Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Tiny File Manager HIGH 8.8
CVE-2019-16790

In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.

Fix: 2.3.9+
Fix from $1,950 2019-12-30
Php Shellcommand CRITICAL 9.8
CVE-2019-10774

php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

Fix: 1.6.1+
Fix from $2,300 2019-12-30
Dir 859 Firmware CRITICAL 9.8
CVE-2019-17621 KEVEPSS 90%

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute syste…

Fix: after 3.12b04
Fix from $2,300 2019-12-30
Dba 1510p Firmware MEDIUM 6.6
CVE-2019-6013

DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line Interface (CLI).

Fix: after 1.70b009
Fix from $1,600 2019-12-26
Dba 1510p Firmware HIGH 8.8
CVE-2019-6014

DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User Interface.

Fix: after 1.70b009
Fix from $1,950 2019-12-26
Ubuntu Linux HIGH 8.8
CVE-2019-19920

sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (r…

Patch available
Fix from $1,950 2019-12-22
Treekill CRITICAL 9.8
CVE-2019-15598

A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.

Mitigation only
Fix from $2,300 2019-12-18
Mac Os X HIGH 7.8
CVE-2019-8513

This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to execute arbitrary shell comma…

Fix: 10.14.4+
Fix from $1,950 2019-12-18
Tew 651br Firmware CRITICAL 9.8
CVE-2019-11399

An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. OS command injection occurs through the get…

Mitigation only
Fix from $2,300 2019-12-18
Clickshare Cs 100 Firmware CRITICAL 9.8
CVE-2019-18830

Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the function…

Fix: 1.9.0+
Fix from $2,300 2019-12-16
Petalk Ai Firmware CRITICAL 9.8
CVE-2019-16730

processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary syst…

No fix yet
Fix from $2,300 2019-12-13
Petalk Ai Firmware CRITICAL 9.8
CVE-2019-16733

processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary syste…

No fix yet
Fix from $2,300 2019-12-13
Petalk Ai Firmware CRITICAL 9.8
CVE-2019-16737

The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute ar…

No fix yet
Fix from $2,300 2019-12-13
Petalk Ai Firmware CRITICAL 9.8
CVE-2019-17364

The processCommandUploadLog() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute…

No fix yet
Fix from $2,300 2019-12-13
Spamassassin MEDIUM 6.7
CVE-2018-11805

In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits ca…

Fix: 3.4.3+
Fix from $1,600 2019-12-12
Blink Xt2 Sync Module Firmware HIGH 8.8
CVE-2019-3985

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…

Fix: 2.13.11+
Fix from $1,950 2019-12-11
Blink Xt2 Sync Module Firmware HIGH 8.8
CVE-2019-3986

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…

Fix: 2.13.11+
Fix from $1,950 2019-12-11
Blink Xt2 Sync Module Firmware HIGH 8.8
CVE-2019-3987

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…

Fix: 2.13.11+
Fix from $1,950 2019-12-11
Blink Xt2 Sync Module Firmware HIGH 8.8
CVE-2019-3988

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…

Fix: 2.13.11+
Fix from $1,950 2019-12-11
Blink Xt2 Sync Module Firmware CRITICAL 9.8
CVE-2019-3989

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…

Fix: 2.13.11+
Fix from $2,300 2019-12-11
Openshift HIGH 8.8
CVE-2014-0163

Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.

Mitigation only
Fix from $1,950 2019-12-11
Spectrum Scale HIGH 8.8
CVE-2019-4715

IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafte…

Fix: after 5.0.4.0
Fix from $1,950 2019-12-11
Git HIGH 7.8
CVE-2019-19604

Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.2…

Fix: 2.20.0 / 2.21.1+
Fix from $1,950 2019-12-11
Ubuntu Linux HIGH 8.8
CVE-2019-14889

A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a serve…

Fix: 0.8.8 / 0.9.3+
Fix from $1,950 2019-12-10
Yachtcontrol CRITICAL 9.8
CVE-2019-17270EPSS 59%

Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?…

Fix: after 2019-10-06
Fix from $2,300 2019-12-10
X8sti F Bios HIGH 8.8
CVE-2019-19642EPSS 19%

On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated att…

No fix yet
Fix from $1,950 2019-12-08
Strapi HIGH 7.2
CVE-2019-19609EPSS 54%

The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel,…

Fix: after 1.6.4
Fix from $1,950 2019-12-05
Amanda HIGH 8.8
CVE-2019-19469

In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with s…

Mitigation only
Fix from $1,950 2019-12-01
Debian Linux CRITICAL 9.8
CVE-2011-2523EPSS 96%

vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

No fix yet
Fix from $2,300 2019-11-27
Solstice Firmware HIGH 8.8
CVE-2017-12945EPSS 17%

Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to execute …

Fix: 2.8.4+
Fix from $1,950 2019-11-27