Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Pan Os HIGH 7.2
CVE-2020-2000

An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrup…

Fix: 8.1.16 / 9.0.10+
Fix from $1,950 2020-11-12
Windows 10 HIGH 7.8
CVE-2020-17010

Win32k Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2020-11-11
Ac1750 Firmware CRITICAL 9.8
CVE-2020-28347EPSS 77%

tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this…

Fix: 201029+
Fix from $2,300 2020-11-08
Integrated Management Controller HIGH 8.8
CVE-2020-3371

A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code …

Fix: 3.0+
Fix from $1,950 2020-11-06
Debian Linux CRITICAL 9.8
CVE-2020-16846 KEVEPSS 100%

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shel…

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2020-11-06
Fruitywifi HIGH 8.8
CVE-2020-24849

A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST …

Fix: after 2.4
Fix from $1,950 2020-11-05
Music Station CRITICAL 9.8
CVE-2018-19950

If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. …

Fix: 5.1.13 / 5.2.9+
Fix from $2,300 2020-11-02
Mailaudit HIGH 8.8
CVE-2020-25849

MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after…

Mitigation only
Fix from $1,950 2020-11-01
Eyesofnetwork HIGH 8.8
CVE-2020-27887

An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module…

Fix: after 5.3-8
Fix from $1,950 2020-10-29
My Cloud Firmware CRITICAL 9.8
CVE-2020-27744EPSS 6%

An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privil…

Fix: 5.04.114+
Fix from $2,300 2020-10-29
Qts CRITICAL 9.8
CVE-2018-19949 KEVEPSS 24%

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the fo…

Fix: 4.2.6 / 4.3.3.1161+
Fix from $2,300 2020-10-28
Winston Firmware CRITICAL 9.8
CVE-2020-16257

Winston 1.5.4 devices are vulnerable to command injection via the API.

No fix yet
Fix from $2,300 2020-10-28
Oscommerce CRITICAL 9.8
CVE-2020-27976EPSS 7%

osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the applicat…

Fix: 1.0.5.4+
Fix from $2,300 2020-10-28
My Cloud Firmware CRITICAL 9.8
CVE-2020-27158EPSS 7%

Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5…

Fix: 5.04.114+
Fix from $2,300 2020-10-27
My Cloud Firmware CRITICAL 9.8
CVE-2020-27159EPSS 6%

Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western …

Fix: 5.04.114+
Fix from $2,300 2020-10-27
My Cloud Firmware CRITICAL 9.8
CVE-2020-25765EPSS 6%

Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prio…

Fix: 5.04.114+
Fix from $2,300 2020-10-27
Ruckus Vriot HIGH 8.8
CVE-2020-26878EPSS 12%

Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoi…

Fix: after 1.5.1.0.21
Fix from $1,950 2020-10-26
Git Tag Annotation Action CRITICAL 9.6
CVE-2020-15272

In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can c…

Fix: 1.0.1+
Fix from $2,300 2020-10-26
Lookatme HIGH 8.8
CVE-2020-15271

In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Use…

Fix: 2.3.0+
Fix from $1,950 2020-10-26
Systeminformation HIGH 8.8
CVE-2020-7752EPSS 6%

This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's param…

Fix: 4.27.11+
Fix from $1,950 2020-10-26
Firepower Extensible Operating System MEDIUM 6.7
CVE-2020-3457

A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro…

Fix: 2.4.1.266 / 2.6.1.204+
Fix from $1,600 2020-10-21
Firepower Extensible Operating System HIGH 7.8
CVE-2020-3459

A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro…

Fix: 2.4.1.266 / 2.6.1.204+
Fix from $1,950 2020-10-21
Nagios Xi HIGH 7.2
CVE-2020-5791EPSS 79%

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating s…

Fix: after 5.7.3
Fix from $1,950 2020-10-20
Rconfig HIGH 8.8
CVE-2020-13778

rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to lib/ajaxHandlers/ajaxAddTemplat…

Fix: after 3.9.4
Fix from $1,950 2020-10-19
Gitea HIGH 7.2
CVE-2020-14144EPSS 95%

The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentati…

Fix: after 1.12.5
Fix from $1,950 2020-10-16
Qcmap MEDIUM 6.7
CVE-2020-25859

The QCMAP_CLI utility in the Qualcomm QCMAP software suite prior to versions released in October 2020 uses a system() call without validating the inp…

No fix yet
Fix from $1,600 2020-10-15
Introscope Enterprise Manager CRITICAL 10.0
CVE-2020-6364EPSS 6%

SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a…

Mitigation only
Fix from $2,300 2020-10-15
Bullet Lte Firmware HIGH 8.8
CVE-2020-17406EPSS 5%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE prior to v1.2.0-r1112. Authent…

Fix: 1.2.0-r1112+
Fix from $1,950 2020-10-13
Staros MEDIUM 6.7
CVE-2020-3601

A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate…

Fix: 21.19.n4+
Fix from $1,600 2020-10-08
Staros MEDIUM 6.7
CVE-2020-3602

A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate…

Fix: 21.19.n4+
Fix from $1,600 2020-10-08