Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Open Computer Software Inventory Next Generation HIGH 8.8
CVE-2020-14947EPSS 19%

OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main…

Patch available
Fix from $1,950 2020-06-30
Vigor3900 Firmware CRITICAL 9.8
CVE-2020-15415 KEVEPSS 85%

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell …

Fix: 1.5.1+
Fix from $2,300 2020-06-30
Nedi HIGH 8.8
CVE-2020-14412

NeDi 1.9C is vulnerable to Remote Command Execution. System-Snapshot.php improperly escapes shell metacharacters from a POST request. An attacker can…

Mitigation only
Fix from $1,950 2020-06-29
Nedi HIGH 8.8
CVE-2020-14414

NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a POST request. An attacker can exploit t…

Mitigation only
Fix from $1,950 2020-06-29
Wifiscanner CRITICAL 9.8
CVE-2020-15362

wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite the default executable/binary p…

No fix yet
Fix from $2,300 2020-06-29
Mk Auth CRITICAL 9.8
CVE-2020-14072

An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin scripts.

Mitigation only
Fix from $2,300 2020-06-29
Pa6 Firmware HIGH 8.8
CVE-2019-16213

Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a spe…

No fix yet
Fix from $1,950 2020-06-25
Artica Proxy CRITICAL 9.8
CVE-2020-13159EPSS 9%

Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Al…

Fix: 4.30.000000+
Fix from $2,300 2020-06-22
Cloudforms Management Engine HIGH 7.2
CVE-2019-14894

A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution throu…

Mitigation only
Fix from $1,950 2020-06-22
Limdu HIGH 7.2
CVE-2020-4066

In Limdu before 0.95, the trainBatch function has a command injection vulnerability. Clients of the Limdu library are unlikely to be aware of this, s…

Fix: 0.9.5+
Fix from $1,950 2020-06-22
Aapanel HIGH 8.8
CVE-2020-14950

aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a modified /system?action=ServiceAd…

Fix: after 6.6.6
Fix from $1,950 2020-06-21
Roomos HIGH 7.2
CVE-2020-3336

A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authen…

Fix: 9.9.4+
Fix from $1,950 2020-06-18
Rv016 Firmware HIGH 7.2
CVE-2020-3274

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,…

Fix: after 4.2.3.10
Fix from $1,950 2020-06-18
Rv016 Firmware HIGH 7.2
CVE-2020-3275

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,…

Fix: after 4.2.3.10
Fix from $1,950 2020-06-18
Rv016 Firmware HIGH 7.2
CVE-2020-3276

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,…

Fix: after 4.2.3.10
Fix from $1,950 2020-06-18
Rv016 Firmware HIGH 7.2
CVE-2020-3277

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,…

Fix: after 4.2.3.10
Fix from $1,950 2020-06-18
Rv016 Firmware HIGH 7.2
CVE-2020-3278

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,…

Fix: after 4.2.3.10
Fix from $1,950 2020-06-18
Rv016 Firmware HIGH 7.2
CVE-2020-3279

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,…

Fix: after 4.2.3.10
Fix from $1,950 2020-06-18
Spectrum Protect Plus CRITICAL 9.8
CVE-2020-4469EPSS 13%

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted H…

Fix: after 10.1.5
Fix from $2,300 2020-06-15
Tew 827dru Firmware HIGH 8.8
CVE-2020-14075

TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action pppoe_connect, ru_pppoe_connect, or dhcp_…

Fix: after 2.06b04
Fix from $1,950 2020-06-15
Tew 827dru Firmware HIGH 8.8
CVE-2020-14081

TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action send_log_email with the key auth_acname (…

Fix: after 2.06b04
Fix from $1,950 2020-06-15
Pandora Fms HIGH 8.8
CVE-2020-13851EPSS 91%

Artica Pandora FMS 7.44 allows remote command execution via the events feature.

No fix yet
Fix from $1,950 2020-06-11
Pan Os HIGH 7.2
CVE-2020-2028

An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root priv…

Fix: 8.1.13 / 9.0.7+
Fix from $1,950 2020-06-10
Pan Os HIGH 7.2
CVE-2020-2029

An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to execute arbitrary OS commands wit…

Fix: 7.1.26 / 8.1.13+
Fix from $1,950 2020-06-10
Dd Wrt HIGH 8.8
CVE-2020-13976

An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters i…

Fix: after 16214
Fix from $1,950 2020-06-09
Monstra Cms HIGH 7.2
CVE-2020-13978

Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute arbitrary…

No fix yet
Fix from $1,950 2020-06-09
Ios Xe HIGH 8.8
CVE-2020-3224

A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privil…

Patch available
Fix from $1,950 2020-06-03
iOS MEDIUM 6.7
CVE-2020-3210

A vulnerability in the CLI parsers of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 100…

Patch available
Fix from $1,600 2020-06-03
Ios Xe HIGH 7.2
CVE-2020-3211

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileg…

Patch available
Fix from $1,950 2020-06-03
Ios Xe HIGH 7.2
CVE-2020-3212

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileg…

Patch available
Fix from $1,950 2020-06-03