Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2020-2000
An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrup…
Pan Os
8.1.16 / 9.0.10+
HIGH 7.8
CVE-2020-17010
Win32k Elevation of Privilege Vulnerability
Windows 10
Patch available
CRITICAL 9.8
CVE-2020-28347EPSS 77%
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this…
Ac1750 Firmware
201029+
HIGH 8.8
CVE-2020-3371
A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code …
Integrated Management Controller
3.0+
CRITICAL 9.8
CVE-2020-16846 KEVEPSS 100%
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shel…
Debian Linux
2015.8.10 / 2015.8.13+
HIGH 8.8
CVE-2020-24849
A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST …
Fruitywifi
after 2.4
CRITICAL 9.8
CVE-2018-19950
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. …
Music Station
5.1.13 / 5.2.9+
HIGH 8.8
CVE-2020-25849
MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after…
Mailaudit
Mitigation only
HIGH 8.8
CVE-2020-27887
An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module…
Eyesofnetwork
after 5.3-8
CRITICAL 9.8
CVE-2020-27744EPSS 6%
An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privil…
My Cloud Firmware
5.04.114+
CRITICAL 9.8
CVE-2018-19949 KEVEPSS 24%
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the fo…
Qts
4.2.6 / 4.3.3.1161+
CRITICAL 9.8
CVE-2020-16257
Winston 1.5.4 devices are vulnerable to command injection via the API.
Winston Firmware
No fix yet
CRITICAL 9.8
CVE-2020-27976EPSS 7%
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the applicat…
Oscommerce
1.0.5.4+
CRITICAL 9.8
CVE-2020-27158EPSS 7%
Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5…
My Cloud Firmware
5.04.114+
CRITICAL 9.8
CVE-2020-27159EPSS 6%
Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western …
My Cloud Firmware
5.04.114+
CRITICAL 9.8
CVE-2020-25765EPSS 6%
Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prio…
My Cloud Firmware
5.04.114+
HIGH 8.8
CVE-2020-26878EPSS 12%
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoi…
Ruckus Vriot
after 1.5.1.0.21
CRITICAL 9.6
CVE-2020-15272
In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can c…
Git Tag Annotation Action
1.0.1+
HIGH 8.8
CVE-2020-15271
In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Use…
Lookatme
2.3.0+
HIGH 8.8
CVE-2020-7752EPSS 6%
This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's param…
Systeminformation
4.27.11+
MEDIUM 6.7
CVE-2020-3457
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro…
Firepower Extensible Operating System
2.4.1.266 / 2.6.1.204+
HIGH 7.8
CVE-2020-3459
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro…
Firepower Extensible Operating System
2.4.1.266 / 2.6.1.204+
HIGH 7.2
CVE-2020-5791EPSS 79%
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating s…
Nagios Xi
after 5.7.3
HIGH 8.8
CVE-2020-13778
rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to lib/ajaxHandlers/ajaxAddTemplat…
Rconfig
after 3.9.4
HIGH 7.2
CVE-2020-14144EPSS 95%
The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentati…
Gitea
after 1.12.5
MEDIUM 6.7
CVE-2020-25859
The QCMAP_CLI utility in the Qualcomm QCMAP software suite prior to versions released in October 2020 uses a system() call without validating the inp…
Qcmap
No fix yet
CRITICAL 10.0
CVE-2020-6364EPSS 6%
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a…
Introscope Enterprise Manager
Mitigation only
HIGH 8.8
CVE-2020-17406EPSS 5%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE prior to v1.2.0-r1112. Authent…
Bullet Lte Firmware
1.2.0-r1112+
MEDIUM 6.7
CVE-2020-3601
A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate…
Staros
21.19.n4+
MEDIUM 6.7
CVE-2020-3602
A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate…
Staros
21.19.n4+