Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-7630
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.
Git Add Remote
after 1.0.0
CRITICAL 9.8
CVE-2020-7624
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
Effect
after 1.0.4
CRITICAL 9.8
CVE-2020-7625
op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.
Op Browser
after 1.0.6
CRITICAL 9.8
CVE-2020-7626
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
Karma Mojo
after 1.0.1
CRITICAL 9.8
CVE-2020-7627
node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'exe…
Node Key Sender
after 1.0.11
CRITICAL 9.8
CVE-2020-7619
get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-g…
Get Git Data
after 1.3.1
CRITICAL 9.8
CVE-2020-7620
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.
Pomelo Monitor
after 0.3.7
CRITICAL 9.8
CVE-2020-7621
strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' funct…
Strongloop Nginx Controller
after 1.0.2
CRITICAL 9.8
CVE-2020-7623
jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.
Jscover
after 1.0.0
HIGH 7.2
CVE-2020-11490
Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the …
Zen Load Balancer
No fix yet
HIGH 8.8
CVE-2020-4241EPSS 66%
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on t…
Spectrum Protect Plus
after 10.1.5
HIGH 8.8
CVE-2020-4242
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on t…
Spectrum Protect Plus
after 10.1.5
HIGH 8.8
CVE-2020-4206
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user…
Spectrum Protect Plus
after 10.1.5
CRITICAL 9.8
CVE-2019-19606
X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS crede…
X Plane
11.41+
CRITICAL 9.8
CVE-2020-10886EPSS 6%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 route…
Ac1750 Firmware
Mitigation only
HIGH 8.8
CVE-2020-10882EPSS 41%
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC…
Ac1750 Firmware
No fix yet
CRITICAL 9.8
CVE-2020-5282
In Nick Chan Bot before version 1.0.0-beta there is a vulnerability in the `npm` command which is part of this software package. This allows arbitrar…
Nick Chan Bot
Patch available
CRITICAL 9.8
CVE-2020-10789
openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandl…
Openitcockpit
3.7.3+
CRITICAL 9.8
CVE-2020-5560
WL-Enq 1.11 and 1.12 allows remote attackers to execute arbitrary OS commands with the administrative privilege via unspecified vectors.
Wl Enq
Mitigation only
CRITICAL 9.8
CVE-2020-5561
Keijiban Tsumiki v1.15 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Keijiban Tsumiki
Mitigation only
CRITICAL 9.8
CVE-2020-5556
Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Shihonkanri Plus Goout
No fix yet
CRITICAL 9.8
CVE-2020-10879EPSS 84%
rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed direc…
Rconfig
3.9.5+
HIGH 7.2
CVE-2019-19034EPSS 6%
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a…
Manageengine Assetexplorer
No fix yet
HIGH 7.2
CVE-2016-11022
NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell …
Prosafe Wc9500 Firmware
No fix yet
HIGH 7.2
CVE-2020-10818
Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the hostname" field.
Artica Proxy
No fix yet
HIGH 8.8
CVE-2020-10808EPSS 78%
Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to…
Vesta Control Panel
after 0.9.8-26
CRITICAL 9.8
CVE-2019-12767
An issue was discovered on D-Link DAP-1650 devices before 1.04B02_J65H Hot Fix. Attackers can execute arbitrary commands.
Dap 1650 Firmware
1.04b02_j65h+
CRITICAL 9.8
CVE-2019-19148EPSS 8%
Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue …
Optical Line Terminal 1150 Firmware
No fix yet
HIGH 8.8
CVE-2019-19487EPSS 5%
Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.
Centreon
after 19.04.4
CRITICAL 9.8
CVE-2018-20334
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell me…
Asuswrt
No fix yet