Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Firepower Extensible Operating System MEDIUM 6.7
CVE-2020-3169

A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux …

Fix: 2.2.2.97 / 2.3.1.144+
Fix from $1,600 2020-02-26
Ucs Manager HIGH 7.8
CVE-2020-3171

A vulnerability in the local management (local-mgmt) CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local at…

Mitigation only
Fix from $1,950 2020-02-26
Ucs Manager HIGH 7.8
CVE-2020-3173

A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitr…

Fix: 3.2 / 4.0+
Fix from $1,950 2020-02-26
Secure Firewall Threat Defense HIGH 7.8
CVE-2020-3167

A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary co…

Fix: 2.4.1.234 / 3.2+
Fix from $1,950 2020-02-26
Visual Access Manager CRITICAL 9.8
CVE-2019-19994

An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. An attacker without authentica…

Fix: after 4.29.0
Fix from $2,300 2020-02-26
Insync Client HIGH 7.8
CVE-2019-3999EPSS 9%

Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to ex…

No fix yet
Fix from $1,950 2020-02-25
Awk 3131a Firmware CRITICAL 9.9
CVE-2019-5138EPSS 5%

An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A spe…

No fix yet
Fix from $2,300 2020-02-25
Awk 3131a Firmware HIGH 8.8
CVE-2019-5140

An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted di…

Mitigation only
Fix from $1,950 2020-02-25
Awk 3131a Firmware HIGH 8.8
CVE-2019-5141

An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted i…

No fix yet
Fix from $1,950 2020-02-25
Awk 3131a Firmware HIGH 7.2
CVE-2019-5142EPSS 7%

An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted …

No fix yet
Fix from $1,950 2020-02-25
Tl Wr849n Firmware CRITICAL 9.8
CVE-2020-9374EPSS 43%

On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends spe…

No fix yet
Fix from $2,300 2020-02-24
Nighthawk X10 R9000 Firmware CRITICAL 9.8
CVE-2019-12511

In NETGEAR Nighthawk X10-R9000 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a specially-crafted MAC addres…

Fix: 1.0.4.26+
Fix from $2,300 2020-02-24
Rpi CRITICAL 9.8
CVE-2019-10796

rpi through 0.0.3 allows execution of arbritary commands. The variable pinNumbver in function GPIO within src/lib/gpio.js is used as part of the argu…

Fix: after 0.0.3
Fix from $2,300 2020-02-24
Compile Sass HIGH 8.2
CVE-2019-10799

compile-sass prior to 1.0.5 allows execution of arbritary commands. The function "setupCleanupOnExit(cssPath)" within "dist/index.js" is executed as …

Fix: 1.0.5+
Fix from $1,950 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4210EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4211EPSS 71%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4213EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4222EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Fedora CRITICAL 9.8
CVE-2019-18182

pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsi…

Fix: 5.2+
Fix from $2,300 2020-02-24
Fedora CRITICAL 9.8
CVE-2019-18183

pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. This can be exploited when unsig…

Fix: 5.2+
Fix from $2,300 2020-02-24
Ubuntu Linux MEDIUM 6.4
CVE-2020-8130

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character …

Fix: 12.3.3+
Fix from $1,600 2020-02-24
Fedora HIGH 8.8
CVE-2020-8813EPSS 74%

graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has …

No fix yet
Fix from $1,950 2020-02-22
Dch M225 Firmware CRITICAL 9.8
CVE-2020-6841

D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the spotifyConnect.ph…

Fix: after 1.05b01
Fix from $2,300 2020-02-21
Dch M225 Firmware HIGH 7.2
CVE-2020-6842

D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the media …

Fix: after 1.05b01
Fix from $1,950 2020-02-21
Aterm Wg2600hs Firmware HIGH 8.8
CVE-2020-5524

Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier…

Fix: after 1.3.2
Fix from $1,950 2020-02-21
Aterm Wg2600hs Firmware HIGH 8.0
CVE-2020-5525

Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier…

Fix: after 1.3.2
Fix from $1,950 2020-02-21
Aterm Wg2600hs Firmware HIGH 8.0
CVE-2020-5534

Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root …

Fix: after 1.3.2
Fix from $1,950 2020-02-21
Mailmarshal CRITICAL 9.8
CVE-2014-2727

The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.

Fix: 7.2+
Fix from $2,300 2020-02-19
Promise Probe CRITICAL 9.8
CVE-2019-10791

promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and options functions can be controll…

Fix: 0.10.0+
Fix from $2,300 2020-02-18
Lpar2rrd CRITICAL 9.8
CVE-2014-4981EPSS 6%

LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization of the web GUI parameters.

Fix: after 3.50
Fix from $2,300 2020-02-17