Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Dsl 7740c Firmware MEDIUM 6.7
CVE-2020-12774

D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary command.

Mitigation only
Fix from $1,600 2020-07-22
Fedora CRITICAL 9.6
CVE-2020-15121

In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open …

Fix: 4.5.0+
Fix from $2,300 2020-07-20
Codecov CRITICAL 9.3
CVE-2020-15123

In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlike…

Fix: 3.7.1+
Fix from $2,300 2020-07-20
Nagios Plugins Hpilo CRITICAL 9.8
CVE-2020-7206

HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.

Fix: after 1.50
Fix from $2,300 2020-07-17
Gwn7000 Firmware HIGH 8.8
CVE-2020-5756

Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An atta…

Fix: after 1.0.9.4
Fix from $1,950 2020-07-17
Ucm6202 Firmware CRITICAL 9.8
CVE-2020-5757EPSS 7%

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can …

Fix: after 1.0.20.23
Fix from $2,300 2020-07-17
Ucm6202 Firmware HIGH 8.8
CVE-2020-5758

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can …

Fix: after 1.0.20.23
Fix from $1,950 2020-07-17
Ucm6202 Firmware CRITICAL 9.8
CVE-2020-5759

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can e…

Fix: after 1.0.20.23
Fix from $2,300 2020-07-17
Miplatform CRITICAL 9.8
CVE-2020-7825

A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker …

Fix: after 2019.05.16
Fix from $2,300 2020-07-17
Airflow HIGH 8.8
CVE-2020-11978 KEVEPSS 99%

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example D…

Fix: 1.10.11+
Fix from $1,950 2020-07-17
Airflow CRITICAL 9.8
CVE-2020-11981EPSS 37%

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ…

Fix: after 1.10.10
Fix from $2,300 2020-07-17
Rv110w Wireless N Vpn Firewall Firmware HIGH 8.8
CVE-2020-3332

A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authent…

Fix: 1.0.3.55 / 1.2.2.8+
Fix from $1,950 2020-07-16
1ge Router Wifi Onu V2801rw Firmware HIGH 7.2
CVE-2020-8958EPSS 47%

Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to execute …

Fix: after 2.9.0-181024
Fix from $1,950 2020-07-15
Jison CRITICAL 9.8
CVE-2020-8178

Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.

Fix: after 0.4.18
Fix from $2,300 2020-07-15
Ipear MEDIUM 5.4
CVE-2020-11084

In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developer…

Mitigation only
Fix from $1,600 2020-07-14
Cmciii Pu 9333e0fb Firmware HIGH 8.8
CVE-2020-11953

An issue was discovered on Rittal PDU-3C002DEC through 5.15.40 and CMCIII-PU-9333E0FB through 3.15.70_4 devices. Attackers can execute code.

Fix: after 6.17.00
Fix from $1,950 2020-07-14
Qradar Security Information And Event Manager HIGH 7.2
CVE-2020-4512

IBM QRadar SIEM 7.3 and 7.4 could allow a remote privileged user to execute commands.

Fix: after 7.3.2
Fix from $1,950 2020-07-14
Kylin CRITICAL 9.8
CVE-2020-13925EPSS 20%

Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi…

Fix: 3.1.0+
Fix from $2,300 2020-07-14
Ac15 Firmware CRITICAL 9.8
CVE-2020-10987 KEVEPSS 80%

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the device…

Mitigation only
Fix from $2,300 2020-07-13
Devcert CRITICAL 9.8
CVE-2020-8186

A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `cer…

No fix yet
Fix from $2,300 2020-07-10
Dir 610 Firmware HIGH 8.8
CVE-2020-9377 KEVEPSS 21%

D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are n…

Patch available
Fix from $1,950 2020-07-09
Pan Os HIGH 8.1
CVE-2020-2034EPSS 7%

An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS com…

Fix: 8.1.15 / 9.0.9+
Fix from $1,950 2020-07-08
Pan Os HIGH 7.2
CVE-2020-2030

An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands wi…

Fix: 8.1.15+
Fix from $1,950 2020-07-08
Emc Data Protection Advisor HIGH 8.8
CVE-2020-5352

Dell EMC Data Protection Advisor 6.4, 6.5 and 18.1 contain an OS command injection vulnerability. A remote authenticated malicious user may exploit t…

Mitigation only
Fix from $1,950 2020-07-06
Unifi Protect Firmware HIGH 8.8
CVE-2020-8188

We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR r…

Fix: after 1.14.9
Fix from $1,950 2020-07-02
Wl Wn530hg4 Firmware CRITICAL 9.8
CVE-2020-15489

An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scrip…

Mitigation only
Fix from $2,300 2020-07-01
Linkplay CRITICAL 9.8
CVE-2019-15310EPSS 8%

An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could …

No fix yet
Fix from $2,300 2020-07-01
Linkplay CRITICAL 9.8
CVE-2019-15311EPSS 8%

An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. The Zolo Halo Bluetooth speaker…

No fix yet
Fix from $2,300 2020-07-01
Mversion HIGH 7.8
CVE-2020-7688

The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.

Fix: 2.0.1+
Fix from $1,950 2020-07-01
Locutus Php CRITICAL 9.8
CVE-2020-13619

php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.

Fix: after 2.0.11
Fix from $2,300 2020-07-01