Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Dap 1360u Firmware HIGH 8.8
CVE-2020-26582

D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the IP JSON value fo…

Fix: 3.0.1+
Fix from $1,950 2020-10-06
Wn530h4 Firmware CRITICAL 9.8
CVE-2020-12124EPSS 75%

A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to e…

Mitigation only
Fix from $2,300 2020-10-02
Domos HIGH 7.5
CVE-2020-14293EPSS 5%

conf_datetime in Secudos DOMOS 5.8 allows remote attackers to execute arbitrary commands as root via shell metacharacters in the zone field (obtained…

Fix: after 5.8
Fix from $1,950 2020-10-02
Ng Packagr MEDIUM 6.6
CVE-2020-7735

The package ng-packagr before 10.1.1 are vulnerable to Command Injection via the styleIncludePaths option.

Fix: 10.1.1+
Fix from $1,600 2020-09-25
Unified Threat Management CRITICAL 9.8
CVE-2020-25223 KEVEPSS 97%

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

Fix: 9.511 / 9.607+
Fix from $2,300 2020-09-25
Ios Xe MEDIUM 6.7
CVE-2020-3417

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to execute persistent code at boot time and break the chain of …

Mitigation only
Fix from $1,600 2020-09-24
Ios Xe HIGH 7.8
CVE-2020-3403

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to inject a command to the underlying operating syst…

Mitigation only
Fix from $1,950 2020-09-24
Wrtm 127acn Firmware HIGH 8.8
CVE-2020-24365EPSS 11%

An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authent…

No fix yet
Fix from $1,950 2020-09-24
Accesslog Firmware CRITICAL 9.8
CVE-2020-16147

The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated code injection over the netw…

Fix: after 6.0
Fix from $2,300 2020-09-24
Accesslog Firmware HIGH 7.2
CVE-2020-16148

The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via authenticated cod…

Fix: after 6.0
Fix from $1,950 2020-09-24
Spamtitan HIGH 8.8
CVE-2020-11699EPSS 10%

An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execut…

No fix yet
Fix from $1,950 2020-09-17
Selection Tasks HIGH 8.8
CVE-2020-2276

Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing attackers with Job/Configure per…

Fix: after 1.0
Fix from $1,950 2020-09-16
Perfecto HIGH 8.8
CVE-2020-2261

Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitr…

Fix: after 1.17
Fix from $1,950 2020-09-16
Se5901 Firmware HIGH 7.2
CVE-2020-24552

Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation, the device's web management …

Fix: after 1.40
Fix from $1,950 2020-09-10
Ubuntu Linux CRITICAL 9.8
CVE-2020-24916EPSS 17%

CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.

Fix: after 2.0.7
Fix from $2,300 2020-09-09
Pan Os HIGH 7.2
CVE-2020-2037

An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands wi…

Fix: 8.1.16 / 9.0.10+
Fix from $1,950 2020-09-09
Pan Os HIGH 7.2
CVE-2020-2038EPSS 86%

An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands wi…

Fix: 9.0.10 / 9.1.4+
Fix from $1,950 2020-09-09
Fedora HIGH 7.0
CVE-2020-14342

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. A…

Fix: after 6.10
Fix from $1,950 2020-09-09
Bestzip CRITICAL 9.8
CVE-2020-7730

The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param.

Fix: 2.1.7+
Fix from $2,300 2020-09-04
Jabber HIGH 8.8
CVE-2020-3430

A vulnerability in the application protocol handling features of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to execute …

Fix: 12.1.3 / 12.5.2+
Fix from $1,950 2020-09-04
Rebar3 CRITICAL 9.8
CVE-2020-13802EPSS 7%

Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.

Fix: after 3.13.2
Fix from $2,300 2020-09-02
Vmg5313 B30b Firmware HIGH 8.8
CVE-2020-24354

Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell injection.

Fix: after 5.13
Fix from $1,950 2020-08-31
Json HIGH 7.2
CVE-2020-7712

This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

Fix: 10.0.0 / 21.1.1.1.0+
Fix from $1,950 2020-08-30
Nx Os HIGH 7.2
CVE-2020-3454

A vulnerability in the Call Home feature of Cisco NX-OS Software could allow an authenticated, remote attacker to inject arbitrary commands that coul…

Mitigation only
Fix from $1,950 2020-08-27
Ansible HIGH 7.3
CVE-2019-14904

A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name…

Fix: 2.7.15 / 2.8.7+
Fix from $1,950 2020-08-26
Qconvergeconsole HIGH 8.8
CVE-2020-15642EPSS 7%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marvell QConvergeConsole 5.5.0.64.…

Fix: 5.5.00.73+
Fix from $1,950 2020-08-25
Cellos HIGH 7.2
CVE-2020-17384

Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With the cookie of the system administrator, attackers can inject …

Mitigation only
Fix from $1,950 2020-08-25
Raspap HIGH 8.8
CVE-2020-24572EPSS 7%

An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unres…

Patch available
Fix from $1,950 2020-08-24
S5120fd Firmware HIGH 8.8
CVE-2020-24057EPSS 5%

The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows the user to manage network filt…

No fix yet
Fix from $1,950 2020-08-21
Exvf5c 2 Firmware CRITICAL 9.8
CVE-2020-24054

The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that can spawn a given process re…

No fix yet
Fix from $2,300 2020-08-21