Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-16279
The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed to the c…
Rangeeos
Mitigation only
HIGH 8.8
CVE-2020-16282
In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged root user. This may allow a …
Rangeeos
Mitigation only
CRITICAL 9.8
CVE-2020-17456EPSS 74%
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.
Slc 130 Firmware
No fix yet
HIGH 8.8
CVE-2020-23934EPSS 16%
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager…
Ritecms
No fix yet
CRITICAL 9.8
CVE-2020-24032EPSS 5%
tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.
Lpar2rrd
Mitigation only
HIGH 8.8
CVE-2020-24220
ShopXO v1.8.1 has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands and gain control of the serve…
Shopxo
Mitigation only
HIGH 8.8
CVE-2020-13122EPSS 7%
The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, is vulnerable to command injec…
Noviware
No fix yet
HIGH 8.8
CVE-2020-8233
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell comma…
Edgeswitch Firmware
1.9.0+
HIGH 7.2
CVE-2020-16205EPSS 61%
Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 …
G Cam Ebc 2110 Firmware
No fix yet
MEDIUM 6.7
CVE-2020-11733
An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restric…
Avalanche
after 5.08
CRITICAL 9.8
CVE-2020-12107
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module's Operat…
Vpncrypt M10 Firmware
Mitigation only
HIGH 8.8
CVE-2020-17505EPSS 82%
Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands a…
Web Proxy
No fix yet
HIGH 8.8
CVE-2020-13124
SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an authenticated user to execute …
Sabnzbd
Patch available
CRITICAL 9.8
CVE-2020-17368
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
Debian Linux
after 0.9.62
CRITICAL 9.1
CVE-2020-14324
A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerabil…
Cloudforms Management Engine
5.11.7.0+
HIGH 8.8
CVE-2020-17352
Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to r…
Xg Firewall Firmware
Patch available
HIGH 8.8
CVE-2020-11852
DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020…
Secure Messaging Gateway
2020-07-01+
CRITICAL 9.9
CVE-2020-7357EPSS 32%
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and …
Cms Se Firmware
Patch available
HIGH 8.8
CVE-2020-7361EPSS 17%
The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating…
Zentao Pro
after 8.8.2
HIGH 8.8
CVE-2020-13404EPSS 7%
The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.
Atos\/sips
after 3.0.5
CRITICAL 9.8
CVE-2020-13151EPSS 87%
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of …
Aerospike Server
4.5.3.21 / 4.6.0.19+
HIGH 8.8
CVE-2020-15467
The administrative interface of Cohesive Networks vns3:vpn appliances before version 4.11.1 is vulnerable to authenticated remote code execution lead…
Vns3
4.11.1+
HIGH 8.8
CVE-2020-3377
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject…
Data Center Network Manager
Mitigation only
HIGH 7.8
CVE-2020-12620
Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection (shell metacharacters after …
Pi Hole
5.0+
HIGH 7.8
CVE-2020-14162
An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a passw…
Pi Hole
5.1+
HIGH 7.8
CVE-2020-5760EPSS 5%
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers…
Ht801 Firmware
after 1.0.17.5
CRITICAL 9.8
CVE-2020-7698
This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.
Gerapy
0.9.3+
CRITICAL 9.8
CVE-2020-15608EPSS 8%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication …
Webpanel
Mitigation only
CRITICAL 9.8
CVE-2020-15609EPSS 8%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication …
Centos Web Panel
Mitigation only
CRITICAL 9.8
CVE-2020-15610EPSS 8%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication …
Webpanel
Mitigation only