Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2019-14931EPSS 58% An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote… Smartrtu Firmware after 3.0 Fix from $2,3002019-10-28 CRITICAL 9.8 CVE-2019-16662EPSS 98% An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php beca… Rconfig No fix yet Fix from $2,3002019-10-28 HIGH 8.8 CVE-2019-16663EPSS 85% An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the ca… Rconfig No fix yet Fix from $1,9502019-10-28 CRITICAL 9.8 CVE-2019-5127EPSS 45% A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthen… Youphptube Encoder No fix yet Fix from $2,3002019-10-25 CRITICAL 9.8 CVE-2019-5128EPSS 30% A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthen… Youphptube Encoder No fix yet Fix from $2,3002019-10-25 CRITICAL 9.8 CVE-2019-5129EPSS 39% A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthen… Youphptube Encoder No fix yet Fix from $2,3002019-10-25 CRITICAL 9.8 CVE-2019-13649 TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5). M7350 Firmware after 1.0.16 Fix from $2,3002019-10-24 CRITICAL 9.8 CVE-2019-13650 TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow internalPort OS Command Injection (issue 2 of 5). M7350 Firmware after 1.0.16 Fix from $2,3002019-10-24 CRITICAL 9.8 CVE-2019-13651 TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow portMappingProtocol OS Command Injection (issue 3 of 5). M7350 Firmware after 1.0.16 Fix from $2,3002019-10-24 CRITICAL 9.8 CVE-2019-13652 TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow serviceName OS Command Injection (issue 4 of 5). M7350 Firmware after 1.0.16 Fix from $2,3002019-10-24 CRITICAL 9.8 CVE-2019-13653 TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow triggerPort OS Command Injection (issue 5 of 5). M7350 Firmware after 1.0.16 Fix from $2,3002019-10-24 CRITICAL 9.8 CVE-2019-18370EPSS 40% An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application us… Millet Router 3g Firmware 2.28.23+ Fix from $2,3002019-10-23 HIGH 8.8 CVE-2019-16964 app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of inp… Fusionpbx after 4.5.7 Fix from $1,9502019-10-21 HIGH 7.2 CVE-2019-16965 resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticat… Fusionpbx after 4.5.7 Fix from $1,9502019-10-21 CRITICAL 9.8 CVE-2019-17526 An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web app… Sagemathcell Patch available Fix from $2,3002019-10-18 HIGH 8.8 CVE-2019-14423EPSS 20% A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated… Cux Daemon after 2.45.6 Fix from $1,9502019-10-17 MEDIUM 6.7 CVE-2019-15277 A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to execute code wi… Telepresence Collaboration Endpoint 9.8.0+ Fix from $1,6002019-10-16 MEDIUM 6.7 CVE-2019-15274 A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to perform command… Telepresence Collaboration Endpoint 9.8.1+ Fix from $1,6002019-10-16 MEDIUM 6.7 CVE-2019-15275 A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to execute arbitra… Telepresence Collaboration Endpoint 9.8.1+ Fix from $1,6002019-10-16 CRITICAL 9.0 CVE-2019-17625 There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occur… Rambox No fix yet Fix from $2,3002019-10-16 HIGH 8.8 CVE-2019-17501 Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (aka the Configuration > Comma… Centreon No fix yet Fix from $1,9502019-10-14 CRITICAL 9.8 CVE-2019-17508EPSS 16% On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable. Dir 859 A3 Firmware No fix yet Fix from $2,3002019-10-11 CRITICAL 9.8 CVE-2019-17509 D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a … Dir 846 Firmware No fix yet Fix from $2,3002019-10-11 CRITICAL 9.8 CVE-2019-17510 D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a … Dir 846 Firmware No fix yet Fix from $2,3002019-10-11 CRITICAL 9.8 CVE-2019-17059EPSS 7% A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbit… Cyberoamos 10.6.6+ Fix from $2,3002019-10-11 HIGH 8.8 CVE-2019-17499 The setter.xml component of the Common Gateway Interface on Compal CH7465LG 6.12.18.25-2p4 devices does not properly validate ping command arguments,… Ch7465lg Firmware No fix yet Fix from $1,9502019-10-11 HIGH 8.8 CVE-2019-11527 An issue was discovered in Softing uaGate SI 1.60.01. A CGI script is vulnerable to command injection with a maliciously crafted url parameter. Uagate Si Firmware No fix yet Fix from $1,9502019-10-10 HIGH 8.8 CVE-2019-15014 A command injection vulnerability exists in the Zingbox Inspector versions 1.286 and earlier, that allows for an authenticated user to execute arbitr… Inspector after 1.286 Fix from $1,9502019-10-09 HIGH 7.2 CVE-2019-15715EPSS 30% MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution. Mantisbt 1.3.20 / 2.22.1+ Fix from $1,9502019-10-09 HIGH 8.8 CVE-2019-13051EPSS 12% Pi-Hole 4.3 allows Command Injection. Pi Hole Patch available Fix from $1,9502019-10-09