Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2019-17107 minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the command_hostaddress parameter. NOTE… Centreon Web 2.8.27 / 18.10.4+ Fix from $1,9502019-10-08 CRITICAL 9.8 CVE-2019-12811 ActiveX Control in MyBuilder before 6.2.2019.814 allow an attacker to execute arbitrary command via the ShellOpen method. This can be leveraged for c… Mybuilder 6.2.2019.814+ Fix from $2,3002019-10-07 CRITICAL 9.8 CVE-2019-12812 MyBuilder viewer before 6.2.2019.814 allow an attacker to execute arbitrary command via specifically crafted configuration file. This can be leverage… Mybuilder 6.2.2019.814+ Fix from $2,3002019-10-07 CRITICAL 9.8 CVE-2019-15746 SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute sy… Sitos Six Mitigation only Fix from $2,3002019-10-07 CRITICAL 9.8 CVE-2019-17269 Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Ping Test field. Remote Access Mitigation only Fix from $2,3002019-10-07 HIGH 7.2 CVE-2019-15036 An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue w… Teamcity Mitigation only Fix from $1,9502019-10-02 HIGH 7.2 CVE-2019-12690 A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to inject arbitrary comman… Secure Firewall Management Center 6.3.0.5 / 6.4.0.4+ Fix from $1,9502019-10-02 HIGH 7.8 CVE-2019-12699 Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local atta… Firepower 9300 Firmware 2.2.2.101 / 2.3.1.155+ Fix from $1,9502019-10-02 CRITICAL 9.8 CVE-2019-13025 Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation. The attacker can send a… Ch7465lg Firmware No fix yet Fix from $2,3002019-10-02 CRITICAL 9.8 CVE-2019-16920 KEVEPSS 100% Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker… Dir 655 Firmware after 3.02b05 Fix from $2,3002019-09-27 HIGH 7.8 CVE-2019-12091 The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts network connections from loca… Netskope 57.2.0.219 / 60.2.0.214+ Fix from $1,9502019-09-26 MEDIUM 6.7 CVE-2019-12661 A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execu… Ios Xe Mitigation only Fix from $1,6002019-09-25 MEDIUM 6.7 CVE-2019-12709 A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services… Ios Xr 6.5.3 / 6.6.2+ Fix from $1,6002019-09-25 HIGH 7.8 CVE-2019-12717 A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco NX-OS Software could allow an authenticated, local attacker to… Nx Os 7.0 / 7.3+ Fix from $1,9502019-09-25 HIGH 8.8 CVE-2019-12650EPSS 29% Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute c… iOS Mitigation only Fix from $1,9502019-09-25 HIGH 8.8 CVE-2019-12651 Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute c… iOS Mitigation only Fix from $1,9502019-09-25 HIGH 8.8 CVE-2019-16701EPSS 20% pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metac… Pfsense 2.4.4+ Fix from $1,9502019-09-25 HIGH 7.8 CVE-2019-16718 In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's poss… Radare2 3.9.0+ Fix from $1,9502019-09-23 CRITICAL 9.8 CVE-2019-15000EPSS 8% The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed… Bitbucket 5.16.10 / 6.0.10+ Fix from $2,3002019-09-19 CRITICAL 9.8 CVE-2019-16057 KEVEPSS 87% The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection. Dns 320 Firmware after 2.05.b10 Fix from $2,3002019-09-16 CRITICAL 10.0 CVE-2019-5485EPSS 60% NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository n… Gitlabhook Mitigation only Fix from $2,3002019-09-13 HIGH 8.8 CVE-2019-16293 The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a… Open Audit 3.2.0+ Fix from $1,9502019-09-13 HIGH 7.2 CVE-2019-5315 A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary comma… Arubaos 8.3.0.0+ Fix from $1,9502019-09-13 HIGH 8.8 CVE-2019-10392EPSS 26% Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote',… Git Client after 2.8.4 Fix from $1,9502019-09-12 HIGH 7.2 CVE-2019-10669EPSS 81% An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where us… Librenms after 1.47 Fix from $1,9502019-09-09 CRITICAL 9.8 CVE-2019-10891EPSS 19% An issue was discovered in D-Link DIR-806 devices. There is a command injection in function hnap_main, which calls system() without checking the para… Dir 806 Firmware No fix yet Fix from $2,3002019-09-06 HIGH 8.8 CVE-2019-15029EPSS 12% FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will in… Fusionpbx No fix yet Fix from $1,9502019-09-05 HIGH 8.8 CVE-2019-15949 KEVEPSS 77% Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin … Nagios Xi 5.6.6+ Fix from $1,9502019-09-05 HIGH 8.8 CVE-2019-5475EPSS 18% The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable da… Nexus Repository Manager after 2.14.9-01 Fix from $1,9502019-09-03 HIGH 7.2 CVE-2019-11364 An OS Command Injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to inject arbitrary OS commands via the Ser… Snare Central 7.4.5+ Fix from $1,9502019-08-29