Vulnerabilities (CVE)

Filtered by CWE-78
Total 6047 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-7688 1 Mversion Project 1 Mversion 2026-06-17 4.6 MEDIUM 8.4 HIGH
The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.
CVE-2020-7646 1 Curlrequest Project 1 Curlrequest 2026-06-17 7.5 HIGH 9.8 CRITICAL
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
CVE-2020-7645 1 Google 1 Chrome-launcher 2026-06-17 7.5 HIGH 9.8 CRITICAL
All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.
CVE-2020-7640 1 Pixlcore 1 Pixl-class 2026-06-17 7.5 HIGH 9.8 CRITICAL
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.
CVE-2020-7636 1 Adb-driver Project 1 Adb-driver 2026-06-17 7.5 HIGH 9.8 CRITICAL
adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function.
CVE-2020-7635 1 Compass-compile Project 1 Compass-compile 2026-06-17 7.5 HIGH 9.8 CRITICAL
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
CVE-2020-7634 1 Heroku-addonpool Project 1 Heroku-addonpool 2026-06-17 7.5 HIGH 9.8 CRITICAL
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
CVE-2020-7633 1 Apiconnect-cli-plugins Project 1 Apiconnect-cli-plugins 2026-06-17 7.5 HIGH 9.8 CRITICAL
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.
CVE-2020-7632 1 Node-mpv Project 1 Node-mpv 2026-06-17 7.5 HIGH 9.8 CRITICAL
node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
CVE-2020-7631 1 Diskusage-ng Project 1 Diskusage-ng 2026-06-17 7.5 HIGH 9.8 CRITICAL
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.
CVE-2020-7630 1 Git-add-remote Project 1 Git-add-remote 2026-06-17 7.5 HIGH 9.8 CRITICAL
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.
CVE-2020-7629 1 Install-package Project 1 Install-package 2026-06-17 7.5 HIGH 9.8 CRITICAL
install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
CVE-2020-7628 2 Install-package Project, Umount Project 2 Install-package, Umount 2026-06-17 7.5 HIGH 9.8 CRITICAL
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
CVE-2020-7627 1 Node-key-sender Project 1 Node-key-sender 2026-06-17 7.5 HIGH 9.8 CRITICAL
node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.
CVE-2020-7626 1 Karma-mojo Project 1 Karma-mojo 2026-06-17 7.5 HIGH 9.8 CRITICAL
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
CVE-2020-7625 1 Op-browser Project 1 Op-browser 2026-06-17 7.5 HIGH 9.8 CRITICAL
op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.
CVE-2020-7624 1 Effect Project 1 Effect 2026-06-17 7.5 HIGH 9.8 CRITICAL
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
CVE-2020-7623 1 Jscover Project 1 Jscover 2026-06-17 7.5 HIGH 9.8 CRITICAL
jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.
CVE-2020-7621 1 Ibm 1 Strongloop Nginx Controller 2026-06-17 7.5 HIGH 9.8 CRITICAL
strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.
CVE-2020-7620 1 Netease 1 Pomelo-monitor 2026-06-17 7.5 HIGH 9.8 CRITICAL
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.