Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2020-7597
codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is ex…
Codecov
3.6.5+
CRITICAL 9.8
CVE-2020-9026
ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NTP-2 device is also affected.
Ntp 2 Firmware
No fix yet
CRITICAL 9.8
CVE-2020-9027
ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The NTP-2 device is also affected.
Ntp 2 Firmware
No fix yet
CRITICAL 9.8
CVE-2020-9020
Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacte…
Vantage Velocity Firmware
No fix yet
CRITICAL 9.8
CVE-2020-9021
Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections…
Awam Bluetooth Field Device Firmware
No fix yet
HIGH 8.8
CVE-2020-8858EPSS 9%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.1. Authen…
Mgate 5105 Mb Eip Firmware
after 4.1
CRITICAL 9.8
CVE-2020-8963
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003,…
Sr9850 Firmware
No fix yet
HIGH 8.8
CVE-2020-8949
Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572, and ISP3000 4.3.0.17190 devi…
S2a Wl Firmware
No fix yet
HIGH 8.8
CVE-2020-8946
Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-igd/sys_log…
Wf2471 Firmware
No fix yet
HIGH 7.2
CVE-2020-8947EPSS 22%
functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?op…
Pandora Fms
No fix yet
HIGH 8.8
CVE-2020-8429
The Admin web application in Kinetica 7.0.9.2.20191118151947 does not properly sanitise the input for the function getLogs. This lack of sanitisation…
Kinetica
No fix yet
HIGH 7.8
CVE-2013-0517
A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command…
Sterling External Authentication Server
Mitigation only
CRITICAL 9.8
CVE-2019-14514EPSS 7%
An issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu emulator contains a /system/b…
Memu
7.0.2+
CRITICAL 9.8
CVE-2013-4267
Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Powe…
Pydio
5.0.1+
HIGH 7.5
CVE-2019-19356 KEVEPSS 28%
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been fo…
Wf2419 Firmware
Mitigation only
HIGH 7.8
CVE-2020-8126
A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execut…
Edgeswitch
1.7.1+
HIGH 8.8
CVE-2020-8654EPSS 86%
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitr…
Eyesofnetwork
No fix yet
CRITICAL 9.8
CVE-2020-6760
Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu, …
Zi 620 V400 Firmware
No fix yet
CRITICAL 9.8
CVE-2019-10789
All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sani…
Curling
No fix yet
CRITICAL 9.8
CVE-2019-10786
network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.
Network Manager
after 1.0.2
CRITICAL 9.8
CVE-2019-10787
im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be …
Im Resize
after 2.3.2
CRITICAL 9.8
CVE-2019-10788
im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands …
Im Metadata
after 3.0.1
HIGH 8.8
CVE-2015-3611EPSS 6%
A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could l…
Fortimanager
after 5.2.1
CRITICAL 9.8
CVE-2020-8515 KEVEPSS 100%
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as roo…
Vigor2960 Firmware
Mitigation only
HIGH 7.2
CVE-2013-3322
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot interface.
Oncommand System Manager
after 2.1
HIGH 8.1
CVE-2020-1930EPSS 7%
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configur…
Spamassassin
3.4.3+
HIGH 8.1
CVE-2020-1931EPSS 6%
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to…
Spamassassin
3.4.3+
MEDIUM 6.8
CVE-2019-20050
Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated user should create a new folder…
Pandora Fms
No fix yet
HIGH 7.2
CVE-2020-8438
Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler fo…
Ruckus Zoneflex R500 Firmware
No fix yet
CRITICAL 9.8
CVE-2019-10783
All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function…
Isof
after 0.0.4