Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Enterprise Network Function Virtualization Infrastructure CRITICAL 9.8
CVE-2019-1971

A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform …

Fix: after 3.8.1
Fix from $2,300 2019-08-08
Debian Linux HIGH 7.8
CVE-2019-14744

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This r…

Fix: 5.61.0+
Fix from $1,950 2019-08-07
Mdc N4090 Firmware CRITICAL 9.8
CVE-2019-14699EPSS 6%

An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can exploit OS Command Injection in the filena…

Fix: after 6400.0.8.5
Fix from $2,300 2019-08-06
8008 Firmware HIGH 8.0
CVE-2019-14260

On the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injection (missing input validation) …

No fix yet
Fix from $1,950 2019-08-01
Obihai Obi1022 Firmware HIGH 8.0
CVE-2019-14259

On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address fiel…

No fix yet
Fix from $1,950 2019-08-01
6600 Ap Firmware MEDIUM 5.5
CVE-2019-14337

An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is an ability to escape to a shell in the restricted c…

No fix yet
Fix from $1,600 2019-08-01
Tridactyl HIGH 7.5
CVE-2019-1020004

Tridactyl before 1.16.0 allows fake key events.

Fix: after 1.14.10
Fix from $1,950 2019-07-29
Debian Linux HIGH 7.8
CVE-2019-13638

GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style d…

Patch available
Fix from $1,950 2019-07-26
Data Loss Prevention Endpoint MEDIUM 6.5
CVE-2019-3595

Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior …

Fix: 11.1.200 / 11.3.0+
Fix from $1,600 2019-07-24
Phkp CRITICAL 9.8
CVE-2019-1010179

PHKP including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b is affected by: Improper Neutralization of Special Elements used in a Command ('Comman…

Mitigation only
Fix from $2,300 2019-07-24
Voice Builder CRITICAL 9.8
CVE-2019-1010200

Voice Builder Prior to commit c145d4604df67e6fc625992412eef0bf9a85e26b and f6660e6d8f0d1d931359d591dbdec580fef36d36 is affected by: CWE-78: Improper …

Patch available
Fix from $2,300 2019-07-23
A10w Firmware HIGH 8.8
CVE-2019-12328

A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP phone with…

No fix yet
Fix from $1,950 2019-07-22
Sp R50p Firmware HIGH 7.2
CVE-2019-12324

A command injection (missing input validation) issue in the IP address field for the logging server in the configuration web interface on the Akuvox …

No fix yet
Fix from $1,950 2019-07-22
Zeroshell CRITICAL 9.8
CVE-2019-12725EPSS 90%

Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HT…

No fix yet
Fix from $2,300 2019-07-19
Open Network Operating System CRITICAL 9.8
CVE-2019-1010245

The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can ex…

Fix: after 1.15
Fix from $2,300 2019-07-19
Qbittorrent CRITICAL 9.8
CVE-2019-13640EPSS 8%

In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacha…

Fix: 4.1.7+
Fix from $2,300 2019-07-17
Netscaler Sd Wan HIGH 8.8
CVE-2019-12991 KEVEPSS 74%

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

Fix: 10.0.8 / 10.2.3+
Fix from $1,950 2019-07-16
Netscaler Sd Wan HIGH 8.8
CVE-2019-12992EPSS 49%

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).

Fix: 10.0.8 / 10.2.3+
Fix from $1,950 2019-07-16
Netscaler Sd Wan CRITICAL 9.8
CVE-2019-12985EPSS 40%

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).

Fix: 10.0.8 / 10.2.3+
Fix from $2,300 2019-07-16
Netscaler Sd Wan CRITICAL 9.8
CVE-2019-12986EPSS 40%

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).

Fix: 10.0.8 / 10.2.3+
Fix from $2,300 2019-07-16
Netscaler Sd Wan CRITICAL 9.8
CVE-2019-12987EPSS 43%

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).

Fix: 10.0.8 / 10.2.3+
Fix from $2,300 2019-07-16
Netscaler Sd Wan CRITICAL 9.8
CVE-2019-12988EPSS 43%

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).

Fix: 10.0.8 / 10.2.3+
Fix from $2,300 2019-07-16
Pan Os HIGH 8.8
CVE-2019-1576

Command injection in PAN-0S 9.0.2 and earlier may allow an authenticated attacker to gain access to a remote shell in PAN-OS, and potentially run wit…

Fix: after 9.0.2
Fix from $1,950 2019-07-16
Sahi Pro CRITICAL 9.8
CVE-2019-13597EPSS 14%

_s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one ca…

No fix yet
Fix from $2,300 2019-07-14
Vera Edge Firmware CRITICAL 9.8
CVE-2019-13598

LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_34…

No fix yet
Fix from $2,300 2019-07-14
Zoom HIGH 8.8
CVE-2019-13567

The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon …

Fix: 4.4.53932.0709+
Fix from $1,950 2019-07-12
Debian Linux HIGH 7.8
CVE-2019-13574EPSS 8%

In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input…

Fix: 4.9.4+
Fix from $1,950 2019-07-12
Private Internet Access Vpn Client HIGH 7.8
CVE-2019-12579

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attack…

No fix yet
Fix from $1,950 2019-07-11
Wmpro CRITICAL 9.8
CVE-2019-11062EPSS 6%

The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be explo…

No fix yet
Fix from $2,300 2019-07-11
Dir 655 Firmware CRITICAL 9.8
CVE-2019-13561EPSS 8%

D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_c…

No fix yet
Fix from $2,300 2019-07-11