Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-16790
In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.
Tiny File Manager
2.3.9+
CRITICAL 9.8
CVE-2019-10774
php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Php Shellcommand
1.6.1+
CRITICAL 9.8
CVE-2019-17621 KEVEPSS 90%
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute syste…
Dir 859 Firmware
after 3.12b04
MEDIUM 6.6
CVE-2019-6013
DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line Interface (CLI).
Dba 1510p Firmware
after 1.70b009
HIGH 8.8
CVE-2019-6014
DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User Interface.
Dba 1510p Firmware
after 1.70b009
HIGH 8.8
CVE-2019-19920
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (r…
Ubuntu Linux
Patch available
CRITICAL 9.8
CVE-2019-15598
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Treekill
Mitigation only
HIGH 7.8
CVE-2019-8513
This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to execute arbitrary shell comma…
Mac Os X
10.14.4+
CRITICAL 9.8
CVE-2019-11399
An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. OS command injection occurs through the get…
Tew 651br Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-18830
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the function…
Clickshare Cs 100 Firmware
1.9.0+
CRITICAL 9.8
CVE-2019-16730
processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary syst…
Petalk Ai Firmware
No fix yet
CRITICAL 9.8
CVE-2019-16733
processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary syste…
Petalk Ai Firmware
No fix yet
CRITICAL 9.8
CVE-2019-16737
The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute ar…
Petalk Ai Firmware
No fix yet
CRITICAL 9.8
CVE-2019-17364
The processCommandUploadLog() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute…
Petalk Ai Firmware
No fix yet
MEDIUM 6.7
CVE-2018-11805
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits ca…
Spamassassin
3.4.3+
HIGH 8.8
CVE-2019-3985
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…
Blink Xt2 Sync Module Firmware
2.13.11+
HIGH 8.8
CVE-2019-3986
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…
Blink Xt2 Sync Module Firmware
2.13.11+
HIGH 8.8
CVE-2019-3987
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…
Blink Xt2 Sync Module Firmware
2.13.11+
HIGH 8.8
CVE-2019-3988
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…
Blink Xt2 Sync Module Firmware
2.13.11+
CRITICAL 9.8
CVE-2019-3989
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…
Blink Xt2 Sync Module Firmware
2.13.11+
HIGH 8.8
CVE-2014-0163
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.
Openshift
Mitigation only
HIGH 8.8
CVE-2019-4715
IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafte…
Spectrum Scale
after 5.0.4.0
HIGH 7.8
CVE-2019-19604
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.2…
Git
2.20.0 / 2.21.1+
HIGH 8.8
CVE-2019-14889
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a serve…
Ubuntu Linux
0.8.8 / 0.9.3+
CRITICAL 9.8
CVE-2019-17270EPSS 59%
Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?…
Yachtcontrol
after 2019-10-06
HIGH 8.8
CVE-2019-19642EPSS 19%
On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated att…
X8sti F Bios
No fix yet
HIGH 7.2
CVE-2019-19609EPSS 54%
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel,…
Strapi
after 1.6.4
HIGH 8.8
CVE-2019-19469
In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with s…
Amanda
Mitigation only
CRITICAL 9.8
CVE-2011-2523EPSS 96%
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
Debian Linux
No fix yet
HIGH 8.8
CVE-2017-12945EPSS 17%
Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to execute …
Solstice Firmware
2.8.4+