Vulnerabilities (CVE)

Filtered by CWE-77
Total 2218 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-2490 1 Qnap 1 Qts 2024-11-21 6.5 MEDIUM 7.2 HIGH
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
CVE-2020-29548 1 Smartertools 1 Smartermail 2024-11-21 6.8 MEDIUM 8.1 HIGH
An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS command, injecting plaintext commands into an encrypted user session.
CVE-2020-29299 1 Zyxel 7 Atp, Nsg, Nsg Firmware and 4 more 2024-11-21 9.0 HIGH 7.2 HIGH
Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38, and NSG before 1.33 patch 4.
CVE-2020-28908 1 Nagios 1 Fusion 2024-11-21 7.5 HIGH 9.8 CRITICAL
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.
CVE-2020-28902 1 Nagios 1 Fusion 2024-11-21 10.0 HIGH 9.8 CRITICAL
Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.
CVE-2020-28901 1 Nagios 1 Fusion 2024-11-21 10.0 HIGH 9.8 CRITICAL
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.
CVE-2020-28453 1 Npos-tesseract Project 1 Npos-tesseract 2024-11-21 N/A 9.4 CRITICAL
This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
CVE-2020-28451 1 Image-tiler Project 1 Image-tiler 2024-11-21 N/A 9.8 CRITICAL
This affects the package image-tiler before 2.0.2.
CVE-2020-28447 1 Xopen Project 1 Xopen 2024-11-21 N/A 9.8 CRITICAL
This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)
CVE-2020-28446 1 Ntesseract Project 1 Ntesseract 2024-11-21 N/A 9.8 CRITICAL
The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.
CVE-2020-28445 1 Npm-help Project 1 Npm-help 2024-11-21 N/A 9.8 CRITICAL
This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.
CVE-2020-28443 1 Sonar-wrapper Project 1 Sonar-wrapper 2024-11-21 N/A 9.8 CRITICAL
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
CVE-2020-28438 1 Deferred-exec Project 1 Deferred-exec 2024-11-21 N/A 9.8 CRITICAL
This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js
CVE-2020-28437 1 Heroku-env Project 1 Heroku-env 2024-11-21 N/A 9.4 CRITICAL
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
CVE-2020-28436 1 Google-cloudstorage-commands Project 1 Google-cloudstorage-commands 2024-11-21 N/A 7.3 HIGH
This affects all versions of package google-cloudstorage-commands.
CVE-2020-28435 1 Ffmpeg-sdk Project 1 Ffmpeg-sdk 2024-11-21 N/A 9.4 CRITICAL
This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.
CVE-2020-28434 1 Gitblame Project 1 Gitblame 2024-11-21 N/A 9.4 CRITICAL
This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
CVE-2020-28433 1 Node-latex-pdf Project 1 Node-latex-pdf 2024-11-21 N/A 7.3 HIGH
This affects all versions of package node-latex-pdf.
CVE-2020-28425 1 Curljs Project 1 Curljs 2024-11-21 N/A 7.3 HIGH
This affects all versions of package curljs.
CVE-2020-28423 1 Monorepo-build Project 1 Monorepo-build 2024-11-21 N/A 9.8 CRITICAL
This affects all versions of package monorepo-build.