Vulnerabilities (CVE)

Filtered by CWE-78
Total 3597 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-28494 1 Totaljs 1 Total.js 2021-07-21 7.5 HIGH 8.6 HIGH
This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build the command that is then executed using child_process.spawn. The issue occurs because child_process.spawn is called with the option shell set to true and because the type parameter is not properly sanitized.
CVE-2020-8126 1 Ui 1 Edgeswitch 2021-07-21 7.2 HIGH 7.8 HIGH
A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execution, allowing an operator user (Privilege-1) to escalate privileges and became administrator (Privilege-15).
CVE-2020-7636 1 Adb-driver Project 1 Adb-driver 2021-07-21 7.5 HIGH 9.8 CRITICAL
adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function.
CVE-2020-28490 1 Async-git Project 1 Async-git 2021-07-21 7.5 HIGH 9.8 CRITICAL
The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb')
CVE-2020-26878 1 Commscope 2 Ruckus Iot Module, Ruckus Vriot 2021-07-21 9.0 HIGH 8.8 HIGH
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.
CVE-2020-7613 1 Clamscan Project 1 Clamscan 2021-07-21 6.8 MEDIUM 8.1 HIGH
clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_is_clamav_binary` function located within `Index.js`. It should be noted that this vulnerability requires a pre-requisite that a folder should be created with the same command that will be chained to execute. This lowers the risk of this issue.
CVE-2020-6757 1 Rasilient 2 Pixelstor 5000, Pixelstor 5000 Firmware 2021-07-21 6.5 MEDIUM 8.8 HIGH
contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute code via the name parameter.
CVE-2020-16257 1 Winstonprivacy 2 Winston, Winston Firmware 2021-07-21 10.0 HIGH 9.8 CRITICAL
Winston 1.5.4 devices are vulnerable to command injection via the API.
CVE-2020-10209 1 Amino 12 Ak45x, Ak45x Firmware, Ak5xx and 9 more 2021-07-21 9.3 HIGH 8.1 HIGH
Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows man-in-the-middle attackers to execute arbitrary commands with root level privileges.
CVE-2020-28440 1 Corenlp-js-interface Project 1 Corenlp-js-interface 2021-07-21 7.5 HIGH 9.8 CRITICAL
All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.
CVE-2020-7631 1 Diskusage-ng Project 1 Diskusage-ng 2021-07-21 7.5 HIGH 9.8 CRITICAL
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.
CVE-2020-7605 1 Gulp-tape Project 1 Gulp-tape 2021-07-21 7.5 HIGH 9.8 CRITICAL
gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of 'gulp-tape' options.
CVE-2020-7785 1 Node-ps Project 1 Node-ps 2021-07-21 7.5 HIGH 9.8 CRITICAL
This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js.
CVE-2020-6948 1 Hashbrowncms 1 Hashbrown Cms 2021-07-21 7.5 HIGH 9.8 CRITICAL
A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, and password.
CVE-2020-7698 1 Gerapy 1 Gerapy 2021-07-21 7.5 HIGH 9.8 CRITICAL
This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.
CVE-2020-29056 2 Cdata, Cdatatec 57 Fd1104 Firmware, 72408a, 72408a Firmware and 54 more 2021-07-21 10.0 HIGH 9.8 CRITICAL
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. One can escape from a shell and acquire root privileges by leveraging the TFTP download configuration.
CVE-2020-25094 1 Logrhythm 1 Platform Manager 2021-07-21 10.0 HIGH 9.8 CRITICAL
LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges.
CVE-2020-10208 1 Amino 12 Ak45x, Ak45x Firmware, Ak5xx and 9 more 2021-07-21 9.0 HIGH 9.9 CRITICAL
Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows authenticated remote attackers to execute arbitrary commands with root user privileges.
CVE-2020-15489 1 Wavlink 2 Wl-wn530hg4, Wl-wn530hg4 Firmware 2021-07-21 10.0 HIGH 9.8 CRITICAL
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges.
CVE-2020-12620 1 Pi-hole 1 Pi-hole 2021-07-21 7.2 HIGH 7.8 HIGH
Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection (shell metacharacters after an IP address).