Rx4 1500 Firmware No fix yet Fix from $1,6002020-04-23 HIGH 7.8 CVE-2020-7350 Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the libnotify plugin accepts unt… Metasploit 5.0.85+ Fix from $1,9502020-04-22 HIGH 8.8 CVE-2018-21127 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0… Wac505 Firmware 5.0.0.17+ Fix from $1,9502020-04-22 HIGH 8.8 CVE-2018-21130 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0… Wac505 Firmware 5.0.0.17+ Fix from $1,9502020-04-22 HIGH 8.8 CVE-2018-21126 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0… Wac505 Firmware 5.0.0.17+ Fix from $1,9502020-04-22 CRITICAL 9.8 CVE-2020-11963 IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter In… Iqrouter Firmware after 3.3.1 Fix from $2,3002020-04-21 HIGH 7.2 CVE-2020-5350 Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remo… Emc Integrated Data Protection Appliance Mitigation only Fix from $1,9502020-04-15 CRITICAL 9.8 CVE-2020-10511 HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure configurations. Attackers can… Oaklouds Ccm\@il No fix yet Fix from $2,3002020-04-15 HIGH 8.8 CVE-2020-9478 An issue was discovered in Rubrik 5.0.3-2296. An OS command injection vulnerability allows an authenticated attacker to remotely execute arbitrary co… Cdm 5.1.2+ Fix from $1,9502020-04-13 HIGH 7.2 CVE-2020-6765 D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after a supported CLI command, as demonstr… Dsl Gs225 Firmware Patch available Fix from $1,9502020-04-10 HIGH 8.8 CVE-2020-10603 WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely. Webaccess\/nms 3.0.2+ Fix from $1,9502020-04-09 HIGH 8.1 CVE-2020-7613 clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_is_clamav_binary` function lo… Clamscan after 1.2.0 Fix from $1,9502020-04-07 CRITICAL 9.8 CVE-2020-7614 npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validatio… Npm Programmatic after 0.0.12 Fix from $2,3002020-04-07 HIGH 7.8 CVE-2020-7615 fsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep.js#63' can be controlled by u… Fsa after 0.5.1 Fix from $1,9502020-04-07 HIGH 8.1 CVE-2020-11581EPSS 10% An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris … Pulse Connect Secure after 2020-04-06 Fix from $1,9502020-04-06 CRITICAL 9.8 CVE-2020-7631 diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument. Diskusage Ng after 0.2.4 Fix from $2,3002020-04-06 CRITICAL 9.8 CVE-2020-7632 node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument. Node Mpv after 1.4.3 Fix from $2,3002020-04-06 CRITICAL 9.8 CVE-2020-7633 apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument. Apiconnect Cli Plugins after 6.0.1 Fix from $2,3002020-04-06 CRITICAL 9.8 CVE-2020-7634 heroku-addonpool through 0.1.15 is vulnerable to Command Injection. Heroku Addonpool after 0.1.15 Fix from $2,3002020-04-06 CRITICAL 9.8 CVE-2020-7635 compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument. Compass Compile after 0.0.1 Fix from $2,3002020-04-06 CRITICAL 9.8 CVE-2020-7636 adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function. Adb Driver after 0.1.8 Fix from $2,3002020-04-06 CRITICAL 9.8 CVE-2020-7628 umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization. Install Package after 1.1.6 Fix from $2,3002020-04-02 CRITICAL 9.8 CVE-2020-7629 install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument. Install Package after 0.4.0 Fix from $2,3002020-04-02