Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2020-7597 codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is ex… Codecov 3.6.5+ Fix from $1,9502020-02-17 CRITICAL 9.8 CVE-2020-9026 ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NTP-2 device is also affected. Ntp 2 Firmware No fix yet Fix from $2,3002020-02-17 CRITICAL 9.8 CVE-2020-9027 ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The NTP-2 device is also affected. Ntp 2 Firmware No fix yet Fix from $2,3002020-02-17 CRITICAL 9.8 CVE-2020-9020 Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacte… Vantage Velocity Firmware No fix yet Fix from $2,3002020-02-17 CRITICAL 9.8 CVE-2020-9021 Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections… Awam Bluetooth Field Device Firmware No fix yet Fix from $2,3002020-02-17 HIGH 8.8 CVE-2020-8858EPSS 9% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.1. Authen… Mgate 5105 Mb Eip Firmware after 4.1 Fix from $1,9502020-02-14 CRITICAL 9.8 CVE-2020-8963 TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003,… Sr9850 Firmware No fix yet Fix from $2,3002020-02-13 HIGH 8.8 CVE-2020-8949 Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572, and ISP3000 4.3.0.17190 devi… S2a Wl Firmware No fix yet Fix from $1,9502020-02-12 HIGH 8.8 CVE-2020-8946 Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-igd/sys_log… Wf2471 Firmware No fix yet Fix from $1,9502020-02-12 HIGH 7.2 CVE-2020-8947EPSS 22% functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?op… Pandora Fms No fix yet Fix from $1,9502020-02-12 HIGH 8.8 CVE-2020-8429 The Admin web application in Kinetica 7.0.9.2.20191118151947 does not properly sanitise the input for the function getLogs. This lack of sanitisation… Kinetica No fix yet Fix from $1,9502020-02-11 HIGH 7.8 CVE-2013-0517 A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command… Sterling External Authentication Server Mitigation only Fix from $1,9502020-02-11 CRITICAL 9.8 CVE-2019-14514EPSS 7% An issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu emulator contains a /system/b… Memu 7.0.2+ Fix from $2,3002020-02-11 CRITICAL 9.8 CVE-2013-4267 Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Powe… Pydio 5.0.1+ Fix from $2,3002020-02-11 HIGH 7.5 CVE-2019-19356 KEVEPSS 28% Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been fo… Wf2419 Firmware Mitigation only Fix from $1,9502020-02-07 HIGH 7.8 CVE-2020-8126 A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execut… Edgeswitch 1.7.1+ Fix from $1,9502020-02-07 HIGH 8.8 CVE-2020-8654EPSS 86% An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitr… Eyesofnetwork No fix yet Fix from $1,9502020-02-07 CRITICAL 9.8 CVE-2020-6760 Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu, … Zi 620 V400 Firmware No fix yet Fix from $2,3002020-02-06 CRITICAL 9.8 CVE-2019-10789 All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sani… Curling No fix yet Fix from $2,3002020-02-06 CRITICAL 9.8 CVE-2019-10786 network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument. Network Manager after 1.0.2 Fix from $2,3002020-02-04 CRITICAL 9.8 CVE-2019-10787 im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be … Im Resize after 2.3.2 Fix from $2,3002020-02-04 CRITICAL 9.8 CVE-2019-10788 im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands … Im Metadata after 3.0.1 Fix from $2,3002020-02-04 HIGH 8.8 CVE-2015-3611EPSS 6% A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could l… Fortimanager after 5.2.1 Fix from $1,9502020-02-04 CRITICAL 9.8 CVE-2020-8515 KEVEPSS 100% DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as roo… Vigor2960 Firmware Mitigation only Fix from $2,3002020-02-01 HIGH 7.2 CVE-2013-3322 NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot interface. Oncommand System Manager after 2.1 Fix from $1,9502020-01-31 HIGH 8.1 CVE-2020-1930EPSS 7% A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configur… Spamassassin 3.4.3+ Fix from $1,9502020-01-30 HIGH 8.1 CVE-2020-1931EPSS 6% A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to… Spamassassin 3.4.3+ Fix from $1,9502020-01-30 MEDIUM 6.8 CVE-2019-20050 Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated user should create a new folder… Pandora Fms No fix yet Fix from $1,6002020-01-30 HIGH 7.2 CVE-2020-8438 Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler fo… Ruckus Zoneflex R500 Firmware No fix yet Fix from $1,9502020-01-29 CRITICAL 9.8 CVE-2019-10783 All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function… Isof after 0.0.4 Fix from $2,3002020-01-29