Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Meeting Server MEDIUM 6.7
CVE-2019-1623

A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as t…

Fix: 2.2.14 / 2.3.8+
Fix from $1,600 2019-06-20
Sd Wan HIGH 8.8
CVE-2019-1624

A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary c…

Fix: 18.4.0+
Fix from $1,950 2019-06-20
Almond 2015 Firmware HIGH 8.8
CVE-2017-8331EPSS 7%

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of…

No fix yet
Fix from $1,950 2019-06-18
Almond 2015 Firmware HIGH 8.8
CVE-2017-8333EPSS 7%

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of…

No fix yet
Fix from $1,950 2019-06-18
Foxit Pdf Sdk Activex HIGH 7.8
CVE-2018-19445

A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API app.launc…

Fix: after 5.5.0
Fix from $1,950 2019-06-17
Foxit Pdf Sdk Activex HIGH 7.8
CVE-2018-19450

A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a launch action. An attacker can …

Fix: after 5.5.0
Fix from $1,950 2019-06-17
Veraedge Firmware HIGH 8.8
CVE-2017-9384

An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a web user interface that allows a user to manage t…

Fix: after 1.7.481
Fix from $1,950 2019-06-17
Veraedge Firmware HIGH 8.8
CVE-2017-9388

An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a web user interface that allows a user to manage t…

Fix: after 1.7.481
Fix from $1,950 2019-06-17
Coldfusion CRITICAL 9.8
CVE-2019-7839EPSS 44%

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploit…

No fix yet
Fix from $2,300 2019-06-12
Asmax Ar 804gu Firmware CRITICAL 9.8
CVE-2009-5156EPSS 11%

An issue was discovered on ASMAX AR-804gu 66.34.1 devices. There is Command Injection via the cgi-bin/script query string.

No fix yet
Fix from $2,300 2019-06-11
Wag54g2 Firmware HIGH 8.8
CVE-2009-5157EPSS 6%

On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable.

No fix yet
Fix from $1,950 2019-06-11
Airos CRITICAL 9.8
CVE-2010-5330 KEVEPSS 35%

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitize…

Fix: 4.0.1 / 5.3.5+
Fix from $2,300 2019-06-11
Dir 300 Firmware CRITICAL 9.8
CVE-2013-7471EPSS 24%

An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 r…

Fix: 1.02b03 / 1.04b11+
Fix from $2,300 2019-06-11
Swr 300a Firmware CRITICAL 9.8
CVE-2016-10760

On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter.

No fix yet
Fix from $2,300 2019-06-11
Wireless Ip Camera Wificam Firmware CRITICAL 9.8
CVE-2017-18377EPSS 7%

An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in…

No fix yet
Fix from $2,300 2019-06-11
Readynas Surveillance Firmware CRITICAL 9.8
CVE-2017-18378EPSS 8%

In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp…

Fix: 1.1.4-7 / 1.4.3-17+
Fix from $2,300 2019-06-11
Dir 818lw Firmware HIGH 8.8
CVE-2019-12786

An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML in…

No fix yet
Fix from $1,950 2019-06-10
Foxit Pdf Sdk Activex HIGH 7.8
CVE-2018-19451

A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when using the Open File action o…

Fix: after 5.5.0
Fix from $1,950 2019-06-07
Stock Browser MEDIUM 5.3
CVE-2018-20523EPSS 10%

Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a …

No fix yet
Fix from $1,600 2019-06-07
Intelligent Management Center CRITICAL 9.8
CVE-2019-5390

A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Fix: 7.3+
Fix from $2,300 2019-06-05
Antimalware HIGH 8.8
CVE-2019-6739EPSS 10%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711. User interac…

Mitigation only
Fix from $1,950 2019-06-03
Insight HIGH 7.6
CVE-2019-12591

NETGEAR Insight Cloud with firmware before Insight 5.6 allows remote authenticated users to achieve command injection.

Fix: 5.6+
Fix from $1,950 2019-06-03
Computrols Building Automation Software HIGH 8.8
CVE-2019-10854

Computrols CBAS 18.0.0 allows Authenticated Command Injection.

Fix: after 19.0.0
Fix from $1,950 2019-05-23
D6220 Firmware HIGH 8.8
CVE-2018-7825

A Command Injection vulnerability exists in the web-based GUI of the 1st Gen PelcoSarix Enhanced Camera that could allow a remote attacker to execute…

Fix: 2.2.3.0+
Fix from $1,950 2019-05-22
D6220 Firmware HIGH 8.8
CVE-2018-7826

A Command Injection vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhanced Camera that could allow a remote attacker to execut…

Fix: 2.2.3.0+
Fix from $1,950 2019-05-22
Nx Os MEDIUM 6.7
CVE-2019-1780

A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker with administrator credential…

Fix: 2.3.1.130 / 2.4.1.122+
Fix from $1,600 2019-05-16
Nx Os MEDIUM 6.7
CVE-2019-1791

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary c…

Fix: 6.0 / 6.2+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1795

A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands…

Fix: 2.0.1.201 / 2.2.2.54+
Fix from $1,600 2019-05-15
Firepower Extensible Operating System MEDIUM 6.7
CVE-2019-1779

A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands…

Fix: 2.4.1.101 / 6.2+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1781

A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands…

Fix: 2.2.2.91 / 2.3.1.130+
Fix from $1,600 2019-05-15