Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Nx Os HIGH 8.8
CVE-2019-1614

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root p…

Fix: 7.0 / 7.3+
Fix from $1,950 2019-03-11
M2 Firmware CRITICAL 9.8
CVE-2019-9119EPSS 6%

An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote a…

No fix yet
Fix from $2,300 2019-03-07
M2 Firmware CRITICAL 9.8
CVE-2019-9120EPSS 6%

An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote a…

No fix yet
Fix from $2,300 2019-03-07
M2 Firmware CRITICAL 9.8
CVE-2019-9121

An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote a…

Mitigation only
Fix from $2,300 2019-03-07
M2 Firmware CRITICAL 9.8
CVE-2019-9117EPSS 6%

An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote a…

No fix yet
Fix from $2,300 2019-03-07
M2 Firmware CRITICAL 9.8
CVE-2019-9118EPSS 6%

An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote a…

No fix yet
Fix from $2,300 2019-03-07
Nx Os HIGH 7.8
CVE-2019-1591

A vulnerability in a specific CLI command implementation of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local atta…

Fix: 14.0+
Fix from $1,950 2019-03-06
I 240w Q Gpon Ont Firmware HIGH 8.8
CVE-2019-3919

The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent by a remo…

No fix yet
Fix from $1,950 2019-03-05
I 240w Q Gpon Ont Firmware HIGH 8.8
CVE-2019-3920

The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP request …

No fix yet
Fix from $1,950 2019-03-05
Supportutils HIGH 7.8
CVE-2018-19639

If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with…

Fix: 3.1-5.7.1+
Fix from $1,950 2019-03-05
Webex Meetings HIGH 8.8
CVE-2019-1674EPSS 11%

A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated…

Fix: 33.0.7 / 33.6.6+
Fix from $1,950 2019-02-28
Elfinder CRITICAL 9.8
CVE-2019-9194EPSS 97%

elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.

Fix: 2.1.48+
Fix from $2,300 2019-02-26
Fastgate Firmware CRITICAL 9.8
CVE-2018-20122

The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary th…

Fix: after 1.0.1b
Fix from $2,300 2019-02-21
Hyperflex Hx Data Platform HIGH 8.8
CVE-2018-15380

A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as t…

Mitigation only
Fix from $1,950 2019-02-20
Zoneminder CRITICAL 9.8
CVE-2019-8427

daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.

Fix: 1.32.3+
Fix from $2,300 2019-02-18
Dir 878 Firmware HIGH 8.8
CVE-2019-8312EPSS 7%

An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbit…

No fix yet
Fix from $1,950 2019-02-13
Dir 878 Firmware HIGH 8.8
CVE-2019-8313EPSS 6%

An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbit…

No fix yet
Fix from $1,950 2019-02-13
Dir 878 Firmware HIGH 8.8
CVE-2019-8314EPSS 6%

An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbit…

No fix yet
Fix from $1,950 2019-02-13
Dir 878 Firmware HIGH 8.8
CVE-2019-8315EPSS 6%

An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbit…

No fix yet
Fix from $1,950 2019-02-13
Dir 878 Firmware HIGH 8.8
CVE-2019-8316EPSS 7%

An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbit…

No fix yet
Fix from $1,950 2019-02-13
Dir 878 Firmware HIGH 8.8
CVE-2019-8317EPSS 6%

An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbit…

No fix yet
Fix from $1,950 2019-02-13
Dir 878 Firmware HIGH 8.8
CVE-2019-8318EPSS 6%

An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbit…

No fix yet
Fix from $1,950 2019-02-13
Dir 878 Firmware HIGH 8.8
CVE-2019-8319EPSS 8%

An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbit…

No fix yet
Fix from $1,950 2019-02-13
Docker HIGH 8.6
CVE-2019-5736EPSS 98%

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtai…

Fix: 1.4.3 / 1.5.3+
Fix from $1,950 2019-02-11
Team 220 Firmware HIGH 8.8
CVE-2019-7632EPSS 6%

LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metacharacters in …

No fix yet
Fix from $1,950 2019-02-08
Emc Vnx2 Firmware HIGH 7.8
CVE-2019-3704

VNX Control Station in Dell EMC VNX2 OE for File versions prior to 8.1.9.236 contains OS command injection vulnerability. Due to inadequate restricti…

Fix: 8.1.9.217+
Fix from $1,950 2019-02-07
Zen Load Balancer HIGH 7.2
CVE-2019-7301

Zen Load Balancer 3.10.1 allows remote authenticated admin users to execute arbitrary commands as root via shell metacharacters in the index.cgi?acti…

No fix yet
Fix from $1,950 2019-02-01
Dir 823g Firmware HIGH 8.1
CVE-2019-7298EPSS 10%

An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbit…

Fix: after 1.02b03
Fix from $1,950 2019-02-01
Dir 823g Firmware CRITICAL 9.8
CVE-2019-7297EPSS 12%

An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbit…

Fix: after 1.02b03
Fix from $2,300 2019-01-31
Cx Supervisor HIGH 7.3
CVE-2018-19015

An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially…

Fix: after 3.42
Fix from $1,950 2019-01-28