Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2019-5156
An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and…
Pfc200 Firmware
No fix yet
HIGH 7.2
CVE-2019-5157
An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07…
Pfc200 Firmware
No fix yet
CRITICAL 9.8
CVE-2019-10807
Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the arguments provided …
Blamer
1.0.1+
HIGH 7.8
CVE-2020-1980
A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. T…
Pan Os
8.1.13+
HIGH 8.8
CVE-2019-9859
Vesta Control Panel (VestaCP) 0.9.7 through 0.9.8-23 is vulnerable to an authenticated command execution that can result in remote root access on the…
Vesta Control Panel
after 0.9.8-23
CRITICAL 9.8
CVE-2020-10250
BWA DiREX-Pro 1.2181 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the PKG parameter to uninstall.php3.
Direx Pro Firmware
No fix yet
HIGH 8.8
CVE-2020-2159
Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the…
Cryptomove
after 0.1.33
HIGH 8.8
CVE-2020-10235
An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via th…
Froxlor
0.10.14+
CRITICAL 9.8
CVE-2019-20504EPSS 10%
service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell …
Kace Systems Management
6.4.120822+
HIGH 7.2
CVE-2016-11021 KEVEPSS 69%
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
Dcs 930l Firmware
2.12+
HIGH 8.8
CVE-2020-10221 KEVEPSS 37%
lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the…
Rconfig
after 3.9.4
HIGH 8.8
CVE-2020-10213
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin …
Dir 825 Firmware
No fix yet
HIGH 8.8
CVE-2020-10215EPSS 5%
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parame…
Dir 825 Firmware
No fix yet
HIGH 8.8
CVE-2020-10216EPSS 5%
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a s…
Dir 825 Firmware
No fix yet
HIGH 8.8
CVE-2019-17642
An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharac…
Centreon
18.10.8 / 19.04.2+
HIGH 8.8
CVE-2020-10173EPSS 77%
Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and tracerout…
Vr 3033 Firmware
No fix yet
HIGH 7.8
CVE-2019-20499EPSS 95%
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the …
Dwl 2600ap Firmware
after 4.2.0.15
HIGH 7.8
CVE-2019-20500 KEVEPSS 97%
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web…
Dwl 2600ap Firmware
after 4.2.0.15
HIGH 7.8
CVE-2019-20501EPSS 90%
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web i…
Dwl 2600ap Firmware
after 4.2.0.15
CRITICAL 9.8
CVE-2020-9054 KEVEPSS 100%
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, whi…
Nas326 Firmware
4.35 / 5.21+
MEDIUM 6.7
CVE-2020-3176
A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of…
Remote Phy 120 Firmware
7.7+
HIGH 8.8
CVE-2020-5535
OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to execute arbitrary OS commands with root privil…
Openblocks Iot Vx2 Firmware
4.0.0+
HIGH 7.4
CVE-2020-1734
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=…
Ansible Engine
after 3.3.4
CRITICAL 9.8
CVE-2019-20488
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to com…
Wnr1000 Firmware
No fix yet
CRITICAL 9.8
CVE-2019-10803
push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" is not validated before being …
Push Dir
after 0.4.1
CRITICAL 9.8
CVE-2019-10804
serial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is used by the "exec" function …
Serial Number
after 1.3.0
CRITICAL 9.8
CVE-2019-10801
enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization.
Enpeem
after 2.2.0
CRITICAL 9.8
CVE-2019-10802
giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is executed by the package witho…
Giting
0.0.8+
CRITICAL 9.8
CVE-2019-15609
The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.
Kill Port Process
2.2.0+
HIGH 8.8
CVE-2020-9463
Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an …
Centreon
No fix yet