Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Enigma Network Management Solution CRITICAL 9.8
CVE-2019-16072EPSS 26%

An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbit…

Fix: after 65.0.0
Fix from $2,300 2020-03-20
Sd Wan Firmware HIGH 7.8
CVE-2020-3266

A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbitrary commands that are execu…

Fix: 19.2.2+
Fix from $1,950 2020-03-19
Perlspeak CRITICAL 9.8
CVE-2020-10674

PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argument open.

Fix: after 2.01
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12132

An issue was discovered in ONAP SDNC before Dublin. By executing sla/dgUpload with a crafted filename parameter, an unauthenticated attacker can exec…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12112

An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauthenticated attacker can execut…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform HIGH 8.8
CVE-2019-12113

An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authenticated user can execute an …

Fix: 4.0.0+
Fix from $1,950 2020-03-18
Open Network Automation Platform HIGH 8.8
CVE-2019-12123

An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsXml with a crafted module parameter, an authenticated user can execute an…

Fix: 4.0.0+
Fix from $1,950 2020-03-18
Exfat Driver HIGH 8.1
CVE-2019-11689

An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly valida…

No fix yet
Fix from $1,950 2020-03-18
Centro Grande Firmware HIGH 7.2
CVE-2019-19940

Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allows remote authenticated users …

Fix: 6.14.06+
Fix from $1,950 2020-03-16
Fortiap MEDIUM 6.7
CVE-2019-15708

A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under C…

Fix: after 6.0.5
Fix from $1,600 2020-03-15
Gulp Scss Lint CRITICAL 9.8
CVE-2020-7601

gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the "exec" function located in "s…

Fix: after 1.0.0
Fix from $2,300 2020-03-15
Node Prompt Here CRITICAL 9.8
CVE-2020-7602

node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" function in file "linux/manager…

Fix: after 1.0.1
Fix from $2,300 2020-03-15
Closure Compiler Stream CRITICAL 9.8
CVE-2020-7603

closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports function in "index.js" can be co…

Fix: after 0.1.15
Fix from $2,300 2020-03-15
Pulverizr CRITICAL 9.8
CVE-2020-7604

pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be controlled by the attacker. This …

Fix: after 0.7.0
Fix from $2,300 2020-03-15
Gulp Tape CRITICAL 9.8
CVE-2020-7605

gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of 'gulp-tape' options.

Fix: after 1.0.0
Fix from $2,300 2020-03-15
Docker Compose Remote Api CRITICAL 9.8
CVE-2020-7606

docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd…

Fix: after 0.1.4
Fix from $2,300 2020-03-15
Gulp Styledocco CRITICAL 9.8
CVE-2020-7607

gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in 'index.js' can be controlled …

Fix: after 0.0.3
Fix from $2,300 2020-03-15
Hdx System Software HIGH 7.2
CVE-2019-11355

An issue was discovered in Poly (formerly Polycom) HDX 3.1.13. A feature exists that allows the creation of a server / client certificate, or the upl…

Fix: after 3.1.13
Fix from $1,950 2020-03-12
Tc Router 3002t 4g Firmware HIGH 8.8
CVE-2020-9436

PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT t…

Fix: after 2.05.3
Fix from $1,950 2020-03-12
Phpkb HIGH 7.2
CVE-2020-10390

OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-Language 9 allows r…

No fix yet
Fix from $1,950 2020-03-12
Pfc200 Firmware HIGH 7.8
CVE-2019-5170

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14).…

No fix yet
Fix from $1,950 2020-03-12
Pfc200 Firmware HIGH 7.8
CVE-2019-5171

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14).…

No fix yet
Fix from $1,950 2020-03-12
Pfc200 Firmware HIGH 7.8
CVE-2019-5169

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14).…

No fix yet
Fix from $1,950 2020-03-12
Pfc200 Firmware HIGH 7.8
CVE-2019-5172

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14).…

No fix yet
Fix from $1,950 2020-03-11
Pfc200 Firmware HIGH 7.8
CVE-2019-5173

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14).…

No fix yet
Fix from $1,950 2020-03-11
Pfc200 Firmware HIGH 7.8
CVE-2019-5174

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). A specia…

No fix yet
Fix from $1,950 2020-03-11
Pfc200 Firmware HIGH 7.8
CVE-2019-5175

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14).…

No fix yet
Fix from $1,950 2020-03-11
Pfc200 Firmware HIGH 7.8
CVE-2019-5167

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). At 0x1e3…

No fix yet
Fix from $1,950 2020-03-11
Pfc200 Firmware HIGH 7.8
CVE-2019-5168

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). An attac…

No fix yet
Fix from $1,950 2020-03-11
Pfc200 Firmware HIGH 7.2
CVE-2019-5155

An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating system comma…

No fix yet
Fix from $1,950 2020-03-11