Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,180 CVEs tagged with CWE-781,976 Critical, 3,126 High, 890 Medium, 188 Low, 0 Unrated.

CVE-2020-17456

Published Aug 20, 2020

SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2020-24032

Published Aug 18, 2020

tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-23934

Published Aug 18, 2020

An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24220

Published Aug 17, 2020

ShopXO v1.8.1 has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands and gain control of the server.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13122

Published Aug 17, 2020

The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, is vulnerable to command injection in the "show status desti…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-17505

Published Aug 12, 2020

Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileg…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13124

Published Aug 11, 2020

SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an authenticated user to execute arbitrary Python commands on t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14324

Published Aug 11, 2020

A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authen…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-17352

Published Aug 7, 2020

Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11852

Published Aug 7, 2020

DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020. The vulnerability could allo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7361

Published Aug 6, 2020

The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, atta…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7357

Published Aug 6, 2020

Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell comman…

CVSS 9.6 · Critical

CVE-2020-13151

Published Aug 5, 2020

Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15467

Published Aug 4, 2020

The administrative interface of Cohesive Networks vns3:vpn appliances before version 4.11.1 is vulnerable to authenticated remote code execution leading to server compromise.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-3377

Published Jul 31, 2020

A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the aff…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-14162

Published Jul 30, 2020

An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a password, which could allow an atta…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12620

Published Jul 30, 2020

Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection (shell metacharacters after an IP address).

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5760

Published Jul 29, 2020

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers can execute arbitrary command…

CVSS 7.8 · High

CVE-2020-7698

Published Jul 29, 2020

This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 4,651-4,675 of 6,180 CVEsPage 187 of 248