Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Netweaver Process Integration HIGH 7.2
CVE-2019-0328

ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS c…

Mitigation only
Fix from $1,950 2019-07-10
Dir 818lw Firmware HIGH 8.8
CVE-2019-13481EPSS 8%

An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication…

No fix yet
Fix from $1,950 2019-07-10
Dir 818lw Firmware HIGH 8.8
CVE-2019-13482EPSS 8%

An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication…

No fix yet
Fix from $1,950 2019-07-10
Tew 827dru Firmware CRITICAL 9.8
CVE-2019-13278EPSS 9%

TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, a…

Fix: after 2.04b03
Fix from $2,300 2019-07-10
Fd8136 Firmware CRITICAL 9.8
CVE-2018-14495

Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE…

No fix yet
Fix from $2,300 2019-07-10
Fd8136 Firmware CRITICAL 9.8
CVE-2018-14494

Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining th…

Mitigation only
Fix from $2,300 2019-07-10
Fcm Mb40 Firmware HIGH 7.2
CVE-2019-13398

Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CGI script, as demonstrated by …

No fix yet
Fix from $1,950 2019-07-08
Enterprise Nfv Infrastructure Software HIGH 7.8
CVE-2019-1893

A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on…

Mitigation only
Fix from $1,950 2019-07-06
Odoo CRITICAL 9.1
CVE-2018-14860

Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privil…

Fix: after 11.0
Fix from $2,300 2019-07-03
Data Science Workbench CRITICAL 9.8
CVE-2018-11215

Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors.

Fix: after 1.3.0
Fix from $2,300 2019-07-03
Big Ip Access Policy Manager HIGH 7.2
CVE-2019-6620

On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4 and BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, an undisclose…

Fix: 13.1.1.5 / 14.1.0.6+
Fix from $1,950 2019-07-02
Big Ip Access Policy Manager HIGH 7.2
CVE-2019-6621

On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, 11.6.1-11.6.3.4, and 11.5.2-11.5.8 and BIG-IQ 7.0.0-7.1.0.2, 6.0.0-6.1.…

Fix: 11.5.8 / 11.5.9+
Fix from $1,950 2019-07-02
Linear Emerge Essential Firmware CRITICAL 9.8
CVE-2019-7256 KEVEPSS 97%

Linear eMerge E3-Series devices allow Command Injections.

Fix: after 1.00-06
Fix from $2,300 2019-07-02
Linear Emerge 50p Firmware CRITICAL 9.8
CVE-2019-7269EPSS 40%

Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.

Fix: after 4.6.07
Fix from $2,300 2019-07-02
Tew 827dru Firmware HIGH 8.8
CVE-2019-13149

An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v…

Fix: 2.05b11+
Fix from $1,950 2019-07-02
Tew 827dru Firmware HIGH 8.8
CVE-2019-13151

An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v…

Fix: 2.05b11+
Fix from $1,950 2019-07-02
Tew 827dru Firmware HIGH 8.8
CVE-2019-13153

An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v…

Fix: 2.05b11+
Fix from $1,950 2019-07-02
Tew 827dru Firmware HIGH 8.8
CVE-2019-13154

An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v…

Fix: 2.05b11+
Fix from $1,950 2019-07-02
Tew 827dru Firmware HIGH 8.8
CVE-2019-13155

An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v…

Fix: 2.05b11+
Fix from $1,950 2019-07-02
Flexair HIGH 7.2
CVE-2019-7670EPSS 18%

Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could modify the intended OS command …

Fix: after 2.3.38
Fix from $1,950 2019-07-01
Dir 823g Firmware HIGH 8.8
CVE-2019-13128EPSS 8%

An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via…

No fix yet
Fix from $1,950 2019-07-01
Calendar CRITICAL 9.8
CVE-2019-11829

OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrar…

Fix: 2.3.1-0617+
Fix from $2,300 2019-06-30
Loopchain HIGH 8.8
CVE-2019-12997

In Loopchain through 2.2.1.3, an attacker can escalate privileges from a low-privilege shell by changing the environment (aka injection in the DEFAUL…

Fix: after 2.2.1.3
Fix from $1,950 2019-06-28
Enterprise Security Manager HIGH 7.2
CVE-2019-3630

Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute …

Fix: 10.4.0 / 11.2.0+
Fix from $1,950 2019-06-27
Enterprise Security Manager HIGH 7.2
CVE-2019-3631

Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute …

Fix: 10.4.0 / 11.2.0+
Fix from $1,950 2019-06-27
Chrome HIGH 7.8
CVE-2019-5819

Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code vi…

Fix: 74.0.3729.108+
Fix from $1,950 2019-06-27
Qemu CRITICAL 9.8
CVE-2019-12928EPSS 23%

The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code exe…

Fix: after 4.0.0
Fix from $2,300 2019-06-24
Qemu CRITICAL 9.8
CVE-2019-12929

The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achieve code execution, denial of…

Fix: after 4.0.0
Fix from $2,300 2019-06-24
Sfos HIGH 8.8
CVE-2018-16117EPSS 44%

A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to exec…

Fix: after 17.0
Fix from $1,950 2019-06-20
Sfos HIGH 8.1
CVE-2018-16118

A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attacker…

Fix: after 16.0
Fix from $1,950 2019-06-20