Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Git Add Remote CRITICAL 9.8
CVE-2020-7630

git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.

Fix: after 1.0.0
Fix from $2,300 2020-04-02
Effect CRITICAL 9.8
CVE-2020-7624

effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.

Fix: after 1.0.4
Fix from $2,300 2020-04-02
Op Browser CRITICAL 9.8
CVE-2020-7625

op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.

Fix: after 1.0.6
Fix from $2,300 2020-04-02
Karma Mojo CRITICAL 9.8
CVE-2020-7626

karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.

Fix: after 1.0.1
Fix from $2,300 2020-04-02
Node Key Sender CRITICAL 9.8
CVE-2020-7627

node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'exe…

Fix: after 1.0.11
Fix from $2,300 2020-04-02
Get Git Data CRITICAL 9.8
CVE-2020-7619

get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-g…

Fix: after 1.3.1
Fix from $2,300 2020-04-02
Pomelo Monitor CRITICAL 9.8
CVE-2020-7620

pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.

Fix: after 0.3.7
Fix from $2,300 2020-04-02
Strongloop Nginx Controller CRITICAL 9.8
CVE-2020-7621

strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' funct…

Fix: after 1.0.2
Fix from $2,300 2020-04-02
Jscover CRITICAL 9.8
CVE-2020-7623

jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.

Fix: after 1.0.0
Fix from $2,300 2020-04-02
Zen Load Balancer HIGH 7.2
CVE-2020-11490

Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the …

No fix yet
Fix from $1,950 2020-04-02
Spectrum Protect Plus HIGH 8.8
CVE-2020-4241EPSS 66%

IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on t…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
Spectrum Protect Plus HIGH 8.8
CVE-2020-4242

IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on t…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
Spectrum Protect Plus HIGH 8.8
CVE-2020-4206

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
X Plane CRITICAL 9.8
CVE-2019-19606

X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS crede…

Fix: 11.41+
Fix from $2,300 2020-03-30
Ac1750 Firmware CRITICAL 9.8
CVE-2020-10886EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 route…

Mitigation only
Fix from $2,300 2020-03-25
Ac1750 Firmware HIGH 8.8
CVE-2020-10882EPSS 41%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC…

No fix yet
Fix from $1,950 2020-03-25
Nick Chan Bot CRITICAL 9.8
CVE-2020-5282

In Nick Chan Bot before version 1.0.0-beta there is a vulnerability in the `npm` command which is part of this software package. This allows arbitrar…

Patch available
Fix from $2,300 2020-03-25
Openitcockpit CRITICAL 9.8
CVE-2020-10789

openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandl…

Fix: 3.7.3+
Fix from $2,300 2020-03-25
Wl Enq CRITICAL 9.8
CVE-2020-5560

WL-Enq 1.11 and 1.12 allows remote attackers to execute arbitrary OS commands with the administrative privilege via unspecified vectors.

Mitigation only
Fix from $2,300 2020-03-25
Keijiban Tsumiki CRITICAL 9.8
CVE-2020-5561

Keijiban Tsumiki v1.15 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Mitigation only
Fix from $2,300 2020-03-25
Shihonkanri Plus Goout CRITICAL 9.8
CVE-2020-5556

Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

No fix yet
Fix from $2,300 2020-03-25
Rconfig CRITICAL 9.8
CVE-2020-10879EPSS 84%

rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed direc…

Fix: 3.9.5+
Fix from $2,300 2020-03-23
Manageengine Assetexplorer HIGH 7.2
CVE-2019-19034EPSS 6%

Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a…

No fix yet
Fix from $1,950 2020-03-23
Prosafe Wc9500 Firmware HIGH 7.2
CVE-2016-11022

NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell …

No fix yet
Fix from $1,950 2020-03-23
Artica Proxy HIGH 7.2
CVE-2020-10818

Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the hostname" field.

No fix yet
Fix from $1,950 2020-03-22
Vesta Control Panel HIGH 8.8
CVE-2020-10808EPSS 78%

Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to…

Fix: after 0.9.8-26
Fix from $1,950 2020-03-22
Dap 1650 Firmware CRITICAL 9.8
CVE-2019-12767

An issue was discovered on D-Link DAP-1650 devices before 1.04B02_J65H Hot Fix. Attackers can execute arbitrary commands.

Fix: 1.04b02_j65h+
Fix from $2,300 2020-03-21
Optical Line Terminal 1150 Firmware CRITICAL 9.8
CVE-2019-19148EPSS 8%

Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue …

No fix yet
Fix from $2,300 2020-03-20
Centreon HIGH 8.8
CVE-2019-19487EPSS 5%

Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.

Fix: after 19.04.4
Fix from $1,950 2020-03-20
Asuswrt CRITICAL 9.8
CVE-2018-20334

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell me…

No fix yet
Fix from $2,300 2020-03-20