Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2020-14947EPSS 19% OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main… Open Computer Software Inventory Next Generation Patch available Fix from $1,9502020-06-30 CRITICAL 9.8 CVE-2020-15415 KEVEPSS 85% On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell … Vigor3900 Firmware 1.5.1+ Fix from $2,3002020-06-30 HIGH 8.8 CVE-2020-14412 NeDi 1.9C is vulnerable to Remote Command Execution. System-Snapshot.php improperly escapes shell metacharacters from a POST request. An attacker can… Nedi Mitigation only Fix from $1,9502020-06-29 HIGH 8.8 CVE-2020-14414 NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a POST request. An attacker can exploit t… Nedi Mitigation only Fix from $1,9502020-06-29 CRITICAL 9.8 CVE-2020-15362 wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite the default executable/binary p… Wifiscanner No fix yet Fix from $2,3002020-06-29 CRITICAL 9.8 CVE-2020-14072 An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin scripts. Mk Auth Mitigation only Fix from $2,3002020-06-29 HIGH 8.8 CVE-2019-16213 Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a spe… Pa6 Firmware No fix yet Fix from $1,9502020-06-25 CRITICAL 9.8 CVE-2020-13159EPSS 9% Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Al… Artica Proxy 4.30.000000+ Fix from $2,3002020-06-22 HIGH 7.2 CVE-2019-14894 A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution throu… Cloudforms Management Engine Mitigation only Fix from $1,9502020-06-22 HIGH 7.2 CVE-2020-4066 In Limdu before 0.95, the trainBatch function has a command injection vulnerability. Clients of the Limdu library are unlikely to be aware of this, s… Limdu 0.9.5+ Fix from $1,9502020-06-22 HIGH 8.8 CVE-2020-14950 aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a modified /system?action=ServiceAd… Aapanel after 6.6.6 Fix from $1,9502020-06-21 HIGH 7.2 CVE-2020-3336 A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authen… Roomos 9.9.4+ Fix from $1,9502020-06-18 HIGH 7.2 CVE-2020-3274 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,… Rv016 Firmware after 4.2.3.10 Fix from $1,9502020-06-18 HIGH 7.2 CVE-2020-3275 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,… Rv016 Firmware after 4.2.3.10 Fix from $1,9502020-06-18 HIGH 7.2 CVE-2020-3276 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,… Rv016 Firmware after 4.2.3.10 Fix from $1,9502020-06-18 HIGH 7.2 CVE-2020-3277 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,… Rv016 Firmware after 4.2.3.10 Fix from $1,9502020-06-18 HIGH 7.2 CVE-2020-3278 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,… Rv016 Firmware after 4.2.3.10 Fix from $1,9502020-06-18 HIGH 7.2 CVE-2020-3279 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016,… Rv016 Firmware after 4.2.3.10 Fix from $1,9502020-06-18 CRITICAL 9.8 CVE-2020-4469EPSS 13% IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted H… Spectrum Protect Plus after 10.1.5 Fix from $2,3002020-06-15 HIGH 8.8 CVE-2020-14075 TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action pppoe_connect, ru_pppoe_connect, or dhcp_… Tew 827dru Firmware after 2.06b04 Fix from $1,9502020-06-15 HIGH 8.8 CVE-2020-14081 TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action send_log_email with the key auth_acname (… Tew 827dru Firmware after 2.06b04 Fix from $1,9502020-06-15 HIGH 8.8 CVE-2020-13851EPSS 91% Artica Pandora FMS 7.44 allows remote command execution via the events feature. Pandora Fms No fix yet Fix from $1,9502020-06-11 HIGH 7.2 CVE-2020-2028 An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root priv… Pan Os 8.1.13 / 9.0.7+ Fix from $1,9502020-06-10 HIGH 7.2 CVE-2020-2029 An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to execute arbitrary OS commands wit… Pan Os 7.1.26 / 8.1.13+ Fix from $1,9502020-06-10 HIGH 8.8 CVE-2020-13976 An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters i… Dd Wrt after 16214 Fix from $1,9502020-06-09 HIGH 7.2 CVE-2020-13978 Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute arbitrary… Monstra Cms No fix yet Fix from $1,9502020-06-09 HIGH 8.8 CVE-2020-3224 A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privil… Ios Xe Patch available Fix from $1,9502020-06-03 MEDIUM 6.7 CVE-2020-3210 A vulnerability in the CLI parsers of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 100… iOS Patch available Fix from $1,6002020-06-03 HIGH 7.2 CVE-2020-3211 A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileg… Ios Xe Patch available Fix from $1,9502020-06-03 HIGH 7.2 CVE-2020-3212 A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileg… Ios Xe Patch available Fix from $1,9502020-06-03