Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2020-2000 An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrup… Pan Os 8.1.16 / 9.0.10+ Fix from $1,9502020-11-12 HIGH 7.8 CVE-2020-17010 Win32k Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502020-11-11 CRITICAL 9.8 CVE-2020-28347EPSS 77% tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this… Ac1750 Firmware 201029+ Fix from $2,3002020-11-08 HIGH 8.8 CVE-2020-3371 A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code … Integrated Management Controller 3.0+ Fix from $1,9502020-11-06 CRITICAL 9.8 CVE-2020-16846 KEVEPSS 100% An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shel… Debian Linux 2015.8.10 / 2015.8.13+ Fix from $2,3002020-11-06 HIGH 8.8 CVE-2020-24849 A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST … Fruitywifi after 2.4 Fix from $1,9502020-11-05 CRITICAL 9.8 CVE-2018-19950 If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. … Music Station 5.1.13 / 5.2.9+ Fix from $2,3002020-11-02 HIGH 8.8 CVE-2020-25849 MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after… Mailaudit Mitigation only Fix from $1,9502020-11-01 HIGH 8.8 CVE-2020-27887 An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module… Eyesofnetwork after 5.3-8 Fix from $1,9502020-10-29 CRITICAL 9.8 CVE-2020-27744EPSS 6% An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privil… My Cloud Firmware 5.04.114+ Fix from $2,3002020-10-29 CRITICAL 9.8 CVE-2018-19949 KEVEPSS 24% If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the fo… Qts 4.2.6 / 4.3.3.1161+ Fix from $2,3002020-10-28 CRITICAL 9.8 CVE-2020-16257 Winston 1.5.4 devices are vulnerable to command injection via the API. Winston Firmware No fix yet Fix from $2,3002020-10-28 CRITICAL 9.8 CVE-2020-27976EPSS 7% osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the applicat… Oscommerce 1.0.5.4+ Fix from $2,3002020-10-28 CRITICAL 9.8 CVE-2020-27158EPSS 7% Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5… My Cloud Firmware 5.04.114+ Fix from $2,3002020-10-27 CRITICAL 9.8 CVE-2020-27159EPSS 6% Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western … My Cloud Firmware 5.04.114+ Fix from $2,3002020-10-27 CRITICAL 9.8 CVE-2020-25765EPSS 6% Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prio… My Cloud Firmware 5.04.114+ Fix from $2,3002020-10-27 HIGH 8.8 CVE-2020-26878EPSS 12% Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoi… Ruckus Vriot after 1.5.1.0.21 Fix from $1,9502020-10-26 CRITICAL 9.6 CVE-2020-15272 In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can c… Git Tag Annotation Action 1.0.1+ Fix from $2,3002020-10-26 HIGH 8.8 CVE-2020-15271 In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Use… Lookatme 2.3.0+ Fix from $1,9502020-10-26 HIGH 8.8 CVE-2020-7752EPSS 6% This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's param… Systeminformation 4.27.11+ Fix from $1,9502020-10-26 MEDIUM 6.7 CVE-2020-3457 A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro… Firepower Extensible Operating System 2.4.1.266 / 2.6.1.204+ Fix from $1,6002020-10-21 HIGH 7.8 CVE-2020-3459 A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro… Firepower Extensible Operating System 2.4.1.266 / 2.6.1.204+ Fix from $1,9502020-10-21 HIGH 7.2 CVE-2020-5791EPSS 79% Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating s… Nagios Xi after 5.7.3 Fix from $1,9502020-10-20 HIGH 8.8 CVE-2020-13778 rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to lib/ajaxHandlers/ajaxAddTemplat… Rconfig after 3.9.4 Fix from $1,9502020-10-19 HIGH 7.2 CVE-2020-14144EPSS 95% The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentati… Gitea after 1.12.5 Fix from $1,9502020-10-16 MEDIUM 6.7 CVE-2020-25859 The QCMAP_CLI utility in the Qualcomm QCMAP software suite prior to versions released in October 2020 uses a system() call without validating the inp… Qcmap No fix yet Fix from $1,6002020-10-15 CRITICAL 10.0 CVE-2020-6364EPSS 6% SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a… Introscope Enterprise Manager Mitigation only Fix from $2,3002020-10-15 HIGH 8.8 CVE-2020-17406EPSS 5% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE prior to v1.2.0-r1112. Authent… Bullet Lte Firmware 1.2.0-r1112+ Fix from $1,9502020-10-13 MEDIUM 6.7 CVE-2020-3601 A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate… Staros 21.19.n4+ Fix from $1,6002020-10-08 MEDIUM 6.7 CVE-2020-3602 A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate… Staros 21.19.n4+ Fix from $1,6002020-10-08