Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Bloodhound HIGH 8.8
CVE-2019-15701

components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the curr…

No fix yet
Fix from $1,950 2019-08-27
Prontuscms CRITICAL 9.8
CVE-2019-15503

cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization of Special Elements used in an…

Fix: after 12.0.3.0
Fix from $2,300 2019-08-26
Pan Os CRITICAL 9.8
CVE-2019-1581

A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access…

Fix: after 9.0.3
Fix from $2,300 2019-08-23
Dir 823g Firmware HIGH 8.8
CVE-2019-15526

An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v…

No fix yet
Fix from $1,950 2019-08-23
Dir 823g Firmware HIGH 8.8
CVE-2019-15527

An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v…

No fix yet
Fix from $1,950 2019-08-23
Dir 823g Firmware HIGH 8.8
CVE-2019-15528

An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v…

No fix yet
Fix from $1,950 2019-08-23
Dir 823g Firmware HIGH 8.8
CVE-2019-15529EPSS 8%

An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v…

No fix yet
Fix from $1,950 2019-08-23
Dir 823g Firmware HIGH 8.8
CVE-2019-15530

An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v…

No fix yet
Fix from $1,950 2019-08-23
Openitcockpit CRITICAL 9.8
CVE-2019-15490

openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.

Fix: 3.7.1+
Fix from $2,300 2019-08-23
Docker HIGH 8.4
CVE-2019-13139

In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain…

Fix: 18.09.4+
Fix from $1,950 2019-08-22
Tl Wr840n Firmware HIGH 8.8
CVE-2019-15060

The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payl…

Fix: after 0.9.1_3.16
Fix from $1,950 2019-08-22
Unified Computing System HIGH 7.2
CVE-2019-1896

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker t…

Fix: 2.0 / 3.0+
Fix from $1,950 2019-08-21
Unified Computing System HIGH 7.2
CVE-2019-1634

A vulnerability in the Intelligent Platform Management Interface (IPMI) of Cisco Integrated Management Controller (IMC) could allow an authenticated,…

Fix: 1.5 / 2.0+
Fix from $1,950 2019-08-21
Remote Phy 120 Firmware MEDIUM 6.7
CVE-2019-1839

A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of…

Fix: 1.2 / 3.1+
Fix from $1,600 2019-08-21
Unified Computing System HIGH 7.2
CVE-2019-1850

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote a…

Fix: 3.0 / 4.0+
Fix from $1,950 2019-08-21
Unified Computing System HIGH 8.8
CVE-2019-1864

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote a…

Fix: 1.5 / 2.0+
Fix from $1,950 2019-08-21
Unified Computing System HIGH 8.8
CVE-2019-1865

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote a…

Fix: 1.5 / 2.0+
Fix from $1,950 2019-08-21
Unified Computing System HIGH 7.8
CVE-2019-1883

A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-…

Fix: 3.0 / 4.0+
Fix from $1,950 2019-08-21
Unified Computing System HIGH 7.2
CVE-2019-1885

A vulnerability in the Redfish protocol of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject and e…

Fix: 3.0 / 4.0+
Fix from $1,950 2019-08-21
Openemr HIGH 8.8
CVE-2019-3968EPSS 10%

In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creati…

Fix: after 5.0.1
Fix from $1,950 2019-08-20
Datapower Gateway HIGH 7.8
CVE-2019-4294

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2,…

Fix: 2018.4.1.7+
Fix from $1,950 2019-08-20
Ubuntu Linux CRITICAL 9.8
CVE-2019-5477EPSS 6%

A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Pro…

Fix: after 1.10.3
Fix from $2,300 2019-08-16
Eyesofnetwork HIGH 8.8
CVE-2019-14923

EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field.

No fix yet
Fix from $1,950 2019-08-16
Patch HIGH 7.8
CVE-2018-20969

do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-1…

Fix: after 2.7.6
Fix from $1,950 2019-08-16
Webmin CRITICAL 9.8
CVE-2019-15107 KEVEPSS 100%

An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

Fix: after 1.920
Fix from $2,300 2019-08-16
Control Panel HIGH 8.8
CVE-2019-12792

A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered us…

No fix yet
Fix from $1,950 2019-08-15
Zxhn F670 Firmware HIGH 8.8
CVE-2019-3417

All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability. Due to insufficient parameter validation ch…

Fix: after 1.1.10p3t18
Fix from $1,950 2019-08-15
M7350 Firmware CRITICAL 9.8
CVE-2019-12103

The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by a pre-authentication command injection vulne…

Fix: 190531+
Fix from $2,300 2019-08-14
Mr1100 Firmware CRITICAL 9.8
CVE-2019-14527

An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. System commands can be executed, via the web interface, after authe…

Fix: 12.06.03+
Fix from $2,300 2019-08-14
Mt8163 Firmware CRITICAL 9.8
CVE-2019-15027

The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary co…

No fix yet
Fix from $2,300 2019-08-14