Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-11-27 CVE-2019-19874 Command Injection vulnerability in Br-Automation Industrial Automation Aprol
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08.
network
low complexity
br-automation CWE-77
critical
9.8
2020-11-27 CVE-2019-19872 Command Injection vulnerability in Br-Automation Industrial Automation Aprol
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08.
network
low complexity
br-automation CWE-77
critical
9.8
2020-11-16 CVE-2020-2492 Command Injection vulnerability in Qnap QTS
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands.
network
low complexity
qnap CWE-77
7.2
2020-11-16 CVE-2020-2490 Command Injection vulnerability in Qnap QTS
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands.
network
low complexity
qnap CWE-77
7.2
2020-11-13 CVE-2020-9127 Command Injection vulnerability in Huawei products
Some Huawei products have a command injection vulnerability.
local
low complexity
huawei CWE-77
6.7
2020-11-02 CVE-2020-23639 Command Injection vulnerability in Moxa Vport 461 Firmware 3.4
A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a remote attacker to execute arbitrary commands in Moxa's VPort 461 Series Industrial Video Servers.
network
low complexity
moxa CWE-77
critical
9.8
2020-11-02 CVE-2018-19950 Command Injection vulnerability in Qnap Music Station
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands.
network
low complexity
qnap CWE-77
critical
9.8
2020-10-29 CVE-2020-7384 Command Injection vulnerability in Rapid7 Metasploit
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.
local
low complexity
rapid7 CWE-77
7.8
2020-10-28 CVE-2018-19949 Command Injection vulnerability in Qnap QTS
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands.
network
low complexity
qnap CWE-77
critical
9.8
2020-10-23 CVE-2019-14719 Command Injection vulnerability in Verifone Mx900 Firmware 30251000
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager.
local
low complexity
verifone CWE-77
7.8