Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Edgeswitch X HIGH 8.8
CVE-2019-5425

In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the SSH interface bypassing the C…

Fix: after 1.1.0
Fix from $1,950 2019-04-10
Nas326 Firmware HIGH 8.8
CVE-2019-10631

Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary …

Fix: after 5.21
Fix from $1,950 2019-04-09
Rlc 410w Firmware HIGH 7.2
CVE-2019-11001 KEVEPSS 38%

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to …

Fix: after 1.0.227
Fix from $1,950 2019-04-08
Webaccess CRITICAL 9.8
CVE-2019-6552

Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-suppli…

Fix: after 8.3.5
Fix from $2,300 2019-04-05
PostgreSQL HIGH 7.2
CVE-2019-9193EPSS 92%

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute a…

Fix: after 11.2
Fix from $1,950 2019-04-01
Gxp1610 Firmware CRITICAL 9.8
CVE-2018-17565

Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary s…

Mitigation only
Fix from $2,300 2019-04-01
Dsl 3782 Firmware HIGH 8.8
CVE-2018-17990

An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp allows a remote authenticated…

No fix yet
Fix from $1,950 2019-04-01
420hd Ip Phone Firmware HIGH 8.8
CVE-2018-5757EPSS 8%

An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a paramet…

No fix yet
Fix from $1,950 2019-04-01
Diskstation Manager HIGH 8.8
CVE-2018-13284

Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitra…

Fix: 5.2-5967-8 / 6.0.3-8754-8+
Fix from $1,950 2019-04-01
Router Manager HIGH 8.8
CVE-2018-13285

Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to execute arbitrary O…

Fix: 1.1.7-6941-1+
Fix from $1,950 2019-04-01
Gac2500 Firmware CRITICAL 9.8
CVE-2019-10655EPSS 15%

Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unau…

Fix: 1.0.3.51 / 1.0.3.219+
Fix from $2,300 2019-03-30
Gwn7000 Firmware HIGH 8.8
CVE-2019-10656

Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a …

Fix: 1.0.6.32+
Fix from $1,950 2019-03-30
Gwn7610 Firmware MEDIUM 6.5
CVE-2019-10657

Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply …

Fix: 1.0.6.32 / 1.0.8.18+
Fix from $1,600 2019-03-30
Gwn7610 Firmware HIGH 8.8
CVE-2019-10658

Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a …

Fix: 1.0.8.18+
Fix from $1,950 2019-03-30
Gxv3370 Firmware HIGH 8.8
CVE-2019-10659

Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharact…

Fix: 1.0.1.41 / 1.0.3.6+
Fix from $1,950 2019-03-30
Gxv3611ir Hd Firmware HIGH 8.8
CVE-2019-10660

Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/s…

Fix: 1.0.3.23+
Fix from $1,950 2019-03-30
Ucm6204 Firmware HIGH 8.8
CVE-2019-10662EPSS 44%

Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConf…

Fix: 1.0.19.20+
Fix from $1,950 2019-03-30
Ios Xe HIGH 7.8
CVE-2019-1745

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated pr…

Patch available
Fix from $1,950 2019-03-28
Node Opencv CRITICAL 9.8
CVE-2019-10061

utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user in…

Fix: 6.1.0+
Fix from $2,300 2019-03-26
Smart Firewall HIGH 7.8
CVE-2018-3969

An exploitable vulnerability exists in the verified boot protection of the CUJO Smart Firewall. It is possible to add arbitrary shell commands into t…

No fix yet
Fix from $1,950 2019-03-21
Cumilon Isg 600c Firmware HIGH 7.8
CVE-2019-7383

An issue was discovered on Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W devices with firmware V1.1-R2.1_TRUNK-20181105.bin. A shell command inje…

No fix yet
Fix from $1,950 2019-03-21
Iscom Ht803g U Firmware HIGH 7.8
CVE-2019-7384

An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with th…

No fix yet
Fix from $1,950 2019-03-21
Iscom Ht803g U Firmware HIGH 7.8
CVE-2019-7385EPSS 12%

An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with th…

No fix yet
Fix from $1,950 2019-03-21
Kill Port HIGH 8.1
CVE-2019-5414

If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec fu…

Fix: 1.3.2+
Fix from $1,950 2019-03-21
Enc 400 Hdmi Firmware CRITICAL 9.8
CVE-2018-20218EPSS 11%

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without…

Fix: after 2.56
Fix from $2,300 2019-03-21
Mailcleaner HIGH 8.8
CVE-2018-20323EPSS 54%

www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitrary OS commands.

No fix yet
Fix from $1,950 2019-03-21
Yast2 Printer HIGH 8.1
CVE-2018-20106

In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backtic…

Fix: after 4.0.2
Fix from $1,950 2019-03-15
Gitnote HIGH 7.8
CVE-2019-9785

gitnote 3.1.0 allows remote attackers to execute arbitrary code via a crafted Markdown file, as demonstrated by a javascript:window.parent.top.requir…

No fix yet
Fix from $1,950 2019-03-14
Websphere Mq HIGH 7.8
CVE-2018-1998

IBM WebSphere MQ 8.0.0.0 through 9.1.1 could allow a local user to inject code that could be executed with root privileges. This is due to an incompl…

Fix: after 9.1.0.1
Fix from $1,950 2019-03-11
Nx Os MEDIUM 6.7
CVE-2019-1612

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…

Fix: 7.0+
Fix from $1,600 2019-03-11