Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Tl Sc 3130g Firmware CRITICAL 9.8
CVE-2013-2573EPSS 42%

A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G,…

Fix: after 1.6.18p12
Fix from $2,300 2020-01-29
F3105 Firmware CRITICAL 9.8
CVE-2013-2568EPSS 49%

A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a r…

Fix: after 1.6.03
Fix from $2,300 2020-01-29
F3105 Firmware CRITICAL 9.8
CVE-2013-2570EPSS 27%

A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the b…

Fix: after 1.6.03
Fix from $2,300 2020-01-29
Debian Linux CRITICAL 9.8
CVE-2020-7247 KEVEPSS 99%

smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as…

Patch available
Fix from $2,300 2020-01-29
Dir 859 Firmware CRITICAL 9.8
CVE-2019-20215EPSS 75%

D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi()…

Patch available
Fix from $2,300 2020-01-29
Dir 859 Firmware CRITICAL 9.8
CVE-2019-20216

D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi…

Patch available
Fix from $2,300 2020-01-29
Dir 859 Firmware CRITICAL 9.8
CVE-2019-20217

D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi…

Patch available
Fix from $2,300 2020-01-29
Dcs 3411 Firmware CRITICAL 9.8
CVE-2013-1599EPSS 40%

A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01…

No fix yet
Fix from $2,300 2020-01-28
Hdx Video End Points HIGH 8.8
CVE-2012-6610EPSS 11%

Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated b…

Fix: 2.7.1.j / 3.0.4+
Fix from $1,950 2020-01-28
Openshift CRITICAL 9.8
CVE-2013-2060EPSS 6%

The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a req…

No fix yet
Fix from $2,300 2020-01-28
E587 Firmware CRITICAL 9.8
CVE-2013-2612

Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with root priv…

Mitigation only
Fix from $2,300 2020-01-27
Zimbra Collaboration Server CRITICAL 9.8
CVE-2014-8563

Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.

Fix: 8.0.9+
Fix from $2,300 2020-01-27
Box 2 Firmware CRITICAL 9.8
CVE-2019-17095

A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `…

No fix yet
Fix from $2,300 2020-01-27
A3002ru Firmware HIGH 8.8
CVE-2019-19824EPSS 25%

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/for…

Fix: after 4.0.0
Fix from $1,950 2020-01-27
Box 2 Firmware CRITICAL 9.8
CVE-2019-17096

A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_image_url()` function in special…

Fix: 2.0.66 / 2.0.66.88+
Fix from $2,300 2020-01-27
Sd Wan Firmware HIGH 7.2
CVE-2019-12629

A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with…

Fix: 18.3.0+
Fix from $1,950 2020-01-26
Nodejs Uploader HIGH 8.8
CVE-2020-7596

Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.

Fix: 3.6.2+
Fix from $1,950 2020-01-25
Aptus Web CRITICAL 9.8
CVE-2020-7980EPSS 83%

Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. N…

No fix yet
Fix from $2,300 2020-01-25
Pt7135 Firmware HIGH 8.8
CVE-2013-1598EPSS 20%

A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, wh…

No fix yet
Fix from $1,950 2020-01-24
Easyinstall CRITICAL 9.8
CVE-2019-19897EPSS 6%

In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can communicate with the Agent Servic…

No fix yet
Fix from $2,300 2020-01-23
Unleashed CRITICAL 9.8
CVE-2019-19838EPSS 24%

emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=g…

Fix: 9.10.2.0.84 / 9.12.3.0.136+
Fix from $2,300 2020-01-23
Unleashed CRITICAL 9.8
CVE-2019-19839

emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=i…

Fix: 9.10.2.0.84 / 9.12.3.0.136+
Fix from $2,300 2020-01-23
Configfree HIGH 8.8
CVE-2012-4981

Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability

No fix yet
Fix from $1,950 2020-01-23
Unleashed CRITICAL 9.8
CVE-2019-19841

emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=p…

Fix: 9.10.2.0.84 / 9.12.3.0.136+
Fix from $2,300 2020-01-22
Unleashed CRITICAL 9.8
CVE-2019-19842

emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=s…

Fix: 9.10.2.0.84 / 9.12.3.0.136+
Fix from $2,300 2020-01-22
Bibtex Ruby CRITICAL 9.8
CVE-2019-10780

BibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built-in Ruby Kernel.open method t…

Fix: 5.1.0+
Fix from $2,300 2020-01-22
Conduit Mtcdt Lvw2 246a Firmware HIGH 7.2
CVE-2020-7594

MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating …

No fix yet
Fix from $1,950 2020-01-21
Stampede Fx 1010 Firmware HIGH 7.2
CVE-2020-7242

Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Diagnostics Tr…

No fix yet
Fix from $1,950 2020-01-20
Stampede Fx 1010 Firmware HIGH 7.2
CVE-2020-7243

Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Fetch URL page…

No fix yet
Fix from $1,950 2020-01-20
Stampede Fx 1010 Firmware HIGH 7.2
CVE-2020-7244

Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Poll Routes pa…

No fix yet
Fix from $1,950 2020-01-20