Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
MEDIUM 6.8 CVE-2020-5636 Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specially crafted request to a spec… Aterm Sa3500g Firmware 3.5.9+ Fix from $1,6002020-12-14 CRITICAL 9.8 CVE-2020-28439 This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package '… Corenlp Js Prefab Mitigation only Fix from $2,3002020-12-11 CRITICAL 9.8 CVE-2020-28440 All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function. Corenlp Js Interface Mitigation only Fix from $2,3002020-12-11 CRITICAL 9.8 CVE-2020-15357 Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to execute arbitrary commands via a … Ap5100w Firmware after 1.01.097 Fix from $2,3002020-12-11 MEDIUM 6.8 CVE-2020-12148 A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbi… Edgeconnect Enterprise 8.1.9.15 / 8.3.0.8+ Fix from $1,6002020-12-11 MEDIUM 6.8 CVE-2020-12149 The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled… Edgeconnect Enterprise 8.1.9.15 / 8.3.0.8+ Fix from $1,6002020-12-11 MEDIUM 5.6 CVE-2020-7789 This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not … Node Notifier 8.0.1+ Fix from $1,6002020-12-11 CRITICAL 9.8 CVE-2020-29311EPSS 6% Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being trigg… Ubilling No fix yet Fix from $2,3002020-12-10 CRITICAL 9.8 CVE-2020-19142 iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php. Icms No fix yet Fix from $2,3002020-12-10 CRITICAL 9.8 CVE-2020-19527 iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php. Icms No fix yet Fix from $2,3002020-12-10 CRITICAL 9.8 CVE-2019-7198 This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulner… Quts Hero 4.4.3.1354 / 4.5.1.1456+ Fix from $2,3002020-12-10 HIGH 8.8 CVE-2020-25499 TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality… A3002r Firmware 1.0.0-b20201028.1743 / 1.0.0-b20201103.1713+ Fix from $1,9502020-12-09 CRITICAL 9.1 CVE-2020-26838 SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacke… Business Warehouse Mitigation only Fix from $2,3002020-12-09 CRITICAL 9.8 CVE-2020-29390EPSS 40% Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated … Zeroshell No fix yet Fix from $2,3002020-11-30 CRITICAL 9.8 CVE-2020-29381 An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4… V1600d Firmware Mitigation only Fix from $2,3002020-11-29 CRITICAL 9.8 CVE-2020-26245 npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rew… Systeminformation 4.30.5+ Fix from $2,3002020-11-27 HIGH 7.3 CVE-2020-7778 This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to exe… Systeminformation 4.30.2+ Fix from $1,9502020-11-26 CRITICAL 9.8 CVE-2020-29056 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B,… 72408a Firmware No fix yet Fix from $2,3002020-11-24 CRITICAL 9.1 CVE-2020-4006 KEVEPSS 17% VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. Identity Manager after 8.2 Fix from $2,3002020-11-23 HIGH 7.2 CVE-2020-28581EPSS 45% A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, rem… Interscan Web Security Virtual Appliance No fix yet Fix from $1,9502020-11-18 CRITICAL 9.8 CVE-2020-3586 A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitr… Dna Spaces\ after 2.2 Fix from $2,3002020-11-18 HIGH 7.2 CVE-2020-28580EPSS 45% A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote… Interscan Web Security Virtual Appliance No fix yet Fix from $1,9502020-11-18 HIGH 7.8 CVE-2020-3367 A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Security Appliance) could allow a… Asyncos 11.7.2-011 / 11.8.2-009+ Fix from $1,9502020-11-18 HIGH 8.8 CVE-2020-24297 httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS commands by sending crafted POST… Tl Wpa4220 Firmware No fix yet Fix from $1,9502020-11-18 HIGH 8.8 CVE-2020-26217EPSS 85% XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands on… Debian Linux 1.4.14 / 5.15.14+ Fix from $1,9502020-11-16 HIGH 7.2 CVE-2020-2492 If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Q… Qts 4.4.3.1421+ Fix from $1,9502020-11-16 HIGH 8.8 CVE-2020-8270 An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 … Virtual Apps And Desktops after 2006 Fix from $1,9502020-11-16 HIGH 8.8 CVE-2020-8273 Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8. Sd Wan 10.2.8 / 11.1.2b+ Fix from $1,9502020-11-16 HIGH 7.2 CVE-2020-2490 If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Q… Qts 4.4.3.1421+ Fix from $1,9502020-11-16 CRITICAL 9.8 CVE-2020-24719EPSS 23% Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (… Couchbase Server 6.6.0+ Fix from $2,3002020-11-12