Total
2535 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2020-2508 | 1 Qnap | 2 Qts, Quts Hero | 2024-11-21 | 7.2 High |
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later) | ||||
CVE-2020-2507 | 1 Qnap | 1 Helpdesk | 2024-11-21 | 9.8 Critical |
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3. | ||||
CVE-2020-2492 | 1 Qnap | 1 Qts | 2024-11-21 | 7.2 High |
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907. | ||||
CVE-2020-2490 | 1 Qnap | 1 Qts | 2024-11-21 | 7.2 High |
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907. | ||||
CVE-2020-29599 | 3 Debian, Imagemagick, Redhat | 3 Debian Linux, Imagemagick, Enterprise Linux | 2024-11-21 | 7.8 High |
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c. | ||||
CVE-2020-29548 | 1 Smartertools | 1 Smartermail | 2024-11-21 | 8.1 High |
An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS command, injecting plaintext commands into an encrypted user session. | ||||
CVE-2020-29299 | 1 Zyxel | 7 Atp, Nsg, Nsg Firmware and 4 more | 2024-11-21 | 7.2 High |
Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38, and NSG before 1.33 patch 4. | ||||
CVE-2020-28908 | 1 Nagios | 1 Fusion | 2024-11-21 | 9.8 Critical |
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios. | ||||
CVE-2020-28902 | 1 Nagios | 1 Fusion | 2024-11-21 | 9.8 Critical |
Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php. | ||||
CVE-2020-28901 | 1 Nagios | 1 Fusion | 2024-11-21 | 9.8 Critical |
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php. | ||||
CVE-2020-28453 | 1 Npos-tesseract Project | 1 Npos-tesseract | 2024-11-21 | 9.4 Critical |
This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js. | ||||
CVE-2020-28451 | 1 Image-tiler Project | 1 Image-tiler | 2024-11-21 | 9.8 Critical |
This affects the package image-tiler before 2.0.2. | ||||
CVE-2020-28447 | 1 Xopen Project | 1 Xopen | 2024-11-21 | 9.8 Critical |
This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath) | ||||
CVE-2020-28446 | 1 Ntesseract Project | 1 Ntesseract | 2024-11-21 | 9.8 Critical |
The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js. | ||||
CVE-2020-28445 | 1 Npm-help Project | 1 Npm-help | 2024-11-21 | 9.8 Critical |
This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function. | ||||
CVE-2020-28443 | 1 Sonar-wrapper Project | 1 Sonar-wrapper | 2024-11-21 | 9.8 Critical |
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js. | ||||
CVE-2020-28438 | 1 Deferred-exec Project | 1 Deferred-exec | 2024-11-21 | 9.8 Critical |
This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js | ||||
CVE-2020-28437 | 1 Heroku-env Project | 1 Heroku-env | 2024-11-21 | 9.4 Critical |
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js. | ||||
CVE-2020-28436 | 1 Google-cloudstorage-commands Project | 1 Google-cloudstorage-commands | 2024-11-21 | 7.3 High |
This affects all versions of package google-cloudstorage-commands. | ||||
CVE-2020-28435 | 1 Ffmpeg-sdk Project | 1 Ffmpeg-sdk | 2024-11-21 | 9.4 Critical |
This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js. |