Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2020-3205 A vulnerability in the implementation of the inter-VM channel of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Ind… iOS Patch available Fix from $1,9502020-06-03 MEDIUM 6.7 CVE-2020-3207 A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root s… Ios Xe Mitigation only Fix from $1,6002020-06-03 HIGH 8.8 CVE-2020-13782EPSS 27% D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection. Dir 865l Firmware No fix yet Fix from $1,9502020-06-03 HIGH 8.8 CVE-2020-4180 IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted re… Security Guardium Patch available Fix from $1,9502020-06-03 HIGH 8.8 CVE-2020-2200 Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the `play` command on the Jenkins master for a form validation endpoin… Play Framework after 1.0.2 Fix from $1,9502020-06-03 CRITICAL 9.8 CVE-2014-8945 admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields. Lexiglot after 2014-11-20 Fix from $2,3002020-06-01 CRITICAL 9.8 CVE-2014-7173 FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx25MonProxy.php, syseditdate.ph… Farlinx X25 Gateway Firmware after 2014-09-25 Fix from $2,3002020-06-01 HIGH 8.8 CVE-2020-13448EPSS 17% QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via comm… Quickbox after 2.5.5 Fix from $1,9502020-06-01 HIGH 8.8 CVE-2020-13694 In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password, which m… Quickbox after 2.5.5 Fix from $1,9502020-06-01 HIGH 7.2 CVE-2020-8816 KEVEPSS 78% Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease. Pi Hole after 4.3.2 Fix from $1,9502020-05-29 MEDIUM 5.3 CVE-2019-20807 In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby,… Debian Linux 8.1.0881+ Fix from $1,6002020-05-28 HIGH 8.8 CVE-2020-11950 VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a scri… Cc9381 Hv Firmware after 0222g Fix from $1,9502020-05-28 HIGH 8.8 CVE-2020-8605EPSS 88% A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installa… Interscan Web Security Virtual Appliance Patch available Fix from $1,9502020-05-27 HIGH 7.8 CVE-2020-12393 The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If … Firefox 68.8.0 / 76.0+ Fix from $1,9502020-05-26 CRITICAL 9.8 CVE-2020-8171 We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.… Airos after 6.2.0 Fix from $2,3002020-05-26 CRITICAL 9.8 CVE-2020-13388 An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configura… Jw.util 2.3+ Fix from $2,3002020-05-22 HIGH 8.8 CVE-2020-1956 KEVEPSS 97% Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is … Kylin after 2.6.5 Fix from $1,9502020-05-22 HIGH 8.8 CVE-2020-13252EPSS 5% Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a m… Centreon 19.04.15+ Fix from $1,9502020-05-21 HIGH 8.8 CVE-2020-11766 sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection. Hylafax 0.2.5 / 3.3.6+ Fix from $1,9502020-05-19 CRITICAL 9.8 CVE-2020-13167EPSS 95% Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a … Netsweeper after 6.4.3 Fix from $2,3002020-05-19 HIGH 8.8 CVE-2020-2014 An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root… Pan Os after 9.0.6 Fix from $1,9502020-05-13 HIGH 7.2 CVE-2020-2007 An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary comm… Pan Os after 9.0.6 Fix from $1,9502020-05-13 HIGH 7.2 CVE-2020-2008 An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute co… Pan Os after 8.1.13 Fix from $1,9502020-05-13 HIGH 7.2 CVE-2020-2010 An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root… Pan Os after 9.0.6 Fix from $1,9502020-05-13 HIGH 7.2 CVE-2020-10795 Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to authenticated remote code execution via the backup functionality of the web frontend. This can be combin… Tks Ip Gateway Firmware No fix yet Fix from $1,9502020-05-07 CRITICAL 9.1 CVE-2020-4428 KEVEPSS 62% IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-F… Data Risk Manager after 2.0.4 Fix from $2,3002020-05-07 CRITICAL 9.8 CVE-2020-7805 An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection a… Iml500 Firmware after 29.8.2018 Fix from $2,3002020-05-07 CRITICAL 9.8 CVE-2020-7646 curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input. Curlrequest after 1.0.1 Fix from $2,3002020-05-07 HIGH 7.3 CVE-2020-6651 Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allow… Intelligent Power Manager after 1.67 Fix from $1,9502020-05-07 HIGH 7.2 CVE-2020-5332 RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privile… Archer 6.7.0.3+ Fix from $1,9502020-05-04