Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-07-14 CVE-2020-11084 Command Injection vulnerability in Ipear Project Ipear 0.6.14/0.6.15/0.7.0
In iPear, the manual execution of the eval() function can lead to command injection.
network
low complexity
ipear-project CWE-77
5.4
2020-06-30 CVE-2020-5601 Command Injection vulnerability in NTA E-Tax Reception System 1.0.0.0
Chrome Extension for e-Tax Reception System Ver1.0.0.0 allows remote attackers to execute an arbitrary command via unspecified vectors.
network
low complexity
nta CWE-77
8.8
2020-06-26 CVE-2020-9583 Command Injection vulnerability in Magento
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability.
network
low complexity
magento CWE-77
critical
9.8
2020-06-26 CVE-2020-9582 Command Injection vulnerability in Magento
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability.
network
low complexity
magento CWE-77
critical
9.8
2020-06-26 CVE-2020-9578 Command Injection vulnerability in Magento
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability.
network
low complexity
magento CWE-77
critical
9.8
2020-06-26 CVE-2020-9576 Command Injection vulnerability in Magento
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability.
network
low complexity
magento CWE-77
critical
9.8
2020-06-24 CVE-2020-14472 Command Injection vulnerability in Draytek products
On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.
network
low complexity
draytek CWE-77
critical
9.8
2020-06-24 CVE-2020-10561 Command Injection vulnerability in MI Mijia Inkjet Printer Firmware
An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138.
network
low complexity
mi CWE-77
critical
9.8
2020-06-23 CVE-2020-12782 Command Injection vulnerability in Openfind Mailaudit and Mailgates
Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized access to system files.
network
low complexity
openfind CWE-77
critical
9.8
2020-06-18 CVE-2020-14442 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
8.8