Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2020-26582 D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the IP JSON value fo… Dap 1360u Firmware 3.0.1+ Fix from $1,9502020-10-06 CRITICAL 9.8 CVE-2020-12124EPSS 75% A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to e… Wn530h4 Firmware Mitigation only Fix from $2,3002020-10-02 HIGH 7.5 CVE-2020-14293EPSS 5% conf_datetime in Secudos DOMOS 5.8 allows remote attackers to execute arbitrary commands as root via shell metacharacters in the zone field (obtained… Domos after 5.8 Fix from $1,9502020-10-02 MEDIUM 6.6 CVE-2020-7735 The package ng-packagr before 10.1.1 are vulnerable to Command Injection via the styleIncludePaths option. Ng Packagr 10.1.1+ Fix from $1,6002020-09-25 CRITICAL 9.8 CVE-2020-25223 KEVEPSS 97% A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11 Unified Threat Management 9.511 / 9.607+ Fix from $2,3002020-09-25 MEDIUM 6.7 CVE-2020-3417 A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to execute persistent code at boot time and break the chain of … Ios Xe Mitigation only Fix from $1,6002020-09-24 HIGH 7.8 CVE-2020-3403 A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to inject a command to the underlying operating syst… Ios Xe Mitigation only Fix from $1,9502020-09-24 HIGH 8.8 CVE-2020-24365EPSS 11% An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authent… Wrtm 127acn Firmware No fix yet Fix from $1,9502020-09-24 CRITICAL 9.8 CVE-2020-16147 The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated code injection over the netw… Accesslog Firmware after 6.0 Fix from $2,3002020-09-24 HIGH 7.2 CVE-2020-16148 The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via authenticated cod… Accesslog Firmware after 6.0 Fix from $1,9502020-09-24 HIGH 8.8 CVE-2020-11699EPSS 10% An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execut… Spamtitan No fix yet Fix from $1,9502020-09-17 HIGH 8.8 CVE-2020-2276 Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing attackers with Job/Configure per… Selection Tasks after 1.0 Fix from $1,9502020-09-16 HIGH 8.8 CVE-2020-2261 Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitr… Perfecto after 1.17 Fix from $1,9502020-09-16 HIGH 7.2 CVE-2020-24552 Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation, the device's web management … Se5901 Firmware after 1.40 Fix from $1,9502020-09-10 CRITICAL 9.8 CVE-2020-24916EPSS 17% CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection. Ubuntu Linux after 2.0.7 Fix from $2,3002020-09-09 HIGH 7.2 CVE-2020-2037 An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands wi… Pan Os 8.1.16 / 9.0.10+ Fix from $1,9502020-09-09 HIGH 7.2 CVE-2020-2038EPSS 86% An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands wi… Pan Os 9.0.10 / 9.1.4+ Fix from $1,9502020-09-09 HIGH 7.0 CVE-2020-14342 It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. A… Fedora after 6.10 Fix from $1,9502020-09-09 CRITICAL 9.8 CVE-2020-7730 The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param. Bestzip 2.1.7+ Fix from $2,3002020-09-04 HIGH 8.8 CVE-2020-3430 A vulnerability in the application protocol handling features of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to execute … Jabber 12.1.3 / 12.5.2+ Fix from $1,9502020-09-04 CRITICAL 9.8 CVE-2020-13802EPSS 7% Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification. Rebar3 after 3.13.2 Fix from $2,3002020-09-02 HIGH 8.8 CVE-2020-24354 Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell injection. Vmg5313 B30b Firmware after 5.13 Fix from $1,9502020-08-31 HIGH 7.2 CVE-2020-7712 This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function. Json 10.0.0 / 21.1.1.1.0+ Fix from $1,9502020-08-30 HIGH 7.2 CVE-2020-3454 A vulnerability in the Call Home feature of Cisco NX-OS Software could allow an authenticated, remote attacker to inject arbitrary commands that coul… Nx Os Mitigation only Fix from $1,9502020-08-27 HIGH 7.3 CVE-2019-14904 A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name… Ansible 2.7.15 / 2.8.7+ Fix from $1,9502020-08-26 HIGH 8.8 CVE-2020-15642EPSS 7% This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marvell QConvergeConsole 5.5.0.64.… Qconvergeconsole 5.5.00.73+ Fix from $1,9502020-08-25 HIGH 7.2 CVE-2020-17384 Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With the cookie of the system administrator, attackers can inject … Cellos Mitigation only Fix from $1,9502020-08-25 HIGH 8.8 CVE-2020-24572EPSS 7% An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unres… Raspap Patch available Fix from $1,9502020-08-24 HIGH 8.8 CVE-2020-24057EPSS 5% The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows the user to manage network filt… S5120fd Firmware No fix yet Fix from $1,9502020-08-21 CRITICAL 9.8 CVE-2020-24054 The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that can spawn a given process re… Exvf5c 2 Firmware No fix yet Fix from $2,3002020-08-21