Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.7
CVE-2020-12774
D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary command.
Dsl 7740c Firmware
Mitigation only
CRITICAL 9.6
CVE-2020-15121
In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open …
Fedora
4.5.0+
CRITICAL 9.3
CVE-2020-15123
In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlike…
Codecov
3.7.1+
CRITICAL 9.8
CVE-2020-7206
HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.
Nagios Plugins Hpilo
after 1.50
HIGH 8.8
CVE-2020-5756
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An atta…
Gwn7000 Firmware
after 1.0.9.4
CRITICAL 9.8
CVE-2020-5757EPSS 7%
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can …
Ucm6202 Firmware
after 1.0.20.23
HIGH 8.8
CVE-2020-5758
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can …
Ucm6202 Firmware
after 1.0.20.23
CRITICAL 9.8
CVE-2020-5759
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can e…
Ucm6202 Firmware
after 1.0.20.23
CRITICAL 9.8
CVE-2020-7825
A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker …
Miplatform
after 2019.05.16
HIGH 8.8
CVE-2020-11978 KEVEPSS 99%
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example D…
Airflow
1.10.11+
CRITICAL 9.8
CVE-2020-11981EPSS 37%
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ…
Airflow
after 1.10.10
HIGH 8.8
CVE-2020-3332
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authent…
Rv110w Wireless N Vpn Firewall Firmware
1.0.3.55 / 1.2.2.8+
HIGH 7.2
CVE-2020-8958EPSS 47%
Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to execute …
1ge Router Wifi Onu V2801rw Firmware
after 2.9.0-181024
CRITICAL 9.8
CVE-2020-8178
Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.
Jison
after 0.4.18
MEDIUM 5.4
CVE-2020-11084
In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developer…
Ipear
Mitigation only
HIGH 8.8
CVE-2020-11953
An issue was discovered on Rittal PDU-3C002DEC through 5.15.40 and CMCIII-PU-9333E0FB through 3.15.70_4 devices. Attackers can execute code.
Cmciii Pu 9333e0fb Firmware
after 6.17.00
HIGH 7.2
CVE-2020-4512
IBM QRadar SIEM 7.3 and 7.4 could allow a remote privileged user to execute commands.
Qradar Security Information And Event Manager
after 7.3.2
CRITICAL 9.8
CVE-2020-13925EPSS 20%
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi…
Kylin
3.1.0+
CRITICAL 9.8
CVE-2020-10987 KEVEPSS 80%
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the device…
Ac15 Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-8186
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `cer…
Devcert
No fix yet
HIGH 8.8
CVE-2020-9377 KEVEPSS 21%
D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are n…
Dir 610 Firmware
Patch available
HIGH 8.1
CVE-2020-2034EPSS 7%
An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS com…
Pan Os
8.1.15 / 9.0.9+
HIGH 7.2
CVE-2020-2030
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands wi…
Pan Os
8.1.15+
HIGH 8.8
CVE-2020-5352
Dell EMC Data Protection Advisor 6.4, 6.5 and 18.1 contain an OS command injection vulnerability. A remote authenticated malicious user may exploit t…
Emc Data Protection Advisor
Mitigation only
HIGH 8.8
CVE-2020-8188
We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR r…
Unifi Protect Firmware
after 1.14.9
CRITICAL 9.8
CVE-2020-15489
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scrip…
Wl Wn530hg4 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-15310EPSS 8%
An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could …
Linkplay
No fix yet
CRITICAL 9.8
CVE-2019-15311EPSS 8%
An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. The Zolo Halo Bluetooth speaker…
Linkplay
No fix yet
HIGH 7.8
CVE-2020-7688
The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.
Mversion
2.0.1+
CRITICAL 9.8
CVE-2020-13619
php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.
Locutus Php
after 2.0.11