Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2019-1971 A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform … Enterprise Network Function Virtualization Infrastructure after 3.8.1 Fix from $2,3002019-08-08 HIGH 7.8 CVE-2019-14744 In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This r… Debian Linux 5.61.0+ Fix from $1,9502019-08-07 CRITICAL 9.8 CVE-2019-14699EPSS 6% An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can exploit OS Command Injection in the filena… Mdc N4090 Firmware after 6400.0.8.5 Fix from $2,3002019-08-06 HIGH 8.0 CVE-2019-14260 On the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injection (missing input validation) … 8008 Firmware No fix yet Fix from $1,9502019-08-01 HIGH 8.0 CVE-2019-14259 On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address fiel… Obihai Obi1022 Firmware No fix yet Fix from $1,9502019-08-01 MEDIUM 5.5 CVE-2019-14337 An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is an ability to escape to a shell in the restricted c… 6600 Ap Firmware No fix yet Fix from $1,6002019-08-01 HIGH 7.5 CVE-2019-1020004 Tridactyl before 1.16.0 allows fake key events. Tridactyl after 1.14.10 Fix from $1,9502019-07-29 HIGH 7.8 CVE-2019-13638 GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style d… Debian Linux Patch available Fix from $1,9502019-07-26 MEDIUM 6.5 CVE-2019-3595 Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior … Data Loss Prevention Endpoint 11.1.200 / 11.3.0+ Fix from $1,6002019-07-24 CRITICAL 9.8 CVE-2019-1010179 PHKP including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b is affected by: Improper Neutralization of Special Elements used in a Command ('Comman… Phkp Mitigation only Fix from $2,3002019-07-24 CRITICAL 9.8 CVE-2019-1010200 Voice Builder Prior to commit c145d4604df67e6fc625992412eef0bf9a85e26b and f6660e6d8f0d1d931359d591dbdec580fef36d36 is affected by: CWE-78: Improper … Voice Builder Patch available Fix from $2,3002019-07-23 HIGH 8.8 CVE-2019-12328 A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP phone with… A10w Firmware No fix yet Fix from $1,9502019-07-22 HIGH 7.2 CVE-2019-12324 A command injection (missing input validation) issue in the IP address field for the logging server in the configuration web interface on the Akuvox … Sp R50p Firmware No fix yet Fix from $1,9502019-07-22 CRITICAL 9.8 CVE-2019-12725EPSS 90% Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HT… Zeroshell No fix yet Fix from $2,3002019-07-19 CRITICAL 9.8 CVE-2019-1010245 The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can ex… Open Network Operating System after 1.15 Fix from $2,3002019-07-19 CRITICAL 9.8 CVE-2019-13640EPSS 8% In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacha… Qbittorrent 4.1.7+ Fix from $2,3002019-07-17 HIGH 8.8 CVE-2019-12991 KEVEPSS 74% Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). Netscaler Sd Wan 10.0.8 / 10.2.3+ Fix from $1,9502019-07-16 HIGH 8.8 CVE-2019-12992EPSS 49% Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6). Netscaler Sd Wan 10.0.8 / 10.2.3+ Fix from $1,9502019-07-16 CRITICAL 9.8 CVE-2019-12985EPSS 40% Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). Netscaler Sd Wan 10.0.8 / 10.2.3+ Fix from $2,3002019-07-16 CRITICAL 9.8 CVE-2019-12986EPSS 40% Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6). Netscaler Sd Wan 10.0.8 / 10.2.3+ Fix from $2,3002019-07-16 CRITICAL 9.8 CVE-2019-12987EPSS 43% Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6). Netscaler Sd Wan 10.0.8 / 10.2.3+ Fix from $2,3002019-07-16 CRITICAL 9.8 CVE-2019-12988EPSS 43% Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6). Netscaler Sd Wan 10.0.8 / 10.2.3+ Fix from $2,3002019-07-16 HIGH 8.8 CVE-2019-1576 Command injection in PAN-0S 9.0.2 and earlier may allow an authenticated attacker to gain access to a remote shell in PAN-OS, and potentially run wit… Pan Os after 9.0.2 Fix from $1,9502019-07-16 CRITICAL 9.8 CVE-2019-13597EPSS 14% _s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one ca… Sahi Pro No fix yet Fix from $2,3002019-07-14 CRITICAL 9.8 CVE-2019-13598 LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_34… Vera Edge Firmware No fix yet Fix from $2,3002019-07-14 HIGH 8.8 CVE-2019-13567 The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon … Zoom 4.4.53932.0709+ Fix from $1,9502019-07-12 HIGH 7.8 CVE-2019-13574EPSS 8% In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input… Debian Linux 4.9.4+ Fix from $1,9502019-07-12 HIGH 7.8 CVE-2019-12579 A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attack… Private Internet Access Vpn Client No fix yet Fix from $1,9502019-07-11 CRITICAL 9.8 CVE-2019-11062EPSS 6% The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be explo… Wmpro No fix yet Fix from $2,3002019-07-11 CRITICAL 9.8 CVE-2019-13561EPSS 8% D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_c… Dir 655 Firmware No fix yet Fix from $2,3002019-07-11