Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-78
Total 2452 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-14950 1 Aapanel 1 Aapanel 2021-07-21 6.5 MEDIUM 8.8 HIGH
aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a modified /system?action=ServiceAdmin request (start, stop, or restart) to the setting menu of Sotfware Store.
CVE-2019-4715 1 Ibm 1 Spectrum Scale 2021-07-21 9.0 HIGH 8.8 HIGH
IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 172093.
CVE-2020-7604 1 Pulverizr Project 1 Pulverizr 2021-07-21 7.5 HIGH 9.8 CRITICAL
pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be controlled by the attacker. This function uses the variable "filename" to construct the argument of the exec call without any sanitization. In order to successfully exploit this vulnerability, an attacker will need to create a new file with the same name as the attack command.
CVE-2020-7605 1 Gulp-tape Project 1 Gulp-tape 2021-07-21 7.5 HIGH 9.8 CRITICAL
gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of 'gulp-tape' options.
CVE-2020-7607 1 Gulp-styledocco Project 1 Gulp-styledocco 2021-07-21 7.5 HIGH 9.8 CRITICAL
gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in 'index.js' can be controlled by users without any sanitization.
CVE-2020-7603 1 Closure-compiler-stream Project 1 Closure-compiler-stream 2021-07-21 7.5 HIGH 9.8 CRITICAL
closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports function in "index.js" can be controlled by users without any sanitization.
CVE-2020-7606 1 Docker-compose-remote-api Project 1 Docker-compose-remote-api 2021-07-21 7.5 HIGH 9.8 CRITICAL
docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd, fnStdout, fnStderr, fnExit)' uses the variable 'serviceName' which can be controlled by users without any sanitization.
CVE-2020-7601 1 Gulp-scss-lint Project 1 Gulp-scss-lint 2021-07-21 7.5 HIGH 9.8 CRITICAL
gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the "exec" function located in "src/command.js" via the provided options.
CVE-2020-7602 1 Node-prompt-here Project 1 Node-prompt-here 2021-07-21 7.5 HIGH 9.8 CRITICAL
node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" function in file "linux/manager.js", which is required by the "index. process.env.NM_CLI" in the file "linux/manager.js". This function is used to construct the argument of function "execSync()", which can be controlled by users without any sanitization.
CVE-2020-13619 1 Locutus 1 Locutus Php 2021-07-21 7.5 HIGH 9.8 CRITICAL
php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.
CVE-2020-7613 1 Clamscan Project 1 Clamscan 2021-07-21 6.8 MEDIUM 8.1 HIGH
clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_is_clamav_binary` function located within `Index.js`. It should be noted that this vulnerability requires a pre-requisite that a folder should be created with the same command that will be chained to execute. This lowers the risk of this issue.
CVE-2020-7596 1 Codecov 1 Nodejs Uploader 2021-07-21 6.5 MEDIUM 8.8 HIGH
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
CVE-2020-16257 1 Winstonprivacy 2 Winston, Winston Firmware 2021-07-21 10.0 HIGH 9.8 CRITICAL
Winston 1.5.4 devices are vulnerable to command injection via the API.
CVE-2020-6757 1 Rasilient 2 Pixelstor 5000, Pixelstor 5000 Firmware 2021-07-21 6.5 MEDIUM 8.8 HIGH
contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute code via the name parameter.
CVE-2020-6948 1 Hashbrowncms 1 Hashbrown Cms 2021-07-21 7.5 HIGH 9.8 CRITICAL
A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, and password.
CVE-2020-7206 1 Hp 1 Nagios-plugins-hpilo 2021-07-21 7.5 HIGH 9.8 CRITICAL
HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.
CVE-2020-12393 2 Microsoft, Mozilla 4 Windows, Firefox, Firefox Esr and 1 more 2021-07-21 4.6 MEDIUM 7.8 HIGH
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
CVE-2020-6756 1 Rasilient 2 Pixelstor 5000, Pixelstor 5000 Firmware 2021-07-21 7.5 HIGH 9.8 CRITICAL
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.
CVE-2020-13802 1 Erlang 1 Rebar3 2021-07-21 10.0 HIGH 9.8 CRITICAL
Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.
CVE-2020-28431 2021-07-21 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.