Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2019-0328 ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS c… Netweaver Process Integration Mitigation only Fix from $1,9502019-07-10 HIGH 8.8 CVE-2019-13481EPSS 8% An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication… Dir 818lw Firmware No fix yet Fix from $1,9502019-07-10 HIGH 8.8 CVE-2019-13482EPSS 8% An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication… Dir 818lw Firmware No fix yet Fix from $1,9502019-07-10 CRITICAL 9.8 CVE-2019-13278EPSS 9% TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, a… Tew 827dru Firmware after 2.04b03 Fix from $2,3002019-07-10 CRITICAL 9.8 CVE-2018-14495 Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE… Fd8136 Firmware No fix yet Fix from $2,3002019-07-10 CRITICAL 9.8 CVE-2018-14494 Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining th… Fd8136 Firmware Mitigation only Fix from $2,3002019-07-10 HIGH 7.2 CVE-2019-13398 Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CGI script, as demonstrated by … Fcm Mb40 Firmware No fix yet Fix from $1,9502019-07-08 HIGH 7.8 CVE-2019-1893 A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on… Enterprise Nfv Infrastructure Software Mitigation only Fix from $1,9502019-07-06 CRITICAL 9.1 CVE-2018-14860 Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privil… Odoo after 11.0 Fix from $2,3002019-07-03 CRITICAL 9.8 CVE-2018-11215 Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors. Data Science Workbench after 1.3.0 Fix from $2,3002019-07-03 HIGH 7.2 CVE-2019-6620 On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4 and BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, an undisclose… Big Ip Access Policy Manager 13.1.1.5 / 14.1.0.6+ Fix from $1,9502019-07-02 HIGH 7.2 CVE-2019-6621 On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, 11.6.1-11.6.3.4, and 11.5.2-11.5.8 and BIG-IQ 7.0.0-7.1.0.2, 6.0.0-6.1.… Big Ip Access Policy Manager 11.5.8 / 11.5.9+ Fix from $1,9502019-07-02 CRITICAL 9.8 CVE-2019-7256 KEVEPSS 97% Linear eMerge E3-Series devices allow Command Injections. Linear Emerge Essential Firmware after 1.00-06 Fix from $2,3002019-07-02 CRITICAL 9.8 CVE-2019-7269EPSS 40% Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution. Linear Emerge 50p Firmware after 4.6.07 Fix from $2,3002019-07-02 HIGH 8.8 CVE-2019-13149 An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v… Tew 827dru Firmware 2.05b11+ Fix from $1,9502019-07-02 HIGH 8.8 CVE-2019-13151 An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v… Tew 827dru Firmware 2.05b11+ Fix from $1,9502019-07-02 HIGH 8.8 CVE-2019-13153 An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v… Tew 827dru Firmware 2.05b11+ Fix from $1,9502019-07-02 HIGH 8.8 CVE-2019-13154 An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v… Tew 827dru Firmware 2.05b11+ Fix from $1,9502019-07-02 HIGH 8.8 CVE-2019-13155 An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v… Tew 827dru Firmware 2.05b11+ Fix from $1,9502019-07-02 HIGH 7.2 CVE-2019-7670EPSS 18% Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could modify the intended OS command … Flexair after 2.3.38 Fix from $1,9502019-07-01 HIGH 8.8 CVE-2019-13128EPSS 8% An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via… Dir 823g Firmware No fix yet Fix from $1,9502019-07-01 CRITICAL 9.8 CVE-2019-11829 OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrar… Calendar 2.3.1-0617+ Fix from $2,3002019-06-30 HIGH 8.8 CVE-2019-12997 In Loopchain through 2.2.1.3, an attacker can escalate privileges from a low-privilege shell by changing the environment (aka injection in the DEFAUL… Loopchain after 2.2.1.3 Fix from $1,9502019-06-28 HIGH 7.2 CVE-2019-3630 Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute … Enterprise Security Manager 10.4.0 / 11.2.0+ Fix from $1,9502019-06-27 HIGH 7.2 CVE-2019-3631 Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute … Enterprise Security Manager 10.4.0 / 11.2.0+ Fix from $1,9502019-06-27 HIGH 7.8 CVE-2019-5819 Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code vi… Chrome 74.0.3729.108+ Fix from $1,9502019-06-27 CRITICAL 9.8 CVE-2019-12928EPSS 23% The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code exe… Qemu after 4.0.0 Fix from $2,3002019-06-24 CRITICAL 9.8 CVE-2019-12929 The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achieve code execution, denial of… Qemu after 4.0.0 Fix from $2,3002019-06-24 HIGH 8.8 CVE-2018-16117EPSS 44% A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to exec… Sfos after 17.0 Fix from $1,9502019-06-20 HIGH 8.1 CVE-2018-16118 A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attacker… Sfos after 16.0 Fix from $1,9502019-06-20