CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,843 vulnerabilities with CWE-74
CVE-2017-18734 HIGH
NETGEAR devices - Command Injection
CVSS 8.8
CVE-2017-18754 MEDIUM
NETGEAR WNDR3700v4 < 1.0.2.88, WNDR4300v1 < 1.0.2.90, WNR2000v5 < 1.0.0.58 - Authenticated OS Command Injection
CVSS 6.8
CVE-2017-18767 MEDIUM
NETGEAR devices - Command Injection
CVSS 6.8
CVE-2017-18764 HIGH
NETGEAR devices <various - Command Injection
CVSS 8.8
CVE-2017-18762 HIGH
NETGEAR devices - Command Injection
CVSS 8.8
CVE-2017-18787 HIGH
NETGEAR D6200/JNR1010/JR6150/JWNR2010/PR2000/R6050/WNR1000/WNR2020/WNR2050 Firmware - OS Command Injection
CVSS 7.8
CVE-2017-18786 HIGH
NETGEAR D6200/JNR1010/JR6150/JWNR2010/PR2000/R6050/WNR1000/WNR2020/WNR2050 Firmware - OS Command Injection
CVSS 7.8
CVE-2017-18773 MEDIUM
NETGEAR Devices - Command Injection
CVSS 6.7
CVE-2017-18788 MEDIUM
NETGEAR devices <various - Command Injection
CVSS 6.7
CVE-2017-18801 MEDIUM
NETGEAR R6220/R6700/R6800/WNDR3700/D7000 Firmware - OS Command Injection
CVSS 6.7
CVE-2017-18796 MEDIUM
NETGEAR R6400/R6700/R6900/R7000/R7000P/R6900P/R7800 Firmware - OS Command Injection
CVSS 6.7
CVE-2017-18795 MEDIUM
NETGEAR D6220 and D6100 - OS Command Injection
CVSS 6.7
CVE-2017-18794 HIGH
NETGEAR R6300v2/R6400/R6700/R7000/R7100LG/R7900/R8000/R8500/D6100 - OS Command Injection
CVSS 8.4
CVE-2017-18793 MEDIUM
NETGEAR R7800 <1.0.2.36 - Command Injection
CVSS 6.7
CVE-2017-18792 HIGH
NETGEAR D6100 <1.0.0.50_0.0.50 - Command Injection
CVSS 8.4
CVE-2017-18805 MEDIUM
NETGEAR WAC510/WAC120/WNDAP620/WND930/WN604/WNDAP660/WNDAP350/WNAP320/WNAP210/WNDAP360 Firmware - OS Command Injection
CVSS 6.7
CVE-2017-18804 MEDIUM
NETGEAR <1.0.2.16-1.0.2.4 - Command Injection
CVSS 6.7
CVE-2017-18802 MEDIUM
NETGEAR R6100/R7500/R7800/EX6200/D7800 Firmware - OS Command Injection
CVSS 6.7
CVE-2017-18806 MEDIUM
NETGEAR WAC510/WAC120/WNDAP620/WND930/WN604/WNDAP660/WNDAP350/WNAP320/WNAP210/WNDAP360 Firmware - OS Command Injection
CVSS 6.7
CVE-2017-18849 HIGH
NETGEAR devices - Command Injection
CVSS 7.8
CVE-2017-18841 MEDIUM
NETGEAR R6220/R6700/R6800/WNDR3700/D7000 - OS Command Injection
CVSS 6.7
CVE-2017-18851 MEDIUM
NETGEAR D8500/R6400/R8300/R8500/R6100 Firmware - Authenticated Command Injection
CVSS 6.7
CVE-2017-18652 CRITICAL
Samsung Android M(6.0) and N(7.x) - Remote Code Execution via SVoice Dynamic Library Manipulation
CVSS 9.8
CVE-2017-18634 CRITICAL
Newspaper Theme <6.7.2 - Code Injection
CVSS 9.8
CVE-2017-18605 CRITICAL
Gravitate-qa-tracker <1.2.1 - Code Injection
CVSS 9.8
Details
Vulnerabilities 4,843
Exploit Likelihood High