Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-15701
components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the curr…
Bloodhound
No fix yet
CRITICAL 9.8
CVE-2019-15503
cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization of Special Elements used in an…
Prontuscms
after 12.0.3.0
CRITICAL 9.8
CVE-2019-1581
A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access…
Pan Os
after 9.0.3
HIGH 8.8
CVE-2019-15526
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v…
Dir 823g Firmware
No fix yet
HIGH 8.8
CVE-2019-15527
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v…
Dir 823g Firmware
No fix yet
HIGH 8.8
CVE-2019-15528
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v…
Dir 823g Firmware
No fix yet
HIGH 8.8
CVE-2019-15529EPSS 8%
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v…
Dir 823g Firmware
No fix yet
HIGH 8.8
CVE-2019-15530
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v…
Dir 823g Firmware
No fix yet
CRITICAL 9.8
CVE-2019-15490
openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.
Openitcockpit
3.7.1+
HIGH 8.4
CVE-2019-13139
In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain…
Docker
18.09.4+
HIGH 8.8
CVE-2019-15060
The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payl…
Tl Wr840n Firmware
after 0.9.1_3.16
HIGH 7.2
CVE-2019-1896
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker t…
Unified Computing System
2.0 / 3.0+
HIGH 7.2
CVE-2019-1634
A vulnerability in the Intelligent Platform Management Interface (IPMI) of Cisco Integrated Management Controller (IMC) could allow an authenticated,…
Unified Computing System
1.5 / 2.0+
MEDIUM 6.7
CVE-2019-1839
A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of…
Remote Phy 120 Firmware
1.2 / 3.1+
HIGH 7.2
CVE-2019-1850
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote a…
Unified Computing System
3.0 / 4.0+
HIGH 8.8
CVE-2019-1864
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote a…
Unified Computing System
1.5 / 2.0+
HIGH 8.8
CVE-2019-1865
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote a…
Unified Computing System
1.5 / 2.0+
HIGH 7.8
CVE-2019-1883
A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-…
Unified Computing System
3.0 / 4.0+
HIGH 7.2
CVE-2019-1885
A vulnerability in the Redfish protocol of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject and e…
Unified Computing System
3.0 / 4.0+
HIGH 8.8
CVE-2019-3968EPSS 10%
In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creati…
Openemr
after 5.0.1
HIGH 7.8
CVE-2019-4294
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2,…
Datapower Gateway
2018.4.1.7+
CRITICAL 9.8
CVE-2019-5477EPSS 6%
A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Pro…
Ubuntu Linux
after 1.10.3
HIGH 8.8
CVE-2019-14923
EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field.
Eyesofnetwork
No fix yet
HIGH 7.8
CVE-2018-20969
do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-1…
Patch
after 2.7.6
CRITICAL 9.8
CVE-2019-15107 KEVEPSS 100%
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
Webmin
after 1.920
HIGH 8.8
CVE-2019-12792
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered us…
Control Panel
No fix yet
HIGH 8.8
CVE-2019-3417
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability. Due to insufficient parameter validation ch…
Zxhn F670 Firmware
after 1.1.10p3t18
CRITICAL 9.8
CVE-2019-12103
The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by a pre-authentication command injection vulne…
M7350 Firmware
190531+
CRITICAL 9.8
CVE-2019-14527
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. System commands can be executed, via the web interface, after authe…
Mr1100 Firmware
12.06.03+
CRITICAL 9.8
CVE-2019-15027
The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary co…
Mt8163 Firmware
No fix yet