Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2013-2573EPSS 42% A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G,… Tl Sc 3130g Firmware after 1.6.18p12 Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2013-2568EPSS 49% A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a r… F3105 Firmware after 1.6.03 Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2013-2570EPSS 27% A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the b… F3105 Firmware after 1.6.03 Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2020-7247 KEVEPSS 99% smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as… Debian Linux Patch available Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2019-20215EPSS 75% D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi()… Dir 859 Firmware Patch available Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2019-20216 D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi… Dir 859 Firmware Patch available Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2019-20217 D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi… Dir 859 Firmware Patch available Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2013-1599EPSS 40% A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01… Dcs 3411 Firmware No fix yet Fix from $2,3002020-01-28 HIGH 8.8 CVE-2012-6610EPSS 11% Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated b… Hdx Video End Points 2.7.1.j / 3.0.4+ Fix from $1,9502020-01-28 CRITICAL 9.8 CVE-2013-2060EPSS 6% The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a req… Openshift No fix yet Fix from $2,3002020-01-28 CRITICAL 9.8 CVE-2013-2612 Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with root priv… E587 Firmware Mitigation only Fix from $2,3002020-01-27 CRITICAL 9.8 CVE-2014-8563 Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS. Zimbra Collaboration Server 8.0.9+ Fix from $2,3002020-01-27 CRITICAL 9.8 CVE-2019-17095 A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `… Box 2 Firmware No fix yet Fix from $2,3002020-01-27 HIGH 8.8 CVE-2019-19824EPSS 25% On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/for… A3002ru Firmware after 4.0.0 Fix from $1,9502020-01-27 CRITICAL 9.8 CVE-2019-17096 A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_image_url()` function in special… Box 2 Firmware 2.0.66 / 2.0.66.88+ Fix from $2,3002020-01-27 HIGH 7.2 CVE-2019-12629 A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with… Sd Wan Firmware 18.3.0+ Fix from $1,9502020-01-26 HIGH 8.8 CVE-2020-7596 Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument. Nodejs Uploader 3.6.2+ Fix from $1,9502020-01-25 CRITICAL 9.8 CVE-2020-7980EPSS 83% Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. N… Aptus Web No fix yet Fix from $2,3002020-01-25 HIGH 8.8 CVE-2013-1598EPSS 20% A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, wh… Pt7135 Firmware No fix yet Fix from $1,9502020-01-24 CRITICAL 9.8 CVE-2019-19897EPSS 6% In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can communicate with the Agent Servic… Easyinstall No fix yet Fix from $2,3002020-01-23 CRITICAL 9.8 CVE-2019-19838EPSS 24% emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=g… Unleashed 9.10.2.0.84 / 9.12.3.0.136+ Fix from $2,3002020-01-23 CRITICAL 9.8 CVE-2019-19839 emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=i… Unleashed 9.10.2.0.84 / 9.12.3.0.136+ Fix from $2,3002020-01-23 HIGH 8.8 CVE-2012-4981 Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability Configfree No fix yet Fix from $1,9502020-01-23 CRITICAL 9.8 CVE-2019-19841 emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=p… Unleashed 9.10.2.0.84 / 9.12.3.0.136+ Fix from $2,3002020-01-22 CRITICAL 9.8 CVE-2019-19842 emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=s… Unleashed 9.10.2.0.84 / 9.12.3.0.136+ Fix from $2,3002020-01-22 CRITICAL 9.8 CVE-2019-10780 BibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built-in Ruby Kernel.open method t… Bibtex Ruby 5.1.0+ Fix from $2,3002020-01-22 HIGH 7.2 CVE-2020-7594 MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating … Conduit Mtcdt Lvw2 246a Firmware No fix yet Fix from $1,9502020-01-21 HIGH 7.2 CVE-2020-7242 Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Diagnostics Tr… Stampede Fx 1010 Firmware No fix yet Fix from $1,9502020-01-20 HIGH 7.2 CVE-2020-7243 Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Fetch URL page… Stampede Fx 1010 Firmware No fix yet Fix from $1,9502020-01-20 HIGH 7.2 CVE-2020-7244 Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Poll Routes pa… Stampede Fx 1010 Firmware No fix yet Fix from $1,9502020-01-20