Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Rangeeos CRITICAL 9.8
CVE-2020-16279

The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed to the c…

Mitigation only
Fix from $2,300 2020-08-20
Rangeeos HIGH 8.8
CVE-2020-16282

In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged root user. This may allow a …

Mitigation only
Fix from $1,950 2020-08-20
Slc 130 Firmware CRITICAL 9.8
CVE-2020-17456EPSS 74%

SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.

No fix yet
Fix from $2,300 2020-08-20
Ritecms HIGH 8.8
CVE-2020-23934EPSS 16%

An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager…

No fix yet
Fix from $1,950 2020-08-18
Lpar2rrd CRITICAL 9.8
CVE-2020-24032EPSS 5%

tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.

Mitigation only
Fix from $2,300 2020-08-18
Shopxo HIGH 8.8
CVE-2020-24220

ShopXO v1.8.1 has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands and gain control of the serve…

Mitigation only
Fix from $1,950 2020-08-17
Noviware HIGH 8.8
CVE-2020-13122EPSS 7%

The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, is vulnerable to command injec…

No fix yet
Fix from $1,950 2020-08-17
Edgeswitch Firmware HIGH 8.8
CVE-2020-8233

A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell comma…

Fix: 1.9.0+
Fix from $1,950 2020-08-17
G Cam Ebc 2110 Firmware HIGH 7.2
CVE-2020-16205EPSS 61%

Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 …

No fix yet
Fix from $1,950 2020-08-14
Avalanche MEDIUM 6.7
CVE-2020-11733

An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restric…

Fix: after 5.08
Fix from $1,600 2020-08-13
Vpncrypt M10 Firmware CRITICAL 9.8
CVE-2020-12107

The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module's Operat…

Mitigation only
Fix from $2,300 2020-08-12
Web Proxy HIGH 8.8
CVE-2020-17505EPSS 82%

Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands a…

No fix yet
Fix from $1,950 2020-08-12
Sabnzbd HIGH 8.8
CVE-2020-13124

SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an authenticated user to execute …

Patch available
Fix from $1,950 2020-08-11
Debian Linux CRITICAL 9.8
CVE-2020-17368

Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.

Fix: after 0.9.62
Fix from $2,300 2020-08-11
Cloudforms Management Engine CRITICAL 9.1
CVE-2020-14324

A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerabil…

Fix: 5.11.7.0+
Fix from $2,300 2020-08-11
Xg Firewall Firmware HIGH 8.8
CVE-2020-17352

Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to r…

Patch available
Fix from $1,950 2020-08-07
Secure Messaging Gateway HIGH 8.8
CVE-2020-11852

DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020…

Fix: 2020-07-01+
Fix from $1,950 2020-08-07
Cms Se Firmware CRITICAL 9.9
CVE-2020-7357EPSS 32%

Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and …

Patch available
Fix from $2,300 2020-08-06
Zentao Pro HIGH 8.8
CVE-2020-7361EPSS 17%

The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating…

Fix: after 8.8.2
Fix from $1,950 2020-08-06
Atos\/sips HIGH 8.8
CVE-2020-13404EPSS 7%

The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.

Fix: after 3.0.5
Fix from $1,950 2020-08-05
Aerospike Server CRITICAL 9.8
CVE-2020-13151EPSS 87%

Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of …

Fix: 4.5.3.21 / 4.6.0.19+
Fix from $2,300 2020-08-05
Vns3 HIGH 8.8
CVE-2020-15467

The administrative interface of Cohesive Networks vns3:vpn appliances before version 4.11.1 is vulnerable to authenticated remote code execution lead…

Fix: 4.11.1+
Fix from $1,950 2020-08-04
Data Center Network Manager HIGH 8.8
CVE-2020-3377

A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject…

Mitigation only
Fix from $1,950 2020-07-31
Pi Hole HIGH 7.8
CVE-2020-12620

Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection (shell metacharacters after …

Fix: 5.0+
Fix from $1,950 2020-07-30
Pi Hole HIGH 7.8
CVE-2020-14162

An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a passw…

Fix: 5.1+
Fix from $1,950 2020-07-30
Ht801 Firmware HIGH 7.8
CVE-2020-5760EPSS 5%

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers…

Fix: after 1.0.17.5
Fix from $1,950 2020-07-29
Gerapy CRITICAL 9.8
CVE-2020-7698

This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.

Fix: 0.9.3+
Fix from $2,300 2020-07-29
Webpanel CRITICAL 9.8
CVE-2020-15608EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication …

Mitigation only
Fix from $2,300 2020-07-28
Centos Web Panel CRITICAL 9.8
CVE-2020-15609EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication …

Mitigation only
Fix from $2,300 2020-07-28
Webpanel CRITICAL 9.8
CVE-2020-15610EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication …

Mitigation only
Fix from $2,300 2020-07-28