Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Rdkb Ccsppandm HIGH 7.5
CVE-2019-6962

A shell injection issue in cosa_wifi_apis.c in the RDK RDKB-20181217-1 CcspWifiAgent module allows attackers with login credentials to execute arbitr…

Mitigation only
Fix from $1,950 2019-06-20
Telepresence Ce HIGH 8.8
CVE-2019-1878

A vulnerability in the Cisco Discovery Protocol (CDP) implementation for the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software c…

Fix: 7.3.17 / 8.3.7+
Fix from $1,950 2019-06-20
Unified Computing System MEDIUM 6.7
CVE-2019-1879

A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to inject arbitrary commands …

Mitigation only
Fix from $1,600 2019-06-20
Meeting Server MEDIUM 6.7
CVE-2019-1623

A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as t…

Fix: 2.2.14 / 2.3.8+
Fix from $1,600 2019-06-20
Integrated Management Controller MEDIUM 6.5
CVE-2019-1627

A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unautho…

Mitigation only
Fix from $1,600 2019-06-20
R5c Firmware HIGH 8.8
CVE-2018-16593

The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.

Fix: 8.216 / 8.464+
Fix from $1,950 2019-06-19
Storio Max Firmware CRITICAL 9.8
CVE-2018-16618EPSS 8%

VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttran…

Fix: 56.d3jm6+
Fix from $2,300 2019-06-19
My Book Live Firmware CRITICAL 9.8
CVE-2018-18472EPSS 30%

Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/…

Mitigation only
Fix from $2,300 2019-06-19
Dt 300n Firmware HIGH 8.8
CVE-2018-18852EPSS 64%

Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of…

Fix: after 1.1.12
Fix from $1,950 2019-06-18
Fusionpbx HIGH 8.8
CVE-2019-11409EPSS 87%

app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input val…

Patch available
Fix from $1,950 2019-06-17
Fusionpbx HIGH 7.2
CVE-2019-11410

app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which …

Patch available
Fix from $1,950 2019-06-17
Serv U Ftp Server HIGH 8.8
CVE-2019-12181EPSS 66%

A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.

Fix: 15.1.7+
Fix from $1,950 2019-06-17
Orangehrm HIGH 8.8
CVE-2019-12839

In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenti…

Fix: after 4.3.1
Fix from $1,950 2019-06-15
Webmin HIGH 8.8
CVE-2019-12840EPSS 78%

In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data paramet…

Fix: after 1.910
Fix from $1,950 2019-06-15
Tripmate Titan Ht Tm05 Firmware CRITICAL 9.8
CVE-2018-20841EPSS 48%

HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the …

No fix yet
Fix from $2,300 2019-06-11
Mf920 Firmware CRITICAL 9.8
CVE-2019-3412

All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify …

Mitigation only
Fix from $2,300 2019-06-11
Wf820\+ Lte Outdoor Cpe Firmware HIGH 8.8
CVE-2019-3409

All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerability. Due to inadequate para…

Fix: 1.0.0b06+
Fix from $1,950 2019-06-11
Dir 818lw Firmware HIGH 8.8
CVE-2019-12787

An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML in…

No fix yet
Fix from $1,950 2019-06-10
Crock Pot Smart Slow Cooker With Wemo Firmware CRITICAL 9.8
CVE-2019-12780EPSS 72%

The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple …

No fix yet
Fix from $2,300 2019-06-10
Awk 3121 Firmware HIGH 8.8
CVE-2018-10697

An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administrator can execute ICMP calls …

No fix yet
Fix from $1,950 2019-06-07
Awk 3121 Firmware HIGH 8.8
CVE-2018-10699

An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a…

No fix yet
Fix from $1,950 2019-06-07
Awk 3121 Firmware HIGH 8.8
CVE-2018-10702EPSS 5%

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troublesho…

No fix yet
Fix from $1,950 2019-06-07
Edgeos HIGH 7.2
CVE-2018-5265

Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credentials, because /opt/vyatta/share/…

No fix yet
Fix from $1,950 2019-06-07
Thinstation CRITICAL 9.8
CVE-2019-12771

Command injection is possible in ThinStation through 6.1.1 via shell metacharacters after the cgi-bin/CdControl.cgi action= substring, or after the c…

Fix: after 6.1.1
Fix from $2,300 2019-06-07
Ezio Ds3 Server HIGH 8.0
CVE-2019-9156

Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection.

Fix: 3.1.0+
Fix from $1,950 2019-06-05
Ubuntu Linux CRITICAL 9.8
CVE-2019-10149 KEVEPSS 100%

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c …

Fix: after 4.91
Fix from $2,300 2019-06-05
Vim HIGH 8.6
CVE-2019-12735EPSS 19%

getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a model…

Fix: 0.3.6 / 8.1.1365+
Fix from $1,950 2019-06-05
Extract HIGH 8.8
CVE-2019-12739

lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a R…

Fix: 1.2.0+
Fix from $1,950 2019-06-05
Citrix Sd Wan Center CRITICAL 9.8
CVE-2019-10883EPSS 65%

Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.

Fix: 10.0.7 / 10.2.1+
Fix from $2,300 2019-06-03
Antimalware HIGH 8.8
CVE-2019-6739EPSS 10%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711. User interac…

Mitigation only
Fix from $1,950 2019-06-03