Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
iOS HIGH 8.8
CVE-2020-3205

A vulnerability in the implementation of the inter-VM channel of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Ind…

Patch available
Fix from $1,950 2020-06-03
Ios Xe MEDIUM 6.7
CVE-2020-3207

A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root s…

Mitigation only
Fix from $1,600 2020-06-03
Dir 865l Firmware HIGH 8.8
CVE-2020-13782EPSS 27%

D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.

No fix yet
Fix from $1,950 2020-06-03
Security Guardium HIGH 8.8
CVE-2020-4180

IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted re…

Patch available
Fix from $1,950 2020-06-03
Play Framework HIGH 8.8
CVE-2020-2200

Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the `play` command on the Jenkins master for a form validation endpoin…

Fix: after 1.0.2
Fix from $1,950 2020-06-03
Lexiglot CRITICAL 9.8
CVE-2014-8945

admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.

Fix: after 2014-11-20
Fix from $2,300 2020-06-01
Farlinx X25 Gateway Firmware CRITICAL 9.8
CVE-2014-7173

FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx25MonProxy.php, syseditdate.ph…

Fix: after 2014-09-25
Fix from $2,300 2020-06-01
Quickbox HIGH 8.8
CVE-2020-13448EPSS 17%

QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via comm…

Fix: after 2.5.5
Fix from $1,950 2020-06-01
Quickbox HIGH 8.8
CVE-2020-13694

In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password, which m…

Fix: after 2.5.5
Fix from $1,950 2020-06-01
Pi Hole HIGH 7.2
CVE-2020-8816 KEVEPSS 78%

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

Fix: after 4.3.2
Fix from $1,950 2020-05-29
Debian Linux MEDIUM 5.3
CVE-2019-20807

In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby,…

Fix: 8.1.0881+
Fix from $1,600 2020-05-28
Cc9381 Hv Firmware HIGH 8.8
CVE-2020-11950

VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a scri…

Fix: after 0222g
Fix from $1,950 2020-05-28
Interscan Web Security Virtual Appliance HIGH 8.8
CVE-2020-8605EPSS 88%

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installa…

Patch available
Fix from $1,950 2020-05-27
Firefox HIGH 7.8
CVE-2020-12393

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If …

Fix: 68.8.0 / 76.0+
Fix from $1,950 2020-05-26
Airos CRITICAL 9.8
CVE-2020-8171

We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.…

Fix: after 6.2.0
Fix from $2,300 2020-05-26
Jw.util CRITICAL 9.8
CVE-2020-13388

An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configura…

Fix: 2.3+
Fix from $2,300 2020-05-22
Kylin HIGH 8.8
CVE-2020-1956 KEVEPSS 97%

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is …

Fix: after 2.6.5
Fix from $1,950 2020-05-22
Centreon HIGH 8.8
CVE-2020-13252EPSS 5%

Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a m…

Fix: 19.04.15+
Fix from $1,950 2020-05-21
Hylafax HIGH 8.8
CVE-2020-11766

sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.

Fix: 0.2.5 / 3.3.6+
Fix from $1,950 2020-05-19
Netsweeper CRITICAL 9.8
CVE-2020-13167EPSS 95%

Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a …

Fix: after 6.4.3
Fix from $2,300 2020-05-19
Pan Os HIGH 8.8
CVE-2020-2014

An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root…

Fix: after 9.0.6
Fix from $1,950 2020-05-13
Pan Os HIGH 7.2
CVE-2020-2007

An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary comm…

Fix: after 9.0.6
Fix from $1,950 2020-05-13
Pan Os HIGH 7.2
CVE-2020-2008

An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute co…

Fix: after 8.1.13
Fix from $1,950 2020-05-13
Pan Os HIGH 7.2
CVE-2020-2010

An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root…

Fix: after 9.0.6
Fix from $1,950 2020-05-13
Tks Ip Gateway Firmware HIGH 7.2
CVE-2020-10795

Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to authenticated remote code execution via the backup functionality of the web frontend. This can be combin…

No fix yet
Fix from $1,950 2020-05-07
Data Risk Manager CRITICAL 9.1
CVE-2020-4428 KEVEPSS 62%

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-F…

Fix: after 2.0.4
Fix from $2,300 2020-05-07
Iml500 Firmware CRITICAL 9.8
CVE-2020-7805

An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection a…

Fix: after 29.8.2018
Fix from $2,300 2020-05-07
Curlrequest CRITICAL 9.8
CVE-2020-7646

curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.

Fix: after 1.0.1
Fix from $2,300 2020-05-07
Intelligent Power Manager HIGH 7.3
CVE-2020-6651

Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allow…

Fix: after 1.67
Fix from $1,950 2020-05-07
Archer HIGH 7.2
CVE-2020-5332

RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privile…

Fix: 6.7.0.3+
Fix from $1,950 2020-05-04