Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Safepay HIGH 8.8
CVE-2019-6736

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34. User interaction …

Mitigation only
Fix from $1,950 2019-06-03
Safepay HIGH 8.8
CVE-2019-6738

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34. User interaction …

Mitigation only
Fix from $1,950 2019-06-03
Pfsense CRITICAL 9.8
CVE-2019-12585EPSS 5%

Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.

Fix: 2.4.4+
Fix from $2,300 2019-06-03
Pydio HIGH 7.2
CVE-2019-10048

The ImageMagick plugin that is installed by default in Pydio through 8.2.2 does not perform the appropriate validation and sanitization of user suppl…

Fix: after 8.2.2
Fix from $1,950 2019-05-31
Network Video Recorder Firmware CRITICAL 9.8
CVE-2019-9653EPSS 11%

NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to h…

Fix: after 3.3.0
Fix from $2,300 2019-05-31
Ultra Elegant Ip Phone Sip T41p Firmware HIGH 8.8
CVE-2018-16217

The network diagnostic function (ping) in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) allows a remote authenticated attacker t…

Mitigation only
Fix from $1,950 2019-05-29
Comfortel 1200 Ip Firmware HIGH 8.0
CVE-2018-19977

A command injection (missing input validation, escaping) in the ftp upgrade configuration interface on the Auerswald COMfort 1200 IP phone 3.4.4.1-10…

No fix yet
Fix from $1,950 2019-05-29
Luci CRITICAL 9.8
CVE-2019-12272EPSS 7%

In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application a…

Fix: after 0.10.0
Fix from $2,300 2019-05-23
Nx Os MEDIUM 6.7
CVE-2019-1768

A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administra…

Fix: 8.3+
Fix from $1,600 2019-05-16
Nx Os MEDIUM 6.7
CVE-2019-1774

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…

Fix: 6.0 / 6.2+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1775

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…

Fix: 6.0 / 6.2+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1776

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux…

Fix: 4.0 / 6.0+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1778

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux…

Fix: 7.0+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1769

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary c…

Fix: 7.0+
Fix from $1,600 2019-05-15
Ns Ox MEDIUM 6.7
CVE-2019-1770

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary c…

Fix: 5.2 / 6.0+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1767

A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administra…

Fix: 8.3+
Fix from $1,600 2019-05-15
Amx Mvp5150 Firmware HIGH 8.8
CVE-2019-11224EPSS 7%

HARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection.

No fix yet
Fix from $1,950 2019-05-15
Nx Os HIGH 7.8
CVE-2019-1726

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted…

Fix: 4.0 / 6.0+
Fix from $1,950 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1727

A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser an…

Fix: 7.0 / 7.3+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.4
CVE-2019-1732

A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator…

Fix: 7.0+
Fix from $1,600 2019-05-15
Activemq CRITICAL 9.8
CVE-2013-7285EPSS 84%

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary…

Fix: after 1.4.6
Fix from $2,300 2019-05-15
Netwitness CRITICAL 9.8
CVE-2019-3725

RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulner…

Fix: 10.6.6.1 / 11.2.1.1+
Fix from $2,300 2019-05-15
Emc Recoverpoint MEDIUM 6.7
CVE-2019-3727

Dell EMC RecoverPoint versions prior to 5.1.3 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an OS command injection vulnerability in the…

Fix: 5.1.3 / 5.2.0.2+
Fix from $1,600 2019-05-15
N1a1 Firmware CRITICAL 9.8
CVE-2018-14839 KEVEPSS 89%

LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with p…

Mitigation only
Fix from $2,300 2019-05-14
Icon 300 Firmware HIGH 8.8
CVE-2019-3702EPSS 5%

A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated attackers to execute arbitrary…

No fix yet
Fix from $1,950 2019-05-13
Dir 818lw Firmware CRITICAL 9.8
CVE-2018-19986EPSS 42%

In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DI…

No fix yet
Fix from $2,300 2019-05-13
Dir 818lw Firmware CRITICAL 9.8
CVE-2018-19987EPSS 13%

D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-8…

No fix yet
Fix from $2,300 2019-05-13
Dir 868l Firmware CRITICAL 9.8
CVE-2018-19988EPSS 7%

In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.…

No fix yet
Fix from $2,300 2019-05-13
Dir 822 Firmware CRITICAL 9.8
CVE-2018-19989EPSS 6%

In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev…

No fix yet
Fix from $2,300 2019-05-13
Dir 822 Firmware CRITICAL 9.8
CVE-2018-19990EPSS 5%

In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-822 B1 202KRb06 devices. In th…

No fix yet
Fix from $2,300 2019-05-13