Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2019-18184EPSS 8% Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function. Dmc Stro Firmware No fix yet Fix from $2,3002019-11-27 HIGH 8.8 CVE-2019-15298EPSS 27% A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/tra… Centreon Web 2.8.30 / 18.10.8+ Fix from $1,9502019-11-27 MEDIUM 6.8 CVE-2019-16242 On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to OS command injection. An atta… Cingular Flip 2 Firmware No fix yet Fix from $1,6002019-11-26 CRITICAL 9.8 CVE-2019-12489EPSS 6% An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP … Askey Rtv1907vw Firmware No fix yet Fix from $2,3002019-11-26 MEDIUM 6.7 CVE-2019-15996 A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on t… Dna Spaces\ 2.1+ Fix from $1,6002019-11-26 MEDIUM 6.7 CVE-2019-15997 A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injection attack and execute arbitra… Dna Spaces\ 2.0+ Fix from $1,6002019-11-26 MEDIUM 6.7 CVE-2019-15986 A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro… Unity Express 10.1+ Fix from $1,6002019-11-26 HIGH 8.0 CVE-2019-18909 The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will exe… Thinpro No fix yet Fix from $1,9502019-11-22 MEDIUM 6.8 CVE-2019-18910 The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will e… Thinpro No fix yet Fix from $1,6002019-11-22 HIGH 7.8 CVE-2019-5071 An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gig… Ac9v1.0 Firmware No fix yet Fix from $1,9502019-11-21 HIGH 7.8 CVE-2019-5072 An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gig… Ac9v1.0 Firmware No fix yet Fix from $1,9502019-11-21 HIGH 7.8 CVE-2019-17650 An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local use… Forticlient after 6.2.1 Fix from $1,9502019-11-21 HIGH 7.3 CVE-2019-18934 Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answe… Fedora after 1.9.4 Fix from $1,9502019-11-19 HIGH 8.8 CVE-2019-19117EPSS 5% /usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any comman… K2\(psg1218\) Firmware No fix yet Fix from $1,9502019-11-18 HIGH 7.2 CVE-2019-19041 An issue was discovered in Xorux Lpar2RRD 6.11 and Stor2RRD 2.61, as distributed in Xorux 2.41. They do not correctly verify the integrity of an upgr… Lpar2rrd Patch available Fix from $1,9502019-11-17 CRITICAL 9.8 CVE-2019-15800 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec()… Gs1900 8 Firmware 2.50+ Fix from $2,3002019-11-14 HIGH 7.8 CVE-2019-15351 The Tecno Camon Android device with a build fingerprint of TECNO/H622/TECNO-ID5b:8.1.0/O11019/G-180829V31:user/release-keys contains a pre-installed … Tecno\/h622\/tecno Id5b\ Mitigation only Fix from $1,9502019-11-14 HIGH 7.8 CVE-2019-15342 The Tecno Camon iAir 2 Plus Android device with a build fingerprint of TECNO/H622/TECNO-ID3k:8.1.0/O11019/E-180914V83:user/release-keys contains a pr… Camon Iair 2\+ Firmware Mitigation only Fix from $1,9502019-11-14 HIGH 7.8 CVE-2019-15343 The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys contains a pre-inst… Camon Iclick Firmware Mitigation only Fix from $1,9502019-11-14 HIGH 7.8 CVE-2019-15347 The Tecno Camon iClick 2 Android device with a build fingerprint of TECNO/H622/TECNO-ID6:8.1.0/O11019/F-180824V116:user/release-keys contains a pre-i… Camon Iclick 2 Firmware Mitigation only Fix from $1,9502019-11-14 HIGH 7.8 CVE-2019-15348 The Tecno Camon Android device with a build fingerprint of TECNO/H612/TECNO-ID5a:8.1.0/O11019/F-180828V106:user/release-keys contains a pre-installed… Tecno\/h612\/tecno Id5a\ Mitigation only Fix from $1,9502019-11-14 CRITICAL 9.8 CVE-2019-5029EPSS 57% An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands … Exhibitor after 1.7.1 Fix from $2,3002019-11-13 CRITICAL 9.0 CVE-2019-18839EPSS 5% FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to … Fudforum No fix yet Fix from $2,3002019-11-13 CRITICAL 9.0 CVE-2019-18873EPSS 8% FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user accou… Fudforum No fix yet Fix from $2,3002019-11-12 HIGH 8.8 CVE-2019-8159 A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with syste… Magento 2.2.10 / 2.3.2+ Fix from $1,9502019-11-06 HIGH 7.2 CVE-2019-15588EPSS 6% There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (… Nexus Repository Manager after 2.14.14 Fix from $1,9502019-11-01 HIGH 7.2 CVE-2019-15710 An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators … Fortiextender Firmware after 4.1.1 Fix from $1,9502019-10-31 HIGH 7.2 CVE-2019-18396EPSS 16% An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping mod… Td5130v2 Firmware No fix yet Fix from $1,9502019-10-31 HIGH 8.8 CVE-2013-2024 OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0. Debian Linux after 4.8.2 Fix from $1,9502019-10-31 MEDIUM 6.8 CVE-2019-18424 An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has acce… Debian Linux after 4.12.1 Fix from $1,6002019-10-31