Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2020-12109EPSS 74%
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3…
Nc200 Firmware
No fix yet
HIGH 8.8
CVE-2020-12111EPSS 8%
Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.
Nc260 Firmware
No fix yet
CRITICAL 9.8
CVE-2020-12641 KEVEPSS 84%
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for …
Webmail
1.2.10 / 1.3.11+
CRITICAL 9.8
CVE-2020-7645
All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.
Chrome Launcher
0.13.2+
HIGH 8.8
CVE-2020-7351EPSS 65%
An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute com…
Trixbox
after 2.8.0.4
HIGH 8.8
CVE-2020-11016
IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled messages given by user-input in…
Intelmq Manager
2.1.1+
HIGH 8.8
CVE-2019-19217
BMC Control-M/Agent 7.0.00.000 allows OS Command Injection.
Control M\/agent
Mitigation only
HIGH 8.8
CVE-2019-19220
BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).
Control M\/agent
Mitigation only
CRITICAL 9.8
CVE-2019-5623
Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Comma…
File Transfer Appliance
No fix yet
CRITICAL 9.8
CVE-2016-11061
Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do no…
Workcentre 3655 Firmware
073.060.086.15410 / 073.190.086.15410+
HIGH 7.2
CVE-2020-7804
ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShellExec met…
Groupware
Mitigation only
HIGH 8.8
CVE-2020-12246
Beeline Smart Box 2.0.38 routers allow "Advanced settings > Other > Diagnostics" OS command injection via the Ping ping_ipaddr parameter, the Nslooku…
Smart Box Firmware
No fix yet
MEDIUM 6.8
CVE-2018-21225
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000 before 1.0.1.60, D7800 before 1.0.1.34, D8500 …
D7800 Firmware
1.0.1.30 / 1.0.1.34+
CRITICAL 9.8
CVE-2017-18858
Certain NETGEAR devices are affected by command execution. This affects M4200-10MG-POE+ 12.0.2.11 and earlier, M4300-28G 12.0.2.11 and earlier, M4300…
M4200 10mg Poe\+ Firmware
after 12.0.2.11
HIGH 7.2
CVE-2016-11054
NETGEAR DGN2200v4 devices before 2017-01-06 are affected by command execution and an FTP insecure root directory.
Dgn2200 Firmware
2017-01-06+
HIGH 8.8
CVE-2020-12078EPSS 10%
An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker c…
Open Audit
Patch available
CRITICAL 9.8
CVE-2020-7640
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any …
Pixl Class
1.0.3+
HIGH 8.0
CVE-2018-21100
NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.
R7800 Firmware
1.0.2.60+
MEDIUM 6.8
CVE-2018-21152
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, R7500v2 before 1.0.3.26, R780…
D7800 Firmware
1.0.0.54 / 1.0.1.34+
MEDIUM 6.8
CVE-2018-21154
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, DM200 before 1.0.0.50, R6100 …
D7800 Firmware
1.0.0.50 / 1.0.0.122+
MEDIUM 6.8
CVE-2018-21157
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.28, R6700 before 1.0.1.44, R6900 …
D7800 Firmware
1.0.0.50 / 1.0.1.28+
MEDIUM 6.8
CVE-2018-21098
NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.
R7800 Firmware
1.0.2.60+
HIGH 8.0
CVE-2018-21099
NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.
R7800 Firmware
1.0.2.60+
HIGH 8.8
CVE-2020-11941
An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.
Open Audit
No fix yet
HIGH 7.8
CVE-2020-12242
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different us…
Source
No fix yet
CRITICAL 9.8
CVE-2020-5868
In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell commands on affected systems u…
Big Iq Centralized Management
after 6.1.0
HIGH 7.2
CVE-2018-21164
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.64 and WNDR3700v5 before 1.1.0.54.
R6220 Firmware
1.1.0.54 / 1.1.0.64+
CRITICAL 9.8
CVE-2018-21162
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0.0.78, EX6200 before 1.0.3.86,…
D6400 Firmware
1.0.0.64 / 1.0.0.78+
MEDIUM 6.8
CVE-2018-21106
NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.
R7800 Firmware
1.0.2.60+
MEDIUM 6.8
CVE-2018-21107
NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.
R7800 Firmware
1.0.2.60+