Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-19949 KEVEPSS 24%
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the fo…
Qts
4.2.6 / 4.3.3.1161+
HIGH 7.8
CVE-2019-14719
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager.
Mx900 Firmware
Mitigation only
MEDIUM 6.7
CVE-2020-11496
Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitrary code. This firmware lacks …
Sprecon E
8.64b+
HIGH 7.8
CVE-2020-9862
A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6,…
Safari
6.2.8 / 7.20+
HIGH 7.2
CVE-2020-4636
IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503.
Resilient Security Orchestration Automation And Response
Mitigation only
HIGH 8.0
CVE-2020-26929
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.
R6230 Firmware
1.1.0.100+
HIGH 7.1
CVE-2020-26914
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR615…
D6200 Firmware
1.0.0.42 / 1.0.0.66+
HIGH 8.8
CVE-2020-26920
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.3.110, SRR60 before 2.5.3.110…
Srk60 Firmware
2.5.3.110+
MEDIUM 6.7
CVE-2020-26922
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC76…
Wc7500 Firmware
6.5.5.24+
HIGH 8.8
CVE-2020-26907
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.16.6, RBR850 before 3.2.16.6…
Rbk852 Firmware
3.2.16.6+
HIGH 8.8
CVE-2020-26909
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.58 and R7500v2 before 1.0.3…
D7800 Firmware
1.0.1.58 / 1.0.3.48+
MEDIUM 6.8
CVE-2020-26910
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR7…
Cbr40 Firmware
2.5.0.10 / 3.2.15.25+
HIGH 8.8
CVE-2020-26902
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBR750 before 3.2.15.…
Rbk752 Firmware
3.2.15.25+
MEDIUM 5.0
CVE-2020-15228
In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Actions Runner over stdout by ge…
Toolkit
1.2.6+
HIGH 7.8
CVE-2020-0130
In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system pr…
Android
Mitigation only
CRITICAL 9.8
CVE-2020-11698EPSS 74%
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote a…
Spamtitan
No fix yet
CRITICAL 9.1
CVE-2020-24561EPSS 5%
A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system.…
Serverprotect
Mitigation only
CRITICAL 9.8
CVE-2020-14100EPSS 5%
In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator…
R3600 Firmware
1.0.66+
HIGH 7.0
CVE-2020-14342
It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. A…
Fedora
after 6.10
CRITICAL 9.8
CVE-2020-11117EPSS 20%
u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in r…
Ipq4019 Firmware
No fix yet
MEDIUM 6.8
CVE-2020-9199
B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with high privileges may exploit t…
B2368 22 Firmware
Mitigation only
HIGH 8.8
CVE-2020-25079 KEVEPSS 53%
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated comma…
Dcs 4703e Firmware
1.03.02 / 1.03.04+
HIGH 8.8
CVE-2020-25067
NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker.
R8300 Firmware
1.0.2.134+
HIGH 8.8
CVE-2020-10518
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-cont…
GitHub
2.19.21 / 2.20.15+
HIGH 8.8
CVE-2020-15642EPSS 7%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marvell QConvergeConsole 5.5.0.64.…
Qconvergeconsole
5.5.00.73+
HIGH 7.2
CVE-2019-11853
Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.
Aleos
4.9.4 / 4.11.0+
CRITICAL 9.8
CVE-2020-8211
Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 an…
Xenmobile Server
after 10.8.0
HIGH 8.8
CVE-2020-8233
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell comma…
Edgeswitch Firmware
1.9.0+
HIGH 8.8
CVE-2020-9242
FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain parameters post from user, successful…
Fusioncompute
Mitigation only
CRITICAL 9.8
CVE-2020-7697
This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affected Area require('../server/g…
Mock2easy
No fix yet