Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-08-08 CVE-2020-36455 Command Injection vulnerability in Brokenlamp Slock
An issue was discovered in the slock crate through 2020-11-17 for Rust.
network
high complexity
brokenlamp CWE-77
8.1
2021-08-08 CVE-2020-36456 Command Injection vulnerability in Toolshed Project Toolshed
An issue was discovered in the toolshed crate through 2020-11-15 for Rust.
network
high complexity
toolshed-project CWE-77
8.1
2021-08-08 CVE-2020-36457 Command Injection vulnerability in Lever Project Lever 0.0.0/0.1.0/0.1.1
An issue was discovered in the lever crate before 0.1.1 for Rust.
network
high complexity
lever-project CWE-77
8.1
2021-08-08 CVE-2020-36459 Command Injection vulnerability in Dces Project Dces
An issue was discovered in the dces crate through 2020-12-09 for Rust.
network
high complexity
dces-project CWE-77
8.1
2021-08-08 CVE-2020-36461 Command Injection vulnerability in Noise Search Project Noise Search
An issue was discovered in the noise_search crate through 2020-12-10 for Rust.
network
high complexity
noise-search-project CWE-77
8.1
2021-08-08 CVE-2020-36462 Command Injection vulnerability in Syncpool Project Syncpool
An issue was discovered in the syncpool crate before 0.1.6 for Rust.
network
high complexity
syncpool-project CWE-77
8.1
2021-08-08 CVE-2020-36463 Command Injection vulnerability in Multiqueue Project Multiqueue
An issue was discovered in the multiqueue crate through 2020-12-25 for Rust.
network
high complexity
multiqueue-project CWE-77
8.1
2021-08-08 CVE-2021-38189 Command Injection vulnerability in Lettre
An issue was discovered in the lettre crate before 0.9.6 for Rust.
network
low complexity
lettre CWE-77
critical
9.8
2021-08-07 CVE-2021-38173 Command Injection vulnerability in multiple products
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys.
network
low complexity
digint debian fedoraproject CWE-77
critical
9.8
2021-08-07 CVE-2021-38169 Command Injection vulnerability in Roxy-Wi
Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.
network
low complexity
roxy-wi CWE-77
8.8