Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Dmc Stro Firmware CRITICAL 9.8
CVE-2019-18184EPSS 8%

Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.

No fix yet
Fix from $2,300 2019-11-27
Centreon Web HIGH 8.8
CVE-2019-15298EPSS 27%

A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/tra…

Fix: 2.8.30 / 18.10.8+
Fix from $1,950 2019-11-27
Cingular Flip 2 Firmware MEDIUM 6.8
CVE-2019-16242

On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to OS command injection. An atta…

No fix yet
Fix from $1,600 2019-11-26
Askey Rtv1907vw Firmware CRITICAL 9.8
CVE-2019-12489EPSS 6%

An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP …

No fix yet
Fix from $2,300 2019-11-26
Dna Spaces\ MEDIUM 6.7
CVE-2019-15996

A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on t…

Fix: 2.1+
Fix from $1,600 2019-11-26
Dna Spaces\ MEDIUM 6.7
CVE-2019-15997

A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injection attack and execute arbitra…

Fix: 2.0+
Fix from $1,600 2019-11-26
Unity Express MEDIUM 6.7
CVE-2019-15986

A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro…

Fix: 10.1+
Fix from $1,600 2019-11-26
Thinpro HIGH 8.0
CVE-2019-18909

The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will exe…

No fix yet
Fix from $1,950 2019-11-22
Thinpro MEDIUM 6.8
CVE-2019-18910

The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will e…

No fix yet
Fix from $1,600 2019-11-22
Ac9v1.0 Firmware HIGH 7.8
CVE-2019-5071

An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gig…

No fix yet
Fix from $1,950 2019-11-21
Ac9v1.0 Firmware HIGH 7.8
CVE-2019-5072

An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gig…

No fix yet
Fix from $1,950 2019-11-21
Forticlient HIGH 7.8
CVE-2019-17650

An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local use…

Fix: after 6.2.1
Fix from $1,950 2019-11-21
Fedora HIGH 7.3
CVE-2019-18934

Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answe…

Fix: after 1.9.4
Fix from $1,950 2019-11-19
K2\(psg1218\) Firmware HIGH 8.8
CVE-2019-19117EPSS 5%

/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any comman…

No fix yet
Fix from $1,950 2019-11-18
Lpar2rrd HIGH 7.2
CVE-2019-19041

An issue was discovered in Xorux Lpar2RRD 6.11 and Stor2RRD 2.61, as distributed in Xorux 2.41. They do not correctly verify the integrity of an upgr…

Patch available
Fix from $1,950 2019-11-17
Gs1900 8 Firmware CRITICAL 9.8
CVE-2019-15800

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec()…

Fix: 2.50+
Fix from $2,300 2019-11-14
Tecno\/h622\/tecno Id5b\ HIGH 7.8
CVE-2019-15351

The Tecno Camon Android device with a build fingerprint of TECNO/H622/TECNO-ID5b:8.1.0/O11019/G-180829V31:user/release-keys contains a pre-installed …

Mitigation only
Fix from $1,950 2019-11-14
Camon Iair 2\+ Firmware HIGH 7.8
CVE-2019-15342

The Tecno Camon iAir 2 Plus Android device with a build fingerprint of TECNO/H622/TECNO-ID3k:8.1.0/O11019/E-180914V83:user/release-keys contains a pr…

Mitigation only
Fix from $1,950 2019-11-14
Camon Iclick Firmware HIGH 7.8
CVE-2019-15343

The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys contains a pre-inst…

Mitigation only
Fix from $1,950 2019-11-14
Camon Iclick 2 Firmware HIGH 7.8
CVE-2019-15347

The Tecno Camon iClick 2 Android device with a build fingerprint of TECNO/H622/TECNO-ID6:8.1.0/O11019/F-180824V116:user/release-keys contains a pre-i…

Mitigation only
Fix from $1,950 2019-11-14
Tecno\/h612\/tecno Id5a\ HIGH 7.8
CVE-2019-15348

The Tecno Camon Android device with a build fingerprint of TECNO/H612/TECNO-ID5a:8.1.0/O11019/F-180828V106:user/release-keys contains a pre-installed…

Mitigation only
Fix from $1,950 2019-11-14
Exhibitor CRITICAL 9.8
CVE-2019-5029EPSS 57%

An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands …

Fix: after 1.7.1
Fix from $2,300 2019-11-13
Fudforum CRITICAL 9.0
CVE-2019-18839EPSS 5%

FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to …

No fix yet
Fix from $2,300 2019-11-13
Fudforum CRITICAL 9.0
CVE-2019-18873EPSS 8%

FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user accou…

No fix yet
Fix from $2,300 2019-11-12
Magento HIGH 8.8
CVE-2019-8159

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with syste…

Fix: 2.2.10 / 2.3.2+
Fix from $1,950 2019-11-06
Nexus Repository Manager HIGH 7.2
CVE-2019-15588EPSS 6%

There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (…

Fix: after 2.14.14
Fix from $1,950 2019-11-01
Fortiextender Firmware HIGH 7.2
CVE-2019-15710

An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators …

Fix: after 4.1.1
Fix from $1,950 2019-10-31
Td5130v2 Firmware HIGH 7.2
CVE-2019-18396EPSS 16%

An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping mod…

No fix yet
Fix from $1,950 2019-10-31
Debian Linux HIGH 8.8
CVE-2013-2024

OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.

Fix: after 4.8.2
Fix from $1,950 2019-10-31
Debian Linux MEDIUM 6.8
CVE-2019-18424

An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has acce…

Fix: after 4.12.1
Fix from $1,600 2019-10-31