Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Smartrtu Firmware CRITICAL 9.8
CVE-2019-14931EPSS 58%

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote…

Fix: after 3.0
Fix from $2,300 2019-10-28
Rconfig CRITICAL 9.8
CVE-2019-16662EPSS 98%

An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php beca…

No fix yet
Fix from $2,300 2019-10-28
Rconfig HIGH 8.8
CVE-2019-16663EPSS 85%

An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the ca…

No fix yet
Fix from $1,950 2019-10-28
Youphptube Encoder CRITICAL 9.8
CVE-2019-5127EPSS 45%

A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthen…

No fix yet
Fix from $2,300 2019-10-25
Youphptube Encoder CRITICAL 9.8
CVE-2019-5128EPSS 30%

A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthen…

No fix yet
Fix from $2,300 2019-10-25
Youphptube Encoder CRITICAL 9.8
CVE-2019-5129EPSS 39%

A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthen…

No fix yet
Fix from $2,300 2019-10-25
M7350 Firmware CRITICAL 9.8
CVE-2019-13649

TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5).

Fix: after 1.0.16
Fix from $2,300 2019-10-24
M7350 Firmware CRITICAL 9.8
CVE-2019-13650

TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow internalPort OS Command Injection (issue 2 of 5).

Fix: after 1.0.16
Fix from $2,300 2019-10-24
M7350 Firmware CRITICAL 9.8
CVE-2019-13651

TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow portMappingProtocol OS Command Injection (issue 3 of 5).

Fix: after 1.0.16
Fix from $2,300 2019-10-24
M7350 Firmware CRITICAL 9.8
CVE-2019-13652

TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow serviceName OS Command Injection (issue 4 of 5).

Fix: after 1.0.16
Fix from $2,300 2019-10-24
M7350 Firmware CRITICAL 9.8
CVE-2019-13653

TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow triggerPort OS Command Injection (issue 5 of 5).

Fix: after 1.0.16
Fix from $2,300 2019-10-24
Millet Router 3g Firmware CRITICAL 9.8
CVE-2019-18370EPSS 40%

An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application us…

Fix: 2.28.23+
Fix from $2,300 2019-10-23
Fusionpbx HIGH 8.8
CVE-2019-16964

app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of inp…

Fix: after 4.5.7
Fix from $1,950 2019-10-21
Fusionpbx HIGH 7.2
CVE-2019-16965

resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticat…

Fix: after 4.5.7
Fix from $1,950 2019-10-21
Sagemathcell CRITICAL 9.8
CVE-2019-17526

An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web app…

Patch available
Fix from $2,300 2019-10-18
Cux Daemon HIGH 8.8
CVE-2019-14423EPSS 20%

A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated…

Fix: after 2.45.6
Fix from $1,950 2019-10-17
Telepresence Collaboration Endpoint MEDIUM 6.7
CVE-2019-15277

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to execute code wi…

Fix: 9.8.0+
Fix from $1,600 2019-10-16
Telepresence Collaboration Endpoint MEDIUM 6.7
CVE-2019-15274

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to perform command…

Fix: 9.8.1+
Fix from $1,600 2019-10-16
Telepresence Collaboration Endpoint MEDIUM 6.7
CVE-2019-15275

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to execute arbitra…

Fix: 9.8.1+
Fix from $1,600 2019-10-16
Rambox CRITICAL 9.0
CVE-2019-17625

There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occur…

No fix yet
Fix from $2,300 2019-10-16
Centreon HIGH 8.8
CVE-2019-17501

Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (aka the Configuration > Comma…

No fix yet
Fix from $1,950 2019-10-14
Dir 859 A3 Firmware CRITICAL 9.8
CVE-2019-17508EPSS 16%

On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable.

No fix yet
Fix from $2,300 2019-10-11
Dir 846 Firmware CRITICAL 9.8
CVE-2019-17509

D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a …

No fix yet
Fix from $2,300 2019-10-11
Dir 846 Firmware CRITICAL 9.8
CVE-2019-17510

D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a …

No fix yet
Fix from $2,300 2019-10-11
Cyberoamos CRITICAL 9.8
CVE-2019-17059EPSS 7%

A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbit…

Fix: 10.6.6+
Fix from $2,300 2019-10-11
Ch7465lg Firmware HIGH 8.8
CVE-2019-17499

The setter.xml component of the Common Gateway Interface on Compal CH7465LG 6.12.18.25-2p4 devices does not properly validate ping command arguments,…

No fix yet
Fix from $1,950 2019-10-11
Uagate Si Firmware HIGH 8.8
CVE-2019-11527

An issue was discovered in Softing uaGate SI 1.60.01. A CGI script is vulnerable to command injection with a maliciously crafted url parameter.

No fix yet
Fix from $1,950 2019-10-10
Inspector HIGH 8.8
CVE-2019-15014

A command injection vulnerability exists in the Zingbox Inspector versions 1.286 and earlier, that allows for an authenticated user to execute arbitr…

Fix: after 1.286
Fix from $1,950 2019-10-09
Mantisbt HIGH 7.2
CVE-2019-15715EPSS 30%

MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.

Fix: 1.3.20 / 2.22.1+
Fix from $1,950 2019-10-09
Pi Hole HIGH 8.8
CVE-2019-13051EPSS 12%

Pi-Hole 4.3 allows Command Injection.

Patch available
Fix from $1,950 2019-10-09