Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Nx Os MEDIUM 6.7
CVE-2019-1782

A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands…

Fix: 2.2.2.91 / 2.3.1.130+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1783

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary c…

Fix: 7.3 / 8.3+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1784

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux…

Fix: 4.0 / 7.3+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1790

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with valid administrator credentials to execute arbit…

Fix: 4.0 / 6.2+
Fix from $1,600 2019-05-15
GitLab HIGH 7.5
CVE-2019-10640

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input vali…

Fix: 11.7.10 / 11.8.6+
Fix from $1,950 2019-05-15
Nx Os HIGH 7.8
CVE-2019-1735

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privilege…

Fix: 4.0 / 5.2+
Fix from $1,950 2019-05-15
Tidal Workload Automation HIGH 7.8
CVE-2019-6689

An issue was discovered in Dillon Kane Tidal Workload Automation Agent 3.2.0.5 (formerly known as Cisco Workload Automation or CWA). The Enterprise S…

Mitigation only
Fix from $1,950 2019-04-26
Bonobo Git Server CRITICAL 9.8
CVE-2019-11217

The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the context of the web server via a cr…

Fix: 6.5.0+
Fix from $2,300 2019-04-24
Cribl CRITICAL 9.8
CVE-2019-11076

Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request.

No fix yet
Fix from $2,300 2019-04-23
Spectrum Power 4 CRITICAL 9.8
CVE-2019-6579

A vulnerability has been identified in Spectrum Power 4 (with Web Office Portal). An attacker with network access to the web server on port 80/TCP or…

Mitigation only
Fix from $2,300 2019-04-17
Edgeswitch X HIGH 8.8
CVE-2019-5424

In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to…

Fix: after 1.1.0
Fix from $1,950 2019-04-10
Webaccess CRITICAL 9.8
CVE-2019-6552

Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-suppli…

Fix: after 8.3.5
Fix from $2,300 2019-04-05
Rails CRITICAL 9.8
CVE-2019-5420EPSS 92%

A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated dev…

Fix: 5.2.2.1+
Fix from $2,300 2019-03-27
Rad 80211 Xd\/hp Bus Firmware HIGH 8.8
CVE-2019-9743

An issue was discovered on PHOENIX CONTACT RAD-80211-XD and RAD-80211-XD/HP-BUS devices. Command injection can occur in the WebHMI component.

No fix yet
Fix from $1,950 2019-03-26
Cms Made Simple HIGH 7.2
CVE-2019-9059

An issue was discovered in CMS Made Simple 2.2.8. It is possible, with an administrator account, to achieve command injection by modifying the path o…

Fix: after 2.2.8
Fix from $1,950 2019-03-26
Kibana CRITICAL 9.0
CVE-2019-7610

Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.securi…

Fix: 5.6.15 / 6.6.1+
Fix from $2,300 2019-03-25
Donfig CRITICAL 9.8
CVE-2019-7537

An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can execute arbitrary Python comman…

No fix yet
Fix from $2,300 2019-03-21
Smart Firewall HIGH 8.0
CVE-2018-3963

An exploitable command injection vulnerability exists in the DHCP daemon configuration of the CUJO Smart Firewall. When adding a new static DHCP addr…

No fix yet
Fix from $1,950 2019-03-21
Gl Ar300m Lite Firmware HIGH 8.8
CVE-2019-6272EPSS 13%

Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.

No fix yet
Fix from $1,950 2019-03-21
Gl Ar300m Lite Firmware HIGH 8.8
CVE-2019-6275EPSS 13%

Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary cod…

No fix yet
Fix from $1,950 2019-03-21
Morgan CRITICAL 9.8
CVE-2019-5413

An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.

Fix: 1.9.1+
Fix from $2,300 2019-03-21
Kill Port HIGH 8.1
CVE-2019-5414

If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec fu…

Fix: 1.3.2+
Fix from $1,950 2019-03-21
Nx Os MEDIUM 6.7
CVE-2019-1610

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…

Fix: 7.0+
Fix from $1,600 2019-03-11
Nx Os MEDIUM 6.7
CVE-2019-1611

A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands…

Fix: 2.2.2.91 / 2.3.1.110+
Fix from $1,600 2019-03-11
Nx Os MEDIUM 6.7
CVE-2019-1612

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…

Fix: 7.0+
Fix from $1,600 2019-03-11
Nx Os MEDIUM 6.7
CVE-2019-1613

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…

Mitigation only
Fix from $1,600 2019-03-11
Nx Os HIGH 8.8
CVE-2019-1614

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root p…

Fix: 7.0 / 7.3+
Fix from $1,950 2019-03-11
Nx Os HIGH 7.8
CVE-2019-1606

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…

Fix: 7.0+
Fix from $1,950 2019-03-08
Nx Os MEDIUM 6.7
CVE-2019-1607

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…

Fix: 6.2 / 7.3+
Fix from $1,600 2019-03-08
Nx Os MEDIUM 6.7
CVE-2019-1608

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…

Fix: 6.2 / 7.3+
Fix from $1,600 2019-03-08