Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Aterm Sa3500g Firmware MEDIUM 6.8
CVE-2020-5636

Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specially crafted request to a spec…

Fix: 3.5.9+
Fix from $1,600 2020-12-14
Corenlp Js Prefab CRITICAL 9.8
CVE-2020-28439

This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package '…

Mitigation only
Fix from $2,300 2020-12-11
Corenlp Js Interface CRITICAL 9.8
CVE-2020-28440

All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.

Mitigation only
Fix from $2,300 2020-12-11
Ap5100w Firmware CRITICAL 9.8
CVE-2020-15357

Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to execute arbitrary commands via a …

Fix: after 1.01.097
Fix from $2,300 2020-12-11
Edgeconnect Enterprise MEDIUM 6.8
CVE-2020-12148

A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbi…

Fix: 8.1.9.15 / 8.3.0.8+
Fix from $1,600 2020-12-11
Edgeconnect Enterprise MEDIUM 6.8
CVE-2020-12149

The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled…

Fix: 8.1.9.15 / 8.3.0.8+
Fix from $1,600 2020-12-11
Node Notifier MEDIUM 5.6
CVE-2020-7789

This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not …

Fix: 8.0.1+
Fix from $1,600 2020-12-11
Ubilling CRITICAL 9.8
CVE-2020-29311EPSS 6%

Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being trigg…

No fix yet
Fix from $2,300 2020-12-10
Icms CRITICAL 9.8
CVE-2020-19142

iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.

No fix yet
Fix from $2,300 2020-12-10
Icms CRITICAL 9.8
CVE-2020-19527

iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.

No fix yet
Fix from $2,300 2020-12-10
Quts Hero CRITICAL 9.8
CVE-2019-7198

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulner…

Fix: 4.4.3.1354 / 4.5.1.1456+
Fix from $2,300 2020-12-10
A3002r Firmware HIGH 8.8
CVE-2020-25499

TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality…

Fix: 1.0.0-b20201028.1743 / 1.0.0-b20201103.1713+
Fix from $1,950 2020-12-09
Business Warehouse CRITICAL 9.1
CVE-2020-26838

SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacke…

Mitigation only
Fix from $2,300 2020-12-09
Zeroshell CRITICAL 9.8
CVE-2020-29390EPSS 40%

Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated …

No fix yet
Fix from $2,300 2020-11-30
V1600d Firmware CRITICAL 9.8
CVE-2020-29381

An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4…

Mitigation only
Fix from $2,300 2020-11-29
Systeminformation CRITICAL 9.8
CVE-2020-26245

npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rew…

Fix: 4.30.5+
Fix from $2,300 2020-11-27
Systeminformation HIGH 7.3
CVE-2020-7778

This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to exe…

Fix: 4.30.2+
Fix from $1,950 2020-11-26
72408a Firmware CRITICAL 9.8
CVE-2020-29056

An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B,…

No fix yet
Fix from $2,300 2020-11-24
Identity Manager CRITICAL 9.1
CVE-2020-4006 KEVEPSS 17%

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

Fix: after 8.2
Fix from $2,300 2020-11-23
Interscan Web Security Virtual Appliance HIGH 7.2
CVE-2020-28581EPSS 45%

A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, rem…

No fix yet
Fix from $1,950 2020-11-18
Dna Spaces\ CRITICAL 9.8
CVE-2020-3586

A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitr…

Fix: after 2.2
Fix from $2,300 2020-11-18
Interscan Web Security Virtual Appliance HIGH 7.2
CVE-2020-28580EPSS 45%

A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote…

No fix yet
Fix from $1,950 2020-11-18
Asyncos HIGH 7.8
CVE-2020-3367

A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Security Appliance) could allow a…

Fix: 11.7.2-011 / 11.8.2-009+
Fix from $1,950 2020-11-18
Tl Wpa4220 Firmware HIGH 8.8
CVE-2020-24297

httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS commands by sending crafted POST…

No fix yet
Fix from $1,950 2020-11-18
Debian Linux HIGH 8.8
CVE-2020-26217EPSS 85%

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands on…

Fix: 1.4.14 / 5.15.14+
Fix from $1,950 2020-11-16
Qts HIGH 7.2
CVE-2020-2492

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Q…

Fix: 4.4.3.1421+
Fix from $1,950 2020-11-16
Virtual Apps And Desktops HIGH 8.8
CVE-2020-8270

An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 …

Fix: after 2006
Fix from $1,950 2020-11-16
Sd Wan HIGH 8.8
CVE-2020-8273

Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.

Fix: 10.2.8 / 11.1.2b+
Fix from $1,950 2020-11-16
Qts HIGH 7.2
CVE-2020-2490

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Q…

Fix: 4.4.3.1421+
Fix from $1,950 2020-11-16
Couchbase Server CRITICAL 9.8
CVE-2020-24719EPSS 23%

Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (…

Fix: 6.6.0+
Fix from $2,300 2020-11-12