Skip to main content

CWE archive

CWE-88 CVEs

Programmatic archive

403 CVEs tagged with CWE-8886 Critical, 205 High, 102 Medium, 10 Low, 0 Unrated.

CVE-2020-21224

Published Feb 22, 2021

A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-3401

Published Feb 4, 2021

Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformpluginpath argument to the bitcoin-qt progr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35136

Published Dec 23, 2020

Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7769

Published Nov 12, 2020

This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25268

Published Nov 10, 2020

Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27129

Published Nov 6, 2020

A vulnerability in the remote management feature of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands and potentially gain el…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5792

Published Oct 20, 2020

Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code wi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14027

Published Sep 22, 2020

An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The database connection strings accept custom unsafe arguments, such as ENABLE_LOCAL_INFILE, that can be leveraged…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4492

Published Aug 31, 2020

IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the kernel by sending a subset of io…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15692

Published Aug 14, 2020

In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that will be opened in the default e…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-13699

Published Jul 29, 2020

TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrate…

CVSS 8.8 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2020-3380

Published Jul 16, 2020

A vulnerability in the CLI of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to elevate privileges to root and execute arbitrary commands on…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14049

Published Jun 22, 2020

Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTL…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14421

Published Jun 18, 2020

aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via the Script Content box on the Add Cron Job screen.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7496

Published Jun 16, 2020

A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could caus…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 301-325 of 403 CVEsPage 13 of 17