Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.9
CVE-2020-17363
USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHu…
Usvn
1.0.9+
HIGH 8.8
CVE-2020-19664EPSS 5%
DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.
Vigor2960 Firmware
after 1.5.1
HIGH 8.8
CVE-2020-35789
NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.
Nms300 Firmware
1.6.0.27+
CRITICAL 9.9
CVE-2020-10208
Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B …
Ak45x Firmware
No fix yet
HIGH 8.1
CVE-2020-10209
Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx se…
Ak45x Firmware
No fix yet
HIGH 8.8
CVE-2020-25847
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulner…
Qts
4.5.1.1495+
CRITICAL 9.8
CVE-2020-35729EPSS 88%
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
Klog Server
No fix yet
CRITICAL 9.8
CVE-2020-35713EPSS 33%
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters …
Re6500 Firmware
1.0.012.001+
HIGH 8.8
CVE-2020-35714
Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in c…
Re6500 Firmware
1.0.011.001+
HIGH 8.8
CVE-2020-35715
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters in a filenam…
Re6500 Firmware
1.0.012.001+
CRITICAL 9.8
CVE-2020-28188EPSS 97%
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/m…
Tos
after 4.2.06
CRITICAL 9.8
CVE-2020-35665EPSS 78%
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in includ…
Terramaster Operating System
after 4.2.06
CRITICAL 9.8
CVE-2020-29552
An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0%3bpowershell+-c+" substring,…
Urve
No fix yet
HIGH 8.0
CVE-2020-24581EPSS 14%
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not r…
Dsl2888a Firmware
No fix yet
HIGH 8.5
CVE-2020-26284
Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc docu…
Hugo
0.79.1+
HIGH 8.8
CVE-2020-35606EPSS 28%
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with…
Webmin
after 1.962
CRITICAL 9.8
CVE-2020-25494EPSS 39%
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels paramet…
Openserver
No fix yet
CRITICAL 9.8
CVE-2020-12522
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC …
Pfc 100 Firmware
after 10
CRITICAL 9.8
CVE-2020-8466EPSS 64%
A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled,…
Interscan Web Security Virtual Appliance
No fix yet
CRITICAL 9.8
CVE-2020-25094
LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSo…
Platform Manager
No fix yet
HIGH 8.8
CVE-2020-26274
In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a s…
Systeminformation
4.31.1+
CRITICAL 9.8
CVE-2020-7781
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vu…
Connection Tester
0.2.1+
HIGH 8.8
CVE-2019-14479
AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can execute arbitrary code on the se…
Netcrunch
No fix yet
HIGH 8.8
CVE-2020-25618
An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is…
N Central
Mitigation only
CRITICAL 9.8
CVE-2020-35476EPSS 85%
A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to …
Opentsdb
after 2.4.0
MEDIUM 6.8
CVE-2020-26259EPSS 82%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion o…
Struts
1.4.15 / 6.0.0+
HIGH 8.8
CVE-2020-25757
A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command API…
Dsr 150 Firmware
after 3.17
HIGH 8.8
CVE-2020-25759
An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticat…
Dsr 150 Firmware
after 3.17
CRITICAL 9.8
CVE-2020-20184
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.
Gateone
No fix yet
HIGH 8.8
CVE-2020-5635
Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specific URL,…
Aterm Sa3500g Firmware
3.5.9+