Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Lantime M300 Firmware HIGH 8.8
CVE-2020-7240

Meinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS commands by editing the /conf…

No fix yet
Fix from $1,950 2020-01-20
Cacti HIGH 8.8
CVE-2020-7237EPSS 37%

Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation…

No fix yet
Fix from $1,950 2020-01-20
G Code Eec 2400 Firmware HIGH 7.2
CVE-2019-10956

Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticat…

Fix: after 1.12.0.25
Fix from $1,950 2020-01-17
G Code Eec 2400 Firmware HIGH 7.2
CVE-2019-10958

Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticat…

Fix: after 1.12.0.25
Fix from $1,950 2020-01-17
Junos HIGH 8.8
CVE-2020-1602

When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured…

Mitigation only
Fix from $1,950 2020-01-15
Junos HIGH 8.8
CVE-2020-1605

When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured…

Mitigation only
Fix from $1,950 2020-01-15
Junos HIGH 8.8
CVE-2020-1609

When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured…

Mitigation only
Fix from $1,950 2020-01-15
Freelancy CRITICAL 9.8
CVE-2020-5505EPSS 44%

Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-p…

No fix yet
Fix from $2,300 2020-01-14
Hashbrown Cms CRITICAL 9.8
CVE-2020-6948

A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call…

Fix: after 1.3.3
Fix from $2,300 2020-01-13
Premium Security HIGH 7.8
CVE-2019-18894

In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast Antivirus on port 27275 to s…

No fix yet
Fix from $1,950 2020-01-13
Pixelstor 5000 Firmware CRITICAL 9.8
CVE-2020-6756EPSS 11%

languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the l…

No fix yet
Fix from $2,300 2020-01-09
Pixelstor 5000 Firmware HIGH 8.8
CVE-2020-6757

contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute code via t…

No fix yet
Fix from $1,950 2020-01-09
Pandora Fms HIGH 8.8
CVE-2019-20224EPSS 50%

netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metachar…

No fix yet
Fix from $1,950 2020-01-09
Openstage 80 Firmware CRITICAL 9.8
CVE-2014-2650

Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface

Mitigation only
Fix from $2,300 2020-01-09
Aws Lambda CRITICAL 9.8
CVE-2019-10777

In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any…

Fix: 1.0.5+
Fix from $2,300 2020-01-08
Devcert Sanscache CRITICAL 9.8
CVE-2019-10778

devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `co…

Fix: 0.4.7+
Fix from $2,300 2020-01-08
Parallels Desktop HIGH 7.8
CVE-2019-17148

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (454…

Mitigation only
Fix from $1,950 2020-01-07
Git Diff Apply CRITICAL 9.8
CVE-2019-10776

In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply a…

Fix: 0.22.2+
Fix from $2,300 2020-01-07
G232v1 Firmware MEDIUM 6.8
CVE-2019-20348

OKER G232V1 v1.03.02.20161129 devices provide a root terminal on a UART serial interface without proper access control. This allows attackers with ph…

No fix yet
Fix from $1,600 2020-01-06
Rconfig HIGH 8.8
CVE-2019-19509EPSS 72%

An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFil…

No fix yet
Fix from $1,950 2020-01-06
Network Monitor CRITICAL 9.8
CVE-2016-11017

The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via …

Fix: after 16.5
Fix from $2,300 2020-01-06
Data Center Network Manager HIGH 7.2
CVE-2019-15979

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker…

Fix: 11.3+
Fix from $1,950 2020-01-06
Data Center Network Manager HIGH 7.2
CVE-2019-15978EPSS 37%

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker…

Fix: 11.3+
Fix from $1,950 2020-01-06
Cgi An Anlyzer HIGH 8.8
CVE-2019-5987

Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the M…

Fix: after 2019-06-24
Fix from $1,950 2020-01-06
Smartphone Pentest Framework CRITICAL 9.8
CVE-2012-5878EPSS 9%

Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters i…

Fix: after 0.1.4
Fix from $2,300 2020-01-03
Smartphone Pentest Framework HIGH 8.8
CVE-2012-5693

Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the i…

Fix: 0.1.3+
Fix from $1,950 2020-01-03
Stampede Fx 1010 Firmware HIGH 7.2
CVE-2020-5179

Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Diagnostics Pi…

No fix yet
Fix from $1,950 2020-01-02
Nagios Xi HIGH 8.8
CVE-2019-20197EPSS 22%

In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php…

No fix yet
Fix from $1,950 2019-12-31
Blink Xt2 Sync Module Firmware CRITICAL 9.8
CVE-2019-3984

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…

Fix: 2.3.11+
Fix from $2,300 2019-12-31
Unity Editor HIGH 8.8
CVE-2019-9197

The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.

Fix: 5.6.7f1 / 2017.4.22f1+
Fix from $1,950 2019-12-31