Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2020-3205
A vulnerability in the implementation of the inter-VM channel of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Ind…
iOS
Patch available
MEDIUM 6.7
CVE-2020-3207
A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root s…
Ios Xe
Mitigation only
HIGH 8.8
CVE-2020-13782EPSS 27%
D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.
Dir 865l Firmware
No fix yet
HIGH 8.8
CVE-2020-4180
IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted re…
Security Guardium
Patch available
HIGH 8.8
CVE-2020-2200
Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the `play` command on the Jenkins master for a form validation endpoin…
Play Framework
after 1.0.2
CRITICAL 9.8
CVE-2014-8945
admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.
Lexiglot
after 2014-11-20
CRITICAL 9.8
CVE-2014-7173
FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx25MonProxy.php, syseditdate.ph…
Farlinx X25 Gateway Firmware
after 2014-09-25
HIGH 8.8
CVE-2020-13448EPSS 17%
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via comm…
Quickbox
after 2.5.5
HIGH 8.8
CVE-2020-13694
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password, which m…
Quickbox
after 2.5.5
HIGH 7.2
CVE-2020-8816 KEVEPSS 78%
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
Pi Hole
after 4.3.2
MEDIUM 5.3
CVE-2019-20807
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby,…
Debian Linux
8.1.0881+
HIGH 8.8
CVE-2020-11950
VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a scri…
Cc9381 Hv Firmware
after 0222g
HIGH 8.8
CVE-2020-8605EPSS 88%
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installa…
Interscan Web Security Virtual Appliance
Patch available
HIGH 7.8
CVE-2020-12393
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If …
Firefox
68.8.0 / 76.0+
CRITICAL 9.8
CVE-2020-8171
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.…
Airos
after 6.2.0
CRITICAL 9.8
CVE-2020-13388
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configura…
Jw.util
2.3+
HIGH 8.8
CVE-2020-1956 KEVEPSS 97%
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is …
Kylin
after 2.6.5
HIGH 8.8
CVE-2020-13252EPSS 5%
Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a m…
Centreon
19.04.15+
HIGH 8.8
CVE-2020-11766
sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.
Hylafax
0.2.5 / 3.3.6+
CRITICAL 9.8
CVE-2020-13167EPSS 95%
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a …
Netsweeper
after 6.4.3
HIGH 8.8
CVE-2020-2014
An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root…
Pan Os
after 9.0.6
HIGH 7.2
CVE-2020-2007
An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary comm…
Pan Os
after 9.0.6
HIGH 7.2
CVE-2020-2008
An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute co…
Pan Os
after 8.1.13
HIGH 7.2
CVE-2020-2010
An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root…
Pan Os
after 9.0.6
HIGH 7.2
CVE-2020-10795
Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to authenticated remote code execution via the backup functionality of the web frontend. This can be combin…
Tks Ip Gateway Firmware
No fix yet
CRITICAL 9.1
CVE-2020-4428 KEVEPSS 62%
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-F…
Data Risk Manager
after 2.0.4
CRITICAL 9.8
CVE-2020-7805
An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection a…
Iml500 Firmware
after 29.8.2018
CRITICAL 9.8
CVE-2020-7646
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
Curlrequest
after 1.0.1
HIGH 7.3
CVE-2020-6651
Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allow…
Intelligent Power Manager
after 1.67
HIGH 7.2
CVE-2020-5332
RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privile…
Archer
6.7.0.3+