Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Usvn CRITICAL 9.9
CVE-2020-17363

USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHu…

Fix: 1.0.9+
Fix from $2,300 2020-12-31
Vigor2960 Firmware HIGH 8.8
CVE-2020-19664EPSS 5%

DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.

Fix: after 1.5.1
Fix from $1,950 2020-12-31
Nms300 Firmware HIGH 8.8
CVE-2020-35789

NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.

Fix: 1.6.0.27+
Fix from $1,950 2020-12-30
Ak45x Firmware CRITICAL 9.9
CVE-2020-10208

Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B …

No fix yet
Fix from $2,300 2020-12-30
Ak45x Firmware HIGH 8.1
CVE-2020-10209

Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx se…

No fix yet
Fix from $1,950 2020-12-30
Qts HIGH 8.8
CVE-2020-25847

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulner…

Fix: 4.5.1.1495+
Fix from $1,950 2020-12-29
Klog Server CRITICAL 9.8
CVE-2020-35729EPSS 88%

KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.

No fix yet
Fix from $2,300 2020-12-27
Re6500 Firmware CRITICAL 9.8
CVE-2020-35713EPSS 33%

Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters …

Fix: 1.0.012.001+
Fix from $2,300 2020-12-26
Re6500 Firmware HIGH 8.8
CVE-2020-35714

Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in c…

Fix: 1.0.011.001+
Fix from $1,950 2020-12-26
Re6500 Firmware HIGH 8.8
CVE-2020-35715

Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters in a filenam…

Fix: 1.0.012.001+
Fix from $1,950 2020-12-26
Tos CRITICAL 9.8
CVE-2020-28188EPSS 97%

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/m…

Fix: after 4.2.06
Fix from $2,300 2020-12-24
Terramaster Operating System CRITICAL 9.8
CVE-2020-35665EPSS 78%

An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in includ…

Fix: after 4.2.06
Fix from $2,300 2020-12-23
Urve CRITICAL 9.8
CVE-2020-29552

An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0%3bpowershell+-c+" substring,…

No fix yet
Fix from $2,300 2020-12-23
Dsl2888a Firmware HIGH 8.0
CVE-2020-24581EPSS 14%

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not r…

No fix yet
Fix from $1,950 2020-12-22
Hugo HIGH 8.5
CVE-2020-26284

Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc docu…

Fix: 0.79.1+
Fix from $1,950 2020-12-21
Webmin HIGH 8.8
CVE-2020-35606EPSS 28%

Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with…

Fix: after 1.962
Fix from $1,950 2020-12-21
Openserver CRITICAL 9.8
CVE-2020-25494EPSS 39%

Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels paramet…

No fix yet
Fix from $2,300 2020-12-18
Pfc 100 Firmware CRITICAL 9.8
CVE-2020-12522

The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC …

Fix: after 10
Fix from $2,300 2020-12-17
Interscan Web Security Virtual Appliance CRITICAL 9.8
CVE-2020-8466EPSS 64%

A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled,…

No fix yet
Fix from $2,300 2020-12-17
Platform Manager CRITICAL 9.8
CVE-2020-25094

LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSo…

No fix yet
Fix from $2,300 2020-12-17
Systeminformation HIGH 8.8
CVE-2020-26274

In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a s…

Fix: 4.31.1+
Fix from $1,950 2020-12-16
Connection Tester CRITICAL 9.8
CVE-2020-7781

This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vu…

Fix: 0.2.1+
Fix from $2,300 2020-12-16
Netcrunch HIGH 8.8
CVE-2019-14479

AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can execute arbitrary code on the se…

No fix yet
Fix from $1,950 2020-12-16
N Central HIGH 8.8
CVE-2020-25618

An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is…

Mitigation only
Fix from $1,950 2020-12-16
Opentsdb CRITICAL 9.8
CVE-2020-35476EPSS 85%

A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to …

Fix: after 2.4.0
Fix from $2,300 2020-12-16
Struts MEDIUM 6.8
CVE-2020-26259EPSS 82%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion o…

Fix: 1.4.15 / 6.0.0+
Fix from $1,600 2020-12-16
Dsr 150 Firmware HIGH 8.8
CVE-2020-25757

A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command API…

Fix: after 3.17
Fix from $1,950 2020-12-15
Dsr 150 Firmware HIGH 8.8
CVE-2020-25759

An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticat…

Fix: after 3.17
Fix from $1,950 2020-12-15
Gateone CRITICAL 9.8
CVE-2020-20184

GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.

No fix yet
Fix from $2,300 2020-12-14
Aterm Sa3500g Firmware HIGH 8.8
CVE-2020-5635

Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specific URL,…

Fix: 3.5.9+
Fix from $1,950 2020-12-14