Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-03-25 CVE-2020-10580 Command Injection vulnerability in Invigo Automatic Device Management 5.0
A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application.
network
low complexity
invigo CWE-77
8.8
2021-03-23 CVE-2021-29079 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
critical
9.6
2021-03-23 CVE-2021-29078 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
critical
9.6
2021-03-23 CVE-2021-29077 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
critical
9.6
2021-03-23 CVE-2021-29076 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
critical
9.6
2021-03-23 CVE-2021-29072 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an authenticated user.
low complexity
netgear CWE-77
8.4
2021-03-23 CVE-2021-29071 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an authenticated user.
low complexity
netgear CWE-77
critical
9.0
2021-03-23 CVE-2021-29070 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an authenticated user.
low complexity
netgear CWE-77
8.4
2021-03-23 CVE-2021-29069 Command Injection vulnerability in Netgear Wnr2000V5 Firmware, Xr450 Firmware and Xr500 Firmware
Certain NETGEAR devices are affected by command injection by an authenticated user.
low complexity
netgear CWE-77
8.4
2021-03-19 CVE-2021-26275 Command Injection vulnerability in Eslint-Fixer Project Eslint-Fixer
The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function.
network
low complexity
eslint-fixer-project CWE-77
critical
9.8