Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2020-5636
Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specially crafted request to a spec…
Aterm Sa3500g Firmware
3.5.9+
CRITICAL 9.8
CVE-2020-28439
This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package '…
Corenlp Js Prefab
Mitigation only
CRITICAL 9.8
CVE-2020-28440
All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.
Corenlp Js Interface
Mitigation only
CRITICAL 9.8
CVE-2020-15357
Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to execute arbitrary commands via a …
Ap5100w Firmware
after 1.01.097
MEDIUM 6.8
CVE-2020-12148
A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbi…
Edgeconnect Enterprise
8.1.9.15 / 8.3.0.8+
MEDIUM 6.8
CVE-2020-12149
The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled…
Edgeconnect Enterprise
8.1.9.15 / 8.3.0.8+
MEDIUM 5.6
CVE-2020-7789
This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not …
Node Notifier
8.0.1+
CRITICAL 9.8
CVE-2020-29311EPSS 6%
Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being trigg…
Ubilling
No fix yet
CRITICAL 9.8
CVE-2020-19142
iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.
Icms
No fix yet
CRITICAL 9.8
CVE-2020-19527
iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.
Icms
No fix yet
CRITICAL 9.8
CVE-2019-7198
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulner…
Quts Hero
4.4.3.1354 / 4.5.1.1456+
HIGH 8.8
CVE-2020-25499
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality…
A3002r Firmware
1.0.0-b20201028.1743 / 1.0.0-b20201103.1713+
CRITICAL 9.1
CVE-2020-26838
SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacke…
Business Warehouse
Mitigation only
CRITICAL 9.8
CVE-2020-29390EPSS 40%
Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated …
Zeroshell
No fix yet
CRITICAL 9.8
CVE-2020-29381
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4…
V1600d Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-26245
npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rew…
Systeminformation
4.30.5+
HIGH 7.3
CVE-2020-7778
This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to exe…
Systeminformation
4.30.2+
CRITICAL 9.8
CVE-2020-29056
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B,…
72408a Firmware
No fix yet
CRITICAL 9.1
CVE-2020-4006 KEVEPSS 17%
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
Identity Manager
after 8.2
HIGH 7.2
CVE-2020-28581EPSS 45%
A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, rem…
Interscan Web Security Virtual Appliance
No fix yet
CRITICAL 9.8
CVE-2020-3586
A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitr…
Dna Spaces\
after 2.2
HIGH 7.2
CVE-2020-28580EPSS 45%
A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote…
Interscan Web Security Virtual Appliance
No fix yet
HIGH 7.8
CVE-2020-3367
A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Security Appliance) could allow a…
Asyncos
11.7.2-011 / 11.8.2-009+
HIGH 8.8
CVE-2020-24297
httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS commands by sending crafted POST…
Tl Wpa4220 Firmware
No fix yet
HIGH 8.8
CVE-2020-26217EPSS 85%
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands on…
Debian Linux
1.4.14 / 5.15.14+
HIGH 7.2
CVE-2020-2492
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Q…
Qts
4.4.3.1421+
HIGH 8.8
CVE-2020-8270
An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 …
Virtual Apps And Desktops
after 2006
HIGH 8.8
CVE-2020-8273
Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.
Sd Wan
10.2.8 / 11.1.2b+
HIGH 7.2
CVE-2020-2490
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Q…
Qts
4.4.3.1421+
CRITICAL 9.8
CVE-2020-24719EPSS 23%
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (…
Couchbase Server
6.6.0+