Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Centreon Web HIGH 8.8
CVE-2019-17107

minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the command_hostaddress parameter. NOTE…

Fix: 2.8.27 / 18.10.4+
Fix from $1,950 2019-10-08
Mybuilder CRITICAL 9.8
CVE-2019-12811

ActiveX Control in MyBuilder before 6.2.2019.814 allow an attacker to execute arbitrary command via the ShellOpen method. This can be leveraged for c…

Fix: 6.2.2019.814+
Fix from $2,300 2019-10-07
Mybuilder CRITICAL 9.8
CVE-2019-12812

MyBuilder viewer before 6.2.2019.814 allow an attacker to execute arbitrary command via specifically crafted configuration file. This can be leverage…

Fix: 6.2.2019.814+
Fix from $2,300 2019-10-07
Sitos Six CRITICAL 9.8
CVE-2019-15746

SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute sy…

Mitigation only
Fix from $2,300 2019-10-07
Remote Access CRITICAL 9.8
CVE-2019-17269

Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Ping Test field.

Mitigation only
Fix from $2,300 2019-10-07
Teamcity HIGH 7.2
CVE-2019-15036

An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue w…

Mitigation only
Fix from $1,950 2019-10-02
Secure Firewall Management Center HIGH 7.2
CVE-2019-12690

A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to inject arbitrary comman…

Fix: 6.3.0.5 / 6.4.0.4+
Fix from $1,950 2019-10-02
Firepower 9300 Firmware HIGH 7.8
CVE-2019-12699

Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local atta…

Fix: 2.2.2.101 / 2.3.1.155+
Fix from $1,950 2019-10-02
Ch7465lg Firmware CRITICAL 9.8
CVE-2019-13025

Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation. The attacker can send a…

No fix yet
Fix from $2,300 2019-10-02
Dir 655 Firmware CRITICAL 9.8
CVE-2019-16920 KEVEPSS 100%

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker…

Fix: after 3.02b05
Fix from $2,300 2019-09-27
Netskope HIGH 7.8
CVE-2019-12091

The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts network connections from loca…

Fix: 57.2.0.219 / 60.2.0.214+
Fix from $1,950 2019-09-26
Ios Xe MEDIUM 6.7
CVE-2019-12661

A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execu…

Mitigation only
Fix from $1,600 2019-09-25
Ios Xr MEDIUM 6.7
CVE-2019-12709

A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services…

Fix: 6.5.3 / 6.6.2+
Fix from $1,600 2019-09-25
Nx Os HIGH 7.8
CVE-2019-12717

A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco NX-OS Software could allow an authenticated, local attacker to…

Fix: 7.0 / 7.3+
Fix from $1,950 2019-09-25
iOS HIGH 8.8
CVE-2019-12650EPSS 29%

Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute c…

Mitigation only
Fix from $1,950 2019-09-25
iOS HIGH 8.8
CVE-2019-12651

Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute c…

Mitigation only
Fix from $1,950 2019-09-25
Pfsense HIGH 8.8
CVE-2019-16701EPSS 20%

pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metac…

Fix: 2.4.4+
Fix from $1,950 2019-09-25
Radare2 HIGH 7.8
CVE-2019-16718

In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's poss…

Fix: 3.9.0+
Fix from $1,950 2019-09-23
Bitbucket CRITICAL 9.8
CVE-2019-15000EPSS 8%

The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed…

Fix: 5.16.10 / 6.0.10+
Fix from $2,300 2019-09-19
Dns 320 Firmware CRITICAL 9.8
CVE-2019-16057 KEVEPSS 87%

The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

Fix: after 2.05.b10
Fix from $2,300 2019-09-16
Gitlabhook CRITICAL 10.0
CVE-2019-5485EPSS 60%

NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository n…

Mitigation only
Fix from $2,300 2019-09-13
Open Audit HIGH 8.8
CVE-2019-16293

The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a…

Fix: 3.2.0+
Fix from $1,950 2019-09-13
Arubaos HIGH 7.2
CVE-2019-5315

A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary comma…

Fix: 8.3.0.0+
Fix from $1,950 2019-09-13
Git Client HIGH 8.8
CVE-2019-10392EPSS 26%

Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote',…

Fix: after 2.8.4
Fix from $1,950 2019-09-12
Librenms HIGH 7.2
CVE-2019-10669EPSS 81%

An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where us…

Fix: after 1.47
Fix from $1,950 2019-09-09
Dir 806 Firmware CRITICAL 9.8
CVE-2019-10891EPSS 19%

An issue was discovered in D-Link DIR-806 devices. There is a command injection in function hnap_main, which calls system() without checking the para…

No fix yet
Fix from $2,300 2019-09-06
Fusionpbx HIGH 8.8
CVE-2019-15029EPSS 12%

FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will in…

No fix yet
Fix from $1,950 2019-09-05
Nagios Xi HIGH 8.8
CVE-2019-15949 KEVEPSS 77%

Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin …

Fix: 5.6.6+
Fix from $1,950 2019-09-05
Nexus Repository Manager HIGH 8.8
CVE-2019-5475EPSS 18%

The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable da…

Fix: after 2.14.9-01
Fix from $1,950 2019-09-03
Snare Central HIGH 7.2
CVE-2019-11364

An OS Command Injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to inject arbitrary OS commands via the Ser…

Fix: 7.4.5+
Fix from $1,950 2019-08-29