Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2020-2508
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitra…
Qts
4.5.1.1456+
HIGH 7.2
CVE-2020-17502
Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which is made available over https. …
Transform N
3.8+
HIGH 7.2
CVE-2020-17503
The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users…
Transform N
3.8+
HIGH 7.2
CVE-2020-17504
The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users…
Transform N
3.8+
CRITICAL 9.8
CVE-2020-17500
Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web ad…
Transform N
3.8+
HIGH 7.8
CVE-2018-19418EPSS 8%
Foxit PDF ActiveX before 5.5.1 allows remote code execution via command injection because of the lack of a security permission control.
Pdf Activex
5.5.1+
CRITICAL 9.8
CVE-2018-14067EPSS 7%
Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command execution, via a crafted payload to t…
Dv 360 Firmware
No fix yet
MEDIUM 6.8
CVE-2020-35794
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBS40V before 2.6.1.4, RBK752 before 3.2.15.25, RBR7…
Rbs40v Firmware
2.6.1.4 / 3.2.15.25+
HIGH 7.8
CVE-2020-35798
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.…
R6400v2 Firmware
1.0.2.74 / 1.0.4.26+
MEDIUM 6.8
CVE-2020-35790
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 …
D7800 Firmware
1.0.1.56 / 1.0.2.68+
MEDIUM 6.7
CVE-2020-35791
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.68, R8900 before 1.0.5.2, and R90…
R7800 Firmware
1.0.2.68 / 1.0.5.2+
MEDIUM 6.8
CVE-2020-35792
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7500v2 before 1.0.3.48, R8900 before 1.0.5.2, R9000…
R7500 Firmware
1.0.2.68 / 1.0.3.48+
MEDIUM 6.7
CVE-2020-35793
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.58, R7500v2 before 1.0.3.46, R780…
D7800 Firmware
1.0.1.58 / 1.0.2.74+
HIGH 8.4
CVE-2020-35777
NETGEAR DGN2200v1 devices before v1.0.0.58 are affected by command injection.
Dgn2200v1 Firmware
1.0.0.58+
HIGH 8.8
CVE-2020-25847
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulner…
Qts
4.5.1.1495+
HIGH 7.2
CVE-2020-29299
Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-pr…
Vpn Orchestrator
1.33 / 4.39+
MEDIUM 5.2
CVE-2020-26273
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before version 4.6.0, by using sqlite's AT…
Osquery
4.6.0+
CRITICAL 9.8
CVE-2020-24634
An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management pr…
Arubaos
2.1.0.2 / 2.2.0.1+
CRITICAL 9.8
CVE-2019-7198
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulner…
Quts Hero
4.4.3.1354 / 4.5.1.1456+
HIGH 7.2
CVE-2020-9115
ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An …
Manageone
Mitigation only
HIGH 7.2
CVE-2020-9116
Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to…
Fusioncompute
Mitigation only
CRITICAL 9.8
CVE-2019-19874
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution o…
Industrial Automation Aprol
Mitigation only
CRITICAL 9.8
CVE-2019-19875
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (using Python scripts) via the Apr…
Industrial Automation Aprol
Mitigation only
CRITICAL 9.8
CVE-2019-19872
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintende…
Industrial Automation Aprol
Mitigation only
HIGH 7.2
CVE-2020-2492
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Q…
Qts
4.4.3.1421+
HIGH 7.2
CVE-2020-2490
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Q…
Qts
4.4.3.1421+
MEDIUM 6.7
CVE-2020-9127
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some ma…
Nip6300 Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-23639
A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a remote attacker to execute arb…
Vport 461 Firmware
after 3.4
CRITICAL 9.8
CVE-2018-19950
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. …
Music Station
5.1.13 / 5.2.9+
HIGH 7.8
CVE-2020-7384EPSS 30%
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arb…
Metasploit
4.19.0+