Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
MEDIUM 6.7 CVE-2020-12774 D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary command. Dsl 7740c Firmware Mitigation only Fix from $1,6002020-07-22 CRITICAL 9.6 CVE-2020-15121 In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open … Fedora 4.5.0+ Fix from $2,3002020-07-20 CRITICAL 9.3 CVE-2020-15123 In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlike… Codecov 3.7.1+ Fix from $2,3002020-07-20 CRITICAL 9.8 CVE-2020-7206 HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability. Nagios Plugins Hpilo after 1.50 Fix from $2,3002020-07-17 HIGH 8.8 CVE-2020-5756 Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An atta… Gwn7000 Firmware after 1.0.9.4 Fix from $1,9502020-07-17 CRITICAL 9.8 CVE-2020-5757EPSS 7% Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can … Ucm6202 Firmware after 1.0.20.23 Fix from $2,3002020-07-17 HIGH 8.8 CVE-2020-5758 Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can … Ucm6202 Firmware after 1.0.20.23 Fix from $1,9502020-07-17 CRITICAL 9.8 CVE-2020-5759 Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can e… Ucm6202 Firmware after 1.0.20.23 Fix from $2,3002020-07-17 CRITICAL 9.8 CVE-2020-7825 A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker … Miplatform after 2019.05.16 Fix from $2,3002020-07-17 HIGH 8.8 CVE-2020-11978 KEVEPSS 99% An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example D… Airflow 1.10.11+ Fix from $1,9502020-07-17 CRITICAL 9.8 CVE-2020-11981EPSS 37% An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ… Airflow after 1.10.10 Fix from $2,3002020-07-17 HIGH 8.8 CVE-2020-3332 A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authent… Rv110w Wireless N Vpn Firewall Firmware 1.0.3.55 / 1.2.2.8+ Fix from $1,9502020-07-16 HIGH 7.2 CVE-2020-8958EPSS 47% Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to execute … 1ge Router Wifi Onu V2801rw Firmware after 2.9.0-181024 Fix from $1,9502020-07-15 CRITICAL 9.8 CVE-2020-8178 Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks. Jison after 0.4.18 Fix from $2,3002020-07-15 MEDIUM 5.4 CVE-2020-11084 In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developer… Ipear Mitigation only Fix from $1,6002020-07-14 HIGH 8.8 CVE-2020-11953 An issue was discovered on Rittal PDU-3C002DEC through 5.15.40 and CMCIII-PU-9333E0FB through 3.15.70_4 devices. Attackers can execute code. Cmciii Pu 9333e0fb Firmware after 6.17.00 Fix from $1,9502020-07-14 HIGH 7.2 CVE-2020-4512 IBM QRadar SIEM 7.3 and 7.4 could allow a remote privileged user to execute commands. Qradar Security Information And Event Manager after 7.3.2 Fix from $1,9502020-07-14 CRITICAL 9.8 CVE-2020-13925EPSS 20% Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi… Kylin 3.1.0+ Fix from $2,3002020-07-14 CRITICAL 9.8 CVE-2020-10987 KEVEPSS 80% The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the device… Ac15 Firmware Mitigation only Fix from $2,3002020-07-13 CRITICAL 9.8 CVE-2020-8186 A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `cer… Devcert No fix yet Fix from $2,3002020-07-10 HIGH 8.8 CVE-2020-9377 KEVEPSS 21% D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are n… Dir 610 Firmware Patch available Fix from $1,9502020-07-09 HIGH 8.1 CVE-2020-2034EPSS 7% An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS com… Pan Os 8.1.15 / 9.0.9+ Fix from $1,9502020-07-08 HIGH 7.2 CVE-2020-2030 An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands wi… Pan Os 8.1.15+ Fix from $1,9502020-07-08 HIGH 8.8 CVE-2020-5352 Dell EMC Data Protection Advisor 6.4, 6.5 and 18.1 contain an OS command injection vulnerability. A remote authenticated malicious user may exploit t… Emc Data Protection Advisor Mitigation only Fix from $1,9502020-07-06 HIGH 8.8 CVE-2020-8188 We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR r… Unifi Protect Firmware after 1.14.9 Fix from $1,9502020-07-02 CRITICAL 9.8 CVE-2020-15489 An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scrip… Wl Wn530hg4 Firmware Mitigation only Fix from $2,3002020-07-01 CRITICAL 9.8 CVE-2019-15310EPSS 8% An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could … Linkplay No fix yet Fix from $2,3002020-07-01 CRITICAL 9.8 CVE-2019-15311EPSS 8% An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. The Zolo Halo Bluetooth speaker… Linkplay No fix yet Fix from $2,3002020-07-01 HIGH 7.8 CVE-2020-7688 The issue occurs because tagName user input is formatted inside the exec function is executed without any checks. Mversion 2.0.1+ Fix from $1,9502020-07-01 CRITICAL 9.8 CVE-2020-13619 php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution. Locutus Php after 2.0.11 Fix from $2,3002020-07-01