Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.7
CVE-2020-3169
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux …
Firepower Extensible Operating System
2.2.2.97 / 2.3.1.144+
HIGH 7.8
CVE-2020-3171
A vulnerability in the local management (local-mgmt) CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local at…
Ucs Manager
Mitigation only
HIGH 7.8
CVE-2020-3173
A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitr…
Ucs Manager
3.2 / 4.0+
HIGH 7.8
CVE-2020-3167
A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary co…
Secure Firewall Threat Defense
2.4.1.234 / 3.2+
CRITICAL 9.8
CVE-2019-19994
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. An attacker without authentica…
Visual Access Manager
after 4.29.0
HIGH 7.8
CVE-2019-3999EPSS 9%
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to ex…
Insync Client
No fix yet
CRITICAL 9.9
CVE-2019-5138EPSS 5%
An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A spe…
Awk 3131a Firmware
No fix yet
HIGH 8.8
CVE-2019-5140
An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted di…
Awk 3131a Firmware
Mitigation only
HIGH 8.8
CVE-2019-5141
An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted i…
Awk 3131a Firmware
No fix yet
HIGH 7.2
CVE-2019-5142EPSS 7%
An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted …
Awk 3131a Firmware
No fix yet
CRITICAL 9.8
CVE-2020-9374EPSS 43%
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends spe…
Tl Wr849n Firmware
No fix yet
CRITICAL 9.8
CVE-2019-12511
In NETGEAR Nighthawk X10-R9000 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a specially-crafted MAC addres…
Nighthawk X10 R9000 Firmware
1.0.4.26+
CRITICAL 9.8
CVE-2019-10796
rpi through 0.0.3 allows execution of arbritary commands. The variable pinNumbver in function GPIO within src/lib/gpio.js is used as part of the argu…
Rpi
after 0.0.3
HIGH 8.2
CVE-2019-10799
compile-sass prior to 1.0.5 allows execution of arbritary commands. The function "setupCleanupOnExit(cssPath)" within "dist/index.js" is executed as …
Compile Sass
1.0.5+
CRITICAL 9.8
CVE-2020-4210EPSS 15%
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …
Spectrum Protect
10.1.5+
CRITICAL 9.8
CVE-2020-4211EPSS 71%
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …
Spectrum Protect
10.1.5+
CRITICAL 9.8
CVE-2020-4213EPSS 15%
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …
Spectrum Protect
10.1.5+
CRITICAL 9.8
CVE-2020-4222EPSS 15%
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …
Spectrum Protect
10.1.5+
CRITICAL 9.8
CVE-2019-18182
pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsi…
Fedora
5.2+
CRITICAL 9.8
CVE-2019-18183
pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. This can be exploited when unsig…
Fedora
5.2+
MEDIUM 6.4
CVE-2020-8130
There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character …
Ubuntu Linux
12.3.3+
HIGH 8.8
CVE-2020-8813EPSS 74%
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has …
Fedora
No fix yet
CRITICAL 9.8
CVE-2020-6841
D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the spotifyConnect.ph…
Dch M225 Firmware
after 1.05b01
HIGH 7.2
CVE-2020-6842
D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the media …
Dch M225 Firmware
after 1.05b01
HIGH 8.8
CVE-2020-5524
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier…
Aterm Wg2600hs Firmware
after 1.3.2
HIGH 8.0
CVE-2020-5525
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier…
Aterm Wg2600hs Firmware
after 1.3.2
HIGH 8.0
CVE-2020-5534
Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root …
Aterm Wg2600hs Firmware
after 1.3.2
CRITICAL 9.8
CVE-2014-2727
The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.
Mailmarshal
7.2+
CRITICAL 9.8
CVE-2019-10791
promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and options functions can be controll…
Promise Probe
0.10.0+
CRITICAL 9.8
CVE-2014-4981EPSS 6%
LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization of the web GUI parameters.
Lpar2rrd
after 3.50