Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2019-5156 An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and… Pfc200 Firmware No fix yet Fix from $1,9502020-03-11 HIGH 7.2 CVE-2019-5157 An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07… Pfc200 Firmware No fix yet Fix from $1,9502020-03-11 CRITICAL 9.8 CVE-2019-10807 Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the arguments provided … Blamer 1.0.1+ Fix from $2,3002020-03-11 HIGH 7.8 CVE-2020-1980 A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. T… Pan Os 8.1.13+ Fix from $1,9502020-03-11 HIGH 8.8 CVE-2019-9859 Vesta Control Panel (VestaCP) 0.9.7 through 0.9.8-23 is vulnerable to an authenticated command execution that can result in remote root access on the… Vesta Control Panel after 0.9.8-23 Fix from $1,9502020-03-10 CRITICAL 9.8 CVE-2020-10250 BWA DiREX-Pro 1.2181 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the PKG parameter to uninstall.php3. Direx Pro Firmware No fix yet Fix from $2,3002020-03-09 HIGH 8.8 CVE-2020-2159 Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the… Cryptomove after 0.1.33 Fix from $1,9502020-03-09 HIGH 8.8 CVE-2020-10235 An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via th… Froxlor 0.10.14+ Fix from $1,9502020-03-09 CRITICAL 9.8 CVE-2019-20504EPSS 10% service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell … Kace Systems Management 6.4.120822+ Fix from $2,3002020-03-09 HIGH 7.2 CVE-2016-11021 KEVEPSS 69% setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter. Dcs 930l Firmware 2.12+ Fix from $1,9502020-03-09 HIGH 8.8 CVE-2020-10221 KEVEPSS 37% lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the… Rconfig after 3.9.4 Fix from $1,9502020-03-08 HIGH 8.8 CVE-2020-10213 An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin … Dir 825 Firmware No fix yet Fix from $1,9502020-03-07 HIGH 8.8 CVE-2020-10215EPSS 5% An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parame… Dir 825 Firmware No fix yet Fix from $1,9502020-03-07 HIGH 8.8 CVE-2020-10216EPSS 5% An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a s… Dir 825 Firmware No fix yet Fix from $1,9502020-03-07 HIGH 8.8 CVE-2019-17642 An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharac… Centreon 18.10.8 / 19.04.2+ Fix from $1,9502020-03-05 HIGH 8.8 CVE-2020-10173EPSS 77% Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and tracerout… Vr 3033 Firmware No fix yet Fix from $1,9502020-03-05 HIGH 7.8 CVE-2019-20499EPSS 95% D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the … Dwl 2600ap Firmware after 4.2.0.15 Fix from $1,9502020-03-05 HIGH 7.8 CVE-2019-20500 KEVEPSS 97% D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web… Dwl 2600ap Firmware after 4.2.0.15 Fix from $1,9502020-03-05 HIGH 7.8 CVE-2019-20501EPSS 90% D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web i… Dwl 2600ap Firmware after 4.2.0.15 Fix from $1,9502020-03-05 CRITICAL 9.8 CVE-2020-9054 KEVEPSS 100% Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, whi… Nas326 Firmware 4.35 / 5.21+ Fix from $2,3002020-03-04 MEDIUM 6.7 CVE-2020-3176 A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of… Remote Phy 120 Firmware 7.7+ Fix from $1,6002020-03-04 HIGH 8.8 CVE-2020-5535 OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to execute arbitrary OS commands with root privil… Openblocks Iot Vx2 Firmware 4.0.0+ Fix from $1,9502020-03-04 HIGH 7.4 CVE-2020-1734 A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=… Ansible Engine after 3.3.4 Fix from $1,9502020-03-03 CRITICAL 9.8 CVE-2019-20488 An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to com… Wnr1000 Firmware No fix yet Fix from $2,3002020-03-02 CRITICAL 9.8 CVE-2019-10803 push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" is not validated before being … Push Dir after 0.4.1 Fix from $2,3002020-02-28 CRITICAL 9.8 CVE-2019-10804 serial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is used by the "exec" function … Serial Number after 1.3.0 Fix from $2,3002020-02-28 CRITICAL 9.8 CVE-2019-10801 enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization. Enpeem after 2.2.0 Fix from $2,3002020-02-28 CRITICAL 9.8 CVE-2019-10802 giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is executed by the package witho… Giting 0.0.8+ Fix from $2,3002020-02-28 CRITICAL 9.8 CVE-2019-15609 The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability. Kill Port Process 2.2.0+ Fix from $2,3002020-02-28 HIGH 8.8 CVE-2020-9463 Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an … Centreon No fix yet Fix from $1,9502020-02-28