Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2019-16790 In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted. Tiny File Manager 2.3.9+ Fix from $1,9502019-12-30 CRITICAL 9.8 CVE-2019-10774 php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. Php Shellcommand 1.6.1+ Fix from $2,3002019-12-30 CRITICAL 9.8 CVE-2019-17621 KEVEPSS 90% The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute syste… Dir 859 Firmware after 3.12b04 Fix from $2,3002019-12-30 MEDIUM 6.6 CVE-2019-6013 DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line Interface (CLI). Dba 1510p Firmware after 1.70b009 Fix from $1,6002019-12-26 HIGH 8.8 CVE-2019-6014 DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User Interface. Dba 1510p Firmware after 1.70b009 Fix from $1,9502019-12-26 HIGH 8.8 CVE-2019-19920 sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (r… Ubuntu Linux Patch available Fix from $1,9502019-12-22 CRITICAL 9.8 CVE-2019-15598 A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command. Treekill Mitigation only Fix from $2,3002019-12-18 HIGH 7.8 CVE-2019-8513 This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to execute arbitrary shell comma… Mac Os X 10.14.4+ Fix from $1,9502019-12-18 CRITICAL 9.8 CVE-2019-11399 An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. OS command injection occurs through the get… Tew 651br Firmware Mitigation only Fix from $2,3002019-12-18 CRITICAL 9.8 CVE-2019-18830 Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the function… Clickshare Cs 100 Firmware 1.9.0+ Fix from $2,3002019-12-16 CRITICAL 9.8 CVE-2019-16730 processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary syst… Petalk Ai Firmware No fix yet Fix from $2,3002019-12-13 CRITICAL 9.8 CVE-2019-16733 processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary syste… Petalk Ai Firmware No fix yet Fix from $2,3002019-12-13 CRITICAL 9.8 CVE-2019-16737 The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute ar… Petalk Ai Firmware No fix yet Fix from $2,3002019-12-13 CRITICAL 9.8 CVE-2019-17364 The processCommandUploadLog() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute… Petalk Ai Firmware No fix yet Fix from $2,3002019-12-13 MEDIUM 6.7 CVE-2018-11805 In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits ca… Spamassassin 3.4.3+ Fix from $1,6002019-12-12 HIGH 8.8 CVE-2019-3985 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input… Blink Xt2 Sync Module Firmware 2.13.11+ Fix from $1,9502019-12-11 HIGH 8.8 CVE-2019-3986 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input… Blink Xt2 Sync Module Firmware 2.13.11+ Fix from $1,9502019-12-11 HIGH 8.8 CVE-2019-3987 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input… Blink Xt2 Sync Module Firmware 2.13.11+ Fix from $1,9502019-12-11 HIGH 8.8 CVE-2019-3988 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input… Blink Xt2 Sync Module Firmware 2.13.11+ Fix from $1,9502019-12-11 CRITICAL 9.8 CVE-2019-3989 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input… Blink Xt2 Sync Module Firmware 2.13.11+ Fix from $2,3002019-12-11 HIGH 8.8 CVE-2014-0163 Openshift has shell command injection flaws due to unsanitized data being passed into shell commands. Openshift Mitigation only Fix from $1,9502019-12-11 HIGH 8.8 CVE-2019-4715 IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafte… Spectrum Scale after 5.0.4.0 Fix from $1,9502019-12-11 HIGH 7.8 CVE-2019-19604 Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.2… Git 2.20.0 / 2.21.1+ Fix from $1,9502019-12-11 HIGH 8.8 CVE-2019-14889 A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a serve… Ubuntu Linux 0.8.8 / 0.9.3+ Fix from $1,9502019-12-10 CRITICAL 9.8 CVE-2019-17270EPSS 59% Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?… Yachtcontrol after 2019-10-06 Fix from $2,3002019-12-10 HIGH 8.8 CVE-2019-19642EPSS 19% On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated att… X8sti F Bios No fix yet Fix from $1,9502019-12-08 HIGH 7.2 CVE-2019-19609EPSS 54% The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel,… Strapi after 1.6.4 Fix from $1,9502019-12-05 HIGH 8.8 CVE-2019-19469 In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with s… Amanda Mitigation only Fix from $1,9502019-12-01 CRITICAL 9.8 CVE-2011-2523EPSS 96% vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp. Debian Linux No fix yet Fix from $2,3002019-11-27 HIGH 8.8 CVE-2017-12945EPSS 17% Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to execute … Solstice Firmware 2.8.4+ Fix from $1,9502019-11-27