Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-06-26 CVE-2020-9576 Command Injection vulnerability in Magento
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability.
network
low complexity
magento CWE-77
critical
9.8
2020-06-24 CVE-2020-14472 Command Injection vulnerability in Draytek products
On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.
network
low complexity
draytek CWE-77
critical
9.8
2020-06-24 CVE-2020-10561 Command Injection vulnerability in MI Mijia Inkjet Printer Firmware
An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138.
network
low complexity
mi CWE-77
critical
9.8
2020-06-23 CVE-2020-12782 Command Injection vulnerability in Openfind Mailaudit and Mailgates
Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized access to system files.
network
low complexity
openfind CWE-77
critical
9.8
2020-06-18 CVE-2020-4059 Command Injection vulnerability in Mversion Project Mversion
In mversion before 2.0.0, there is a command injection vulnerability.
network
low complexity
mversion-project CWE-77
7.3
2020-06-18 CVE-2020-14442 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
8.8
2020-06-18 CVE-2020-14441 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
8.8
2020-06-18 CVE-2020-14440 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
8.8
2020-06-18 CVE-2020-14439 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
8.8
2020-06-18 CVE-2020-14438 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
8.8