Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Aruba Instant CRITICAL 9.8
CVE-2018-7084

A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary…

Fix: 4.2.4.12 / 6.5.4.11+
Fix from $2,300 2019-05-10
Aruba Instant HIGH 7.2
CVE-2018-7082

A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execute arbitrary commands on the …

Fix: 4.2.4.12 / 6.5.4.11+
Fix from $1,950 2019-05-10
Ews660ap Firmware CRITICAL 9.8
CVE-2019-11353

The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute utilities …

No fix yet
Fix from $2,300 2019-05-09
Airlink Es450 Firmware HIGH 8.8
CVE-2018-4061EPSS 19%

An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A spec…

No fix yet
Fix from $1,950 2019-05-06
Secure Firewall Management Center HIGH 7.8
CVE-2019-1699

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injecti…

Fix: 6.2.3.12+
Fix from $1,950 2019-05-03
Secure Firewall Management Center HIGH 7.8
CVE-2019-1709

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injecti…

Mitigation only
Fix from $1,950 2019-05-03
5200w T Firmware HIGH 8.8
CVE-2017-18372EPSS 22%

The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting functi…

No fix yet
Fix from $1,950 2019-05-02
5200w T Firmware CRITICAL 9.8
CVE-2017-18368 KEVEPSS 94%

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remo…

Mitigation only
Fix from $2,300 2019-05-02
5200w T Firmware CRITICAL 9.8
CVE-2017-18369EPSS 68%

The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding functio…

No fix yet
Fix from $2,300 2019-05-02
5200w T Firmware HIGH 8.8
CVE-2017-18370EPSS 23%

The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwardi…

No fix yet
Fix from $1,950 2019-05-02
Debian Linux CRITICAL 9.8
CVE-2019-11627

gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.

Fix: 2.10+
Fix from $2,300 2019-04-30
Am 100 Firmware CRITICAL 9.8
CVE-2019-3925EPSS 7%

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.…

No fix yet
Fix from $2,300 2019-04-30
Am 100 Firmware CRITICAL 9.8
CVE-2019-3926EPSS 7%

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14…

No fix yet
Fix from $2,300 2019-04-30
Am 100 Firmware CRITICAL 9.8
CVE-2019-3929 KEVEPSS 99%

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W befo…

Fix: 2.4.1.19+
Fix from $2,300 2019-04-30
Firefox CRITICAL 9.8
CVE-2019-9804

In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the executio…

Fix: 66.0+
Fix from $2,300 2019-04-26
Connect Secure HIGH 7.2
CVE-2019-11539 KEVEPSS 99%

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse P…

Mitigation only
Fix from $1,950 2019-04-26
405hd Firmware HIGH 8.0
CVE-2018-16216

A command injection (missing input validation, escaping) in the monitoring or memory status web interface in AudioCodes 405HD (firmware 2.2.12) VoIP …

No fix yet
Fix from $1,950 2019-04-25
Securesphere HIGH 8.8
CVE-2018-16660EPSS 17%

A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated access to exec…

No fix yet
Fix from $1,950 2019-04-25
Librenms CRITICAL 9.8
CVE-2018-20434EPSS 71%

LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php durin…

No fix yet
Fix from $2,300 2019-04-24
Liferay Portal HIGH 7.2
CVE-2019-11444EPSS 13%

An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be e…

No fix yet
Fix from $1,950 2019-04-22
Sundray Wan Controller Firmware CRITICAL 9.8
CVE-2019-9161

WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote attackers to achieve full ac…

Fix: after 3.7.4.2
Fix from $2,300 2019-04-18
Cx2 Firmware CRITICAL 9.8
CVE-2019-11322

An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in hnap, which leads to remote …

No fix yet
Fix from $2,300 2019-04-18
Cx2 Firmware CRITICAL 9.8
CVE-2019-11319

An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware in hnap, which leads to remot…

No fix yet
Fix from $2,300 2019-04-18
Aironet Access Point Firmware MEDIUM 6.7
CVE-2019-1829

A vulnerability in the CLI of Cisco Aironet Series Access Points (APs) could allow an authenticated, local attacker to gain access to the underlying …

Fix: 8.3.150.0 / 8.5.140.0+
Fix from $1,600 2019-04-18
Unified Computing System MEDIUM 5.5
CVE-2019-1725

A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS B-Series Blade Servers could allow an authenticated…

Fix: 4.0+
Fix from $1,600 2019-04-18
Tomcat HIGH 8.1
CVE-2019-0232EPSS 100%

When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93…

Fix: after 9.0.17
Fix from $1,950 2019-04-15
Api Connect CRITICAL 10.0
CVE-2019-4202

IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitra…

Fix: after 5.0.8.6
Fix from $2,300 2019-04-15
Colorqube 8700 Firmware CRITICAL 9.8
CVE-2019-10880EPSS 8%

Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" req…

Fix: 072.161.009.07200 / 072.180.009.07200+
Fix from $2,300 2019-04-12
Fios Quantum Gateway G1100 Firmware HIGH 7.2
CVE-2019-3914EPSS 30%

Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker t…

No fix yet
Fix from $1,950 2019-04-11
Edgeswitch X HIGH 8.8
CVE-2019-5424

In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to…

Fix: after 1.1.0
Fix from $1,950 2019-04-10