Total
2088 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2019-5414 | 1 Kill-port Project | 1 Kill-port | 2024-08-04 | N/A |
If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module kill-port < 1.3.2. | ||||
CVE-2019-5390 | 1 Hp | 1 Intelligent Management Center | 2024-08-04 | N/A |
A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | ||||
CVE-2019-5323 | 1 Arubanetworks | 1 Airwave | 2024-08-04 | 7.2 High |
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host. | ||||
CVE-2019-3421 | 1 Ztw | 2 Zx297520v3, Zx297520v3 Firmware | 2024-08-04 | 8.0 High |
The 7520V3V1.0.0B09P27 version, and all earlier versions of ZTE product ZX297520V3 are impacted by a Command Injection vulnerability. Unauthorized users can exploit this vulnerability to control the user terminal system. | ||||
CVE-2019-1584 | 1 Zingbox | 1 Inspector | 2024-08-04 | 9.8 Critical |
A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a malicious command from the Zingbox cloud, or if the Zingbox Inspector were tampered with to connect to an attacker's cloud endpoint. | ||||
CVE-2019-0542 | 2 Redhat, Xtermjs | 3 Openshift, Openshift Container Platform, Xterm.js | 2024-08-04 | 8.8 High |
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js. | ||||
CVE-2019-0541 | 1 Microsoft | 13 Excel Viewer, Internet Explorer, Office and 10 more | 2024-08-04 | N/A |
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus. | ||||
CVE-2020-36650 | 1 Gry Project | 1 Gry | 2024-08-04 | 5.5 Medium |
A vulnerability, which was classified as critical, was found in IonicaBizau node-gry up to 5.x. This affects an unknown part. The manipulation leads to command injection. Upgrading to version 6.0.0 is able to address this issue. The patch is named 5108446c1e23960d65e8b973f1d9486f9f9dbd6c. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-218019. | ||||
CVE-2020-36642 | 1 Jobe Project | 1 Jobe | 2024-08-04 | 5.5 Medium |
A vulnerability was found in trampgeek jobe up to 1.6.x and classified as critical. This issue affects the function run_in_sandbox of the file application/libraries/LanguageTask.php. The manipulation leads to command injection. Upgrading to version 1.7.0 is able to address this issue. The identifier of the patch is 8f43daf50c943b98eaf0c542da901a4a16e85b02. It is recommended to upgrade the affected component. The identifier VDB-217553 was assigned to this vulnerability. | ||||
CVE-2020-36529 | 1 Ibm | 1 Sevone Network Performance Management | 2024-08-04 | 8.8 High |
A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the Traceroute Handler. The manipulation leads to privilege escalation with a command injection. It is possible to initiate the attack remotely. | ||||
CVE-2020-36463 | 1 Multiqueue Project | 1 Multiqueue | 2024-08-04 | 8.1 High |
An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of Send for InnerSend<RW, T>, InnerRecv<RW, T>, FutInnerSend<RW, T>, and FutInnerRecv<RW, T>. | ||||
CVE-2020-36457 | 1 Lever Project | 1 Lever | 2024-08-04 | 8.1 High |
An issue was discovered in the lever crate before 0.1.1 for Rust. AtomicBox<T> implements the Send and Sync traits for all types T. | ||||
CVE-2020-36449 | 1 Kekbit Project | 1 Kekbit | 2024-08-04 | 8.1 High |
An issue was discovered in the kekbit crate before 0.3.4 for Rust. For ShmWriter<H>, Send is implemented without requiring H: Send. | ||||
CVE-2020-36462 | 1 Syncpool Project | 1 Syncpool | 2024-08-04 | 8.1 High |
An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send for Bucket2. | ||||
CVE-2020-36448 | 1 Cache Project | 1 Cache | 2024-08-04 | 8.1 High |
An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for Cache<K>. | ||||
CVE-2020-36450 | 1 Bunch Project | 1 Bunch | 2024-08-04 | 8.1 High |
An issue was discovered in the bunch crate through 2020-11-12 for Rust. There are unconditional implementations of Send and Sync for Bunch<T>. | ||||
CVE-2020-36461 | 1 Noise Search Project | 1 Noise Search | 2024-08-04 | 8.1 High |
An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync for MvccRwLock. | ||||
CVE-2020-36451 | 1 Rcu Cell Project | 1 Rcu Cell | 2024-08-04 | 8.1 High |
An issue was discovered in the rcu_cell crate through 2020-11-14 for Rust. There are unconditional implementations of Send and Sync for RcuCell<T>. | ||||
CVE-2020-36459 | 1 Dces Project | 1 Dces | 2024-08-04 | 8.1 High |
An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds on its EntityStore and ComponentStore. | ||||
CVE-2020-36456 | 1 Toolshed Project | 1 Toolshed | 2024-08-04 | 8.1 High |
An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell<T>, the Send trait lacks bounds on the contained type. |