Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2019-18184EPSS 8%
Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.
Dmc Stro Firmware
No fix yet
HIGH 8.8
CVE-2019-15298EPSS 27%
A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/tra…
Centreon Web
2.8.30 / 18.10.8+
MEDIUM 6.8
CVE-2019-16242
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to OS command injection. An atta…
Cingular Flip 2 Firmware
No fix yet
CRITICAL 9.8
CVE-2019-12489EPSS 6%
An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP …
Askey Rtv1907vw Firmware
No fix yet
MEDIUM 6.7
CVE-2019-15996
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on t…
Dna Spaces\
2.1+
MEDIUM 6.7
CVE-2019-15997
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injection attack and execute arbitra…
Dna Spaces\
2.0+
MEDIUM 6.7
CVE-2019-15986
A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro…
Unity Express
10.1+
HIGH 8.0
CVE-2019-18909
The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will exe…
Thinpro
No fix yet
MEDIUM 6.8
CVE-2019-18910
The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will e…
Thinpro
No fix yet
HIGH 7.8
CVE-2019-5071
An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gig…
Ac9v1.0 Firmware
No fix yet
HIGH 7.8
CVE-2019-5072
An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gig…
Ac9v1.0 Firmware
No fix yet
HIGH 7.8
CVE-2019-17650
An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local use…
Forticlient
after 6.2.1
HIGH 7.3
CVE-2019-18934
Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answe…
Fedora
after 1.9.4
HIGH 8.8
CVE-2019-19117EPSS 5%
/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any comman…
K2\(psg1218\) Firmware
No fix yet
HIGH 7.2
CVE-2019-19041
An issue was discovered in Xorux Lpar2RRD 6.11 and Stor2RRD 2.61, as distributed in Xorux 2.41. They do not correctly verify the integrity of an upgr…
Lpar2rrd
Patch available
CRITICAL 9.8
CVE-2019-15800
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec()…
Gs1900 8 Firmware
2.50+
HIGH 7.8
CVE-2019-15351
The Tecno Camon Android device with a build fingerprint of TECNO/H622/TECNO-ID5b:8.1.0/O11019/G-180829V31:user/release-keys contains a pre-installed …
Tecno\/h622\/tecno Id5b\
Mitigation only
HIGH 7.8
CVE-2019-15342
The Tecno Camon iAir 2 Plus Android device with a build fingerprint of TECNO/H622/TECNO-ID3k:8.1.0/O11019/E-180914V83:user/release-keys contains a pr…
Camon Iair 2\+ Firmware
Mitigation only
HIGH 7.8
CVE-2019-15343
The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys contains a pre-inst…
Camon Iclick Firmware
Mitigation only
HIGH 7.8
CVE-2019-15347
The Tecno Camon iClick 2 Android device with a build fingerprint of TECNO/H622/TECNO-ID6:8.1.0/O11019/F-180824V116:user/release-keys contains a pre-i…
Camon Iclick 2 Firmware
Mitigation only
HIGH 7.8
CVE-2019-15348
The Tecno Camon Android device with a build fingerprint of TECNO/H612/TECNO-ID5a:8.1.0/O11019/F-180828V106:user/release-keys contains a pre-installed…
Tecno\/h612\/tecno Id5a\
Mitigation only
CRITICAL 9.8
CVE-2019-5029EPSS 57%
An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands …
Exhibitor
after 1.7.1
CRITICAL 9.0
CVE-2019-18839EPSS 5%
FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to …
Fudforum
No fix yet
CRITICAL 9.0
CVE-2019-18873EPSS 8%
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user accou…
Fudforum
No fix yet
HIGH 8.8
CVE-2019-8159
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with syste…
Magento
2.2.10 / 2.3.2+
HIGH 7.2
CVE-2019-15588EPSS 6%
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (…
Nexus Repository Manager
after 2.14.14
HIGH 7.2
CVE-2019-15710
An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators …
Fortiextender Firmware
after 4.1.1
HIGH 7.2
CVE-2019-18396EPSS 16%
An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping mod…
Td5130v2 Firmware
No fix yet
HIGH 8.8
CVE-2013-2024
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.
Debian Linux
after 4.8.2
MEDIUM 6.8
CVE-2019-18424
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has acce…
Debian Linux
after 4.12.1