Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2020-7240 Meinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS commands by editing the /conf… Lantime M300 Firmware No fix yet Fix from $1,9502020-01-20 HIGH 8.8 CVE-2020-7237EPSS 37% Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation… Cacti No fix yet Fix from $1,9502020-01-20 HIGH 7.2 CVE-2019-10956 Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticat… G Code Eec 2400 Firmware after 1.12.0.25 Fix from $1,9502020-01-17 HIGH 7.2 CVE-2019-10958 Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticat… G Code Eec 2400 Firmware after 1.12.0.25 Fix from $1,9502020-01-17 HIGH 8.8 CVE-2020-1602 When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured… Junos Mitigation only Fix from $1,9502020-01-15 HIGH 8.8 CVE-2020-1605 When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured… Junos Mitigation only Fix from $1,9502020-01-15 HIGH 8.8 CVE-2020-1609 When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured… Junos Mitigation only Fix from $1,9502020-01-15 CRITICAL 9.8 CVE-2020-5505EPSS 44% Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-p… Freelancy No fix yet Fix from $2,3002020-01-14 CRITICAL 9.8 CVE-2020-6948 A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call… Hashbrown Cms after 1.3.3 Fix from $2,3002020-01-13 HIGH 7.8 CVE-2019-18894 In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast Antivirus on port 27275 to s… Premium Security No fix yet Fix from $1,9502020-01-13 CRITICAL 9.8 CVE-2020-6756EPSS 11% languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the l… Pixelstor 5000 Firmware No fix yet Fix from $2,3002020-01-09 HIGH 8.8 CVE-2020-6757 contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute code via t… Pixelstor 5000 Firmware No fix yet Fix from $1,9502020-01-09 HIGH 8.8 CVE-2019-20224EPSS 50% netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metachar… Pandora Fms No fix yet Fix from $1,9502020-01-09 CRITICAL 9.8 CVE-2014-2650 Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface Openstage 80 Firmware Mitigation only Fix from $2,3002020-01-09 CRITICAL 9.8 CVE-2019-10777 In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any… Aws Lambda 1.0.5+ Fix from $2,3002020-01-08 CRITICAL 9.8 CVE-2019-10778 devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `co… Devcert Sanscache 0.4.7+ Fix from $2,3002020-01-08 HIGH 7.8 CVE-2019-17148 This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (454… Parallels Desktop Mitigation only Fix from $1,9502020-01-07 CRITICAL 9.8 CVE-2019-10776 In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply a… Git Diff Apply 0.22.2+ Fix from $2,3002020-01-07 MEDIUM 6.8 CVE-2019-20348 OKER G232V1 v1.03.02.20161129 devices provide a root terminal on a UART serial interface without proper access control. This allows attackers with ph… G232v1 Firmware No fix yet Fix from $1,6002020-01-06 HIGH 8.8 CVE-2019-19509EPSS 72% An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFil… Rconfig No fix yet Fix from $1,9502020-01-06 CRITICAL 9.8 CVE-2016-11017 The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via … Network Monitor after 16.5 Fix from $2,3002020-01-06 HIGH 7.2 CVE-2019-15979 Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker… Data Center Network Manager 11.3+ Fix from $1,9502020-01-06 HIGH 7.2 CVE-2019-15978EPSS 37% Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker… Data Center Network Manager 11.3+ Fix from $1,9502020-01-06 HIGH 8.8 CVE-2019-5987 Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the M… Cgi An Anlyzer after 2019-06-24 Fix from $1,9502020-01-06 CRITICAL 9.8 CVE-2012-5878EPSS 9% Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters i… Smartphone Pentest Framework after 0.1.4 Fix from $2,3002020-01-03 HIGH 8.8 CVE-2012-5693 Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the i… Smartphone Pentest Framework 0.1.3+ Fix from $1,9502020-01-03 HIGH 7.2 CVE-2020-5179 Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Diagnostics Pi… Stampede Fx 1010 Firmware No fix yet Fix from $1,9502020-01-02 HIGH 8.8 CVE-2019-20197EPSS 22% In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php… Nagios Xi No fix yet Fix from $1,9502019-12-31 CRITICAL 9.8 CVE-2019-3984 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input… Blink Xt2 Sync Module Firmware 2.3.11+ Fix from $2,3002019-12-31 HIGH 8.8 CVE-2019-9197 The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code. Unity Editor 5.6.7f1 / 2017.4.22f1+ Fix from $1,9502019-12-31