Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-03-23 CVE-2021-29078 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
critical
9.6
2021-03-23 CVE-2021-29077 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
critical
9.6
2021-03-23 CVE-2021-29076 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
critical
9.6
2021-03-23 CVE-2021-29072 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an authenticated user.
low complexity
netgear CWE-77
8.4
2021-03-23 CVE-2021-29071 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an authenticated user.
low complexity
netgear CWE-77
critical
9.0
2021-03-23 CVE-2021-29070 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an authenticated user.
low complexity
netgear CWE-77
8.4
2021-03-23 CVE-2021-29069 Command Injection vulnerability in Netgear Wnr2000V5 Firmware, Xr450 Firmware and Xr500 Firmware
Certain NETGEAR devices are affected by command injection by an authenticated user.
low complexity
netgear CWE-77
8.4
2021-03-19 CVE-2021-26275 Command Injection vulnerability in Eslint-Fixer Project Eslint-Fixer
The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function.
network
low complexity
eslint-fixer-project CWE-77
critical
9.8
2021-03-04 CVE-2020-8298 Command Injection vulnerability in Fs-Path Project Fs-Path
fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `removeSync` methods.
network
low complexity
fs-path-project CWE-77
critical
9.8
2021-02-27 CVE-2021-3148 Command Injection vulnerability in multiple products
An issue was discovered in SaltStack Salt before 3002.5.
network
low complexity
saltstack fedoraproject debian CWE-77
critical
9.8