Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Codecov HIGH 8.8
CVE-2020-7597

codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is ex…

Fix: 3.6.5+
Fix from $1,950 2020-02-17
Ntp 2 Firmware CRITICAL 9.8
CVE-2020-9026

ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NTP-2 device is also affected.

No fix yet
Fix from $2,300 2020-02-17
Ntp 2 Firmware CRITICAL 9.8
CVE-2020-9027

ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The NTP-2 device is also affected.

No fix yet
Fix from $2,300 2020-02-17
Vantage Velocity Firmware CRITICAL 9.8
CVE-2020-9020

Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacte…

No fix yet
Fix from $2,300 2020-02-17
Awam Bluetooth Field Device Firmware CRITICAL 9.8
CVE-2020-9021

Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections…

No fix yet
Fix from $2,300 2020-02-17
Mgate 5105 Mb Eip Firmware HIGH 8.8
CVE-2020-8858EPSS 9%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.1. Authen…

Fix: after 4.1
Fix from $1,950 2020-02-14
Sr9850 Firmware CRITICAL 9.8
CVE-2020-8963

TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003,…

No fix yet
Fix from $2,300 2020-02-13
S2a Wl Firmware HIGH 8.8
CVE-2020-8949

Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572, and ISP3000 4.3.0.17190 devi…

No fix yet
Fix from $1,950 2020-02-12
Wf2471 Firmware HIGH 8.8
CVE-2020-8946

Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-igd/sys_log…

No fix yet
Fix from $1,950 2020-02-12
Pandora Fms HIGH 7.2
CVE-2020-8947EPSS 22%

functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?op…

No fix yet
Fix from $1,950 2020-02-12
Kinetica HIGH 8.8
CVE-2020-8429

The Admin web application in Kinetica 7.0.9.2.20191118151947 does not properly sanitise the input for the function getLogs. This lack of sanitisation…

No fix yet
Fix from $1,950 2020-02-11
Sterling External Authentication Server HIGH 7.8
CVE-2013-0517

A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command…

Mitigation only
Fix from $1,950 2020-02-11
Memu CRITICAL 9.8
CVE-2019-14514EPSS 7%

An issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu emulator contains a /system/b…

Fix: 7.0.2+
Fix from $2,300 2020-02-11
Pydio CRITICAL 9.8
CVE-2013-4267

Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Powe…

Fix: 5.0.1+
Fix from $2,300 2020-02-11
Wf2419 Firmware HIGH 7.5
CVE-2019-19356 KEVEPSS 28%

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been fo…

Mitigation only
Fix from $1,950 2020-02-07
Edgeswitch HIGH 7.8
CVE-2020-8126

A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execut…

Fix: 1.7.1+
Fix from $1,950 2020-02-07
Eyesofnetwork HIGH 8.8
CVE-2020-8654EPSS 86%

An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitr…

No fix yet
Fix from $1,950 2020-02-07
Zi 620 V400 Firmware CRITICAL 9.8
CVE-2020-6760

Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu, …

No fix yet
Fix from $2,300 2020-02-06
Curling CRITICAL 9.8
CVE-2019-10789

All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sani…

No fix yet
Fix from $2,300 2020-02-06
Network Manager CRITICAL 9.8
CVE-2019-10786

network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.

Fix: after 1.0.2
Fix from $2,300 2020-02-04
Im Resize CRITICAL 9.8
CVE-2019-10787

im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be …

Fix: after 2.3.2
Fix from $2,300 2020-02-04
Im Metadata CRITICAL 9.8
CVE-2019-10788

im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands …

Fix: after 3.0.1
Fix from $2,300 2020-02-04
Fortimanager HIGH 8.8
CVE-2015-3611EPSS 6%

A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could l…

Fix: after 5.2.1
Fix from $1,950 2020-02-04
Vigor2960 Firmware CRITICAL 9.8
CVE-2020-8515 KEVEPSS 100%

DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as roo…

Mitigation only
Fix from $2,300 2020-02-01
Oncommand System Manager HIGH 7.2
CVE-2013-3322

NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot interface.

Fix: after 2.1
Fix from $1,950 2020-01-31
Spamassassin HIGH 8.1
CVE-2020-1930EPSS 7%

A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configur…

Fix: 3.4.3+
Fix from $1,950 2020-01-30
Spamassassin HIGH 8.1
CVE-2020-1931EPSS 6%

A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to…

Fix: 3.4.3+
Fix from $1,950 2020-01-30
Pandora Fms MEDIUM 6.8
CVE-2019-20050

Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated user should create a new folder…

No fix yet
Fix from $1,600 2020-01-30
Ruckus Zoneflex R500 Firmware HIGH 7.2
CVE-2020-8438

Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler fo…

No fix yet
Fix from $1,950 2020-01-29
Isof CRITICAL 9.8
CVE-2019-10783

All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function…

Fix: after 0.0.4
Fix from $2,300 2020-01-29