Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2020-7630 git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument. Git Add Remote after 1.0.0 Fix from $2,3002020-04-02 CRITICAL 9.8 CVE-2020-7624 effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument. Effect after 1.0.4 Fix from $2,3002020-04-02 CRITICAL 9.8 CVE-2020-7625 op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function. Op Browser after 1.0.6 Fix from $2,3002020-04-02 CRITICAL 9.8 CVE-2020-7626 karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument. Karma Mojo after 1.0.1 Fix from $2,3002020-04-02 CRITICAL 9.8 CVE-2020-7627 node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'exe… Node Key Sender after 1.0.11 Fix from $2,3002020-04-02 CRITICAL 9.8 CVE-2020-7619 get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-g… Get Git Data after 1.3.1 Fix from $2,3002020-04-02 CRITICAL 9.8 CVE-2020-7620 pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params. Pomelo Monitor after 0.3.7 Fix from $2,3002020-04-02 CRITICAL 9.8 CVE-2020-7621 strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' funct… Strongloop Nginx Controller after 1.0.2 Fix from $2,3002020-04-02 CRITICAL 9.8 CVE-2020-7623 jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument. Jscover after 1.0.0 Fix from $2,3002020-04-02 HIGH 7.2 CVE-2020-11490 Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the … Zen Load Balancer No fix yet Fix from $1,9502020-04-02 HIGH 8.8 CVE-2020-4241EPSS 66% IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on t… Spectrum Protect Plus after 10.1.5 Fix from $1,9502020-03-31 HIGH 8.8 CVE-2020-4242 IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on t… Spectrum Protect Plus after 10.1.5 Fix from $1,9502020-03-31 HIGH 8.8 CVE-2020-4206 IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user… Spectrum Protect Plus after 10.1.5 Fix from $1,9502020-03-31 CRITICAL 9.8 CVE-2019-19606 X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS crede… X Plane 11.41+ Fix from $2,3002020-03-30 CRITICAL 9.8 CVE-2020-10886EPSS 6% This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 route… Ac1750 Firmware Mitigation only Fix from $2,3002020-03-25 HIGH 8.8 CVE-2020-10882EPSS 41% This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC… Ac1750 Firmware No fix yet Fix from $1,9502020-03-25 CRITICAL 9.8 CVE-2020-5282 In Nick Chan Bot before version 1.0.0-beta there is a vulnerability in the `npm` command which is part of this software package. This allows arbitrar… Nick Chan Bot Patch available Fix from $2,3002020-03-25 CRITICAL 9.8 CVE-2020-10789 openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandl… Openitcockpit 3.7.3+ Fix from $2,3002020-03-25 CRITICAL 9.8 CVE-2020-5560 WL-Enq 1.11 and 1.12 allows remote attackers to execute arbitrary OS commands with the administrative privilege via unspecified vectors. Wl Enq Mitigation only Fix from $2,3002020-03-25 CRITICAL 9.8 CVE-2020-5561 Keijiban Tsumiki v1.15 allows remote attackers to execute arbitrary OS commands via unspecified vectors. Keijiban Tsumiki Mitigation only Fix from $2,3002020-03-25 CRITICAL 9.8 CVE-2020-5556 Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to execute arbitrary OS commands via unspecified vectors. Shihonkanri Plus Goout No fix yet Fix from $2,3002020-03-25 CRITICAL 9.8 CVE-2020-10879EPSS 84% rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed direc… Rconfig 3.9.5+ Fix from $2,3002020-03-23 HIGH 7.2 CVE-2019-19034EPSS 6% Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a… Manageengine Assetexplorer No fix yet Fix from $1,9502020-03-23 HIGH 7.2 CVE-2016-11022 NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell … Prosafe Wc9500 Firmware No fix yet Fix from $1,9502020-03-23 HIGH 7.2 CVE-2020-10818 Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the hostname" field. Artica Proxy No fix yet Fix from $1,9502020-03-22 HIGH 8.8 CVE-2020-10808EPSS 78% Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to… Vesta Control Panel after 0.9.8-26 Fix from $1,9502020-03-22 CRITICAL 9.8 CVE-2019-12767 An issue was discovered on D-Link DAP-1650 devices before 1.04B02_J65H Hot Fix. Attackers can execute arbitrary commands. Dap 1650 Firmware 1.04b02_j65h+ Fix from $2,3002020-03-21 CRITICAL 9.8 CVE-2019-19148EPSS 8% Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue … Optical Line Terminal 1150 Firmware No fix yet Fix from $2,3002020-03-20 HIGH 8.8 CVE-2019-19487EPSS 5% Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test. Centreon after 19.04.4 Fix from $1,9502020-03-20 CRITICAL 9.8 CVE-2018-20334 An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell me… Asuswrt No fix yet Fix from $2,3002020-03-20