Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.5 CVE-2019-6962 A shell injection issue in cosa_wifi_apis.c in the RDK RDKB-20181217-1 CcspWifiAgent module allows attackers with login credentials to execute arbitr… Rdkb Ccsppandm Mitigation only Fix from $1,9502019-06-20 HIGH 8.8 CVE-2019-1878 A vulnerability in the Cisco Discovery Protocol (CDP) implementation for the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software c… Telepresence Ce 7.3.17 / 8.3.7+ Fix from $1,9502019-06-20 MEDIUM 6.7 CVE-2019-1879 A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to inject arbitrary commands … Unified Computing System Mitigation only Fix from $1,6002019-06-20 MEDIUM 6.7 CVE-2019-1623 A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as t… Meeting Server 2.2.14 / 2.3.8+ Fix from $1,6002019-06-20 MEDIUM 6.5 CVE-2019-1627 A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unautho… Integrated Management Controller Mitigation only Fix from $1,6002019-06-20 HIGH 8.8 CVE-2018-16593 The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection. R5c Firmware 8.216 / 8.464+ Fix from $1,9502019-06-19 CRITICAL 9.8 CVE-2018-16618EPSS 8% VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttran… Storio Max Firmware 56.d3jm6+ Fix from $2,3002019-06-19 CRITICAL 9.8 CVE-2018-18472EPSS 30% Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/… My Book Live Firmware Mitigation only Fix from $2,3002019-06-19 HIGH 8.8 CVE-2018-18852EPSS 64% Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of… Dt 300n Firmware after 1.1.12 Fix from $1,9502019-06-18 HIGH 8.8 CVE-2019-11409EPSS 87% app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input val… Fusionpbx Patch available Fix from $1,9502019-06-17 HIGH 7.2 CVE-2019-11410 app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which … Fusionpbx Patch available Fix from $1,9502019-06-17 HIGH 8.8 CVE-2019-12181EPSS 66% A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux. Serv U Ftp Server 15.1.7+ Fix from $1,9502019-06-17 HIGH 8.8 CVE-2019-12839 In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenti… Orangehrm after 4.3.1 Fix from $1,9502019-06-15 HIGH 8.8 CVE-2019-12840EPSS 78% In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data paramet… Webmin after 1.910 Fix from $1,9502019-06-15 CRITICAL 9.8 CVE-2018-20841EPSS 48% HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the … Tripmate Titan Ht Tm05 Firmware No fix yet Fix from $2,3002019-06-11 CRITICAL 9.8 CVE-2019-3412 All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify … Mf920 Firmware Mitigation only Fix from $2,3002019-06-11 HIGH 8.8 CVE-2019-3409 All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerability. Due to inadequate para… Wf820\+ Lte Outdoor Cpe Firmware 1.0.0b06+ Fix from $1,9502019-06-11 HIGH 8.8 CVE-2019-12787 An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML in… Dir 818lw Firmware No fix yet Fix from $1,9502019-06-10 CRITICAL 9.8 CVE-2019-12780EPSS 72% The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple … Crock Pot Smart Slow Cooker With Wemo Firmware No fix yet Fix from $2,3002019-06-10 HIGH 8.8 CVE-2018-10697 An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administrator can execute ICMP calls … Awk 3121 Firmware No fix yet Fix from $1,9502019-06-07 HIGH 8.8 CVE-2018-10699 An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a… Awk 3121 Firmware No fix yet Fix from $1,9502019-06-07 HIGH 8.8 CVE-2018-10702EPSS 5% An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troublesho… Awk 3121 Firmware No fix yet Fix from $1,9502019-06-07 HIGH 7.2 CVE-2018-5265 Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credentials, because /opt/vyatta/share/… Edgeos No fix yet Fix from $1,9502019-06-07 CRITICAL 9.8 CVE-2019-12771 Command injection is possible in ThinStation through 6.1.1 via shell metacharacters after the cgi-bin/CdControl.cgi action= substring, or after the c… Thinstation after 6.1.1 Fix from $2,3002019-06-07 HIGH 8.0 CVE-2019-9156 Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection. Ezio Ds3 Server 3.1.0+ Fix from $1,9502019-06-05 CRITICAL 9.8 CVE-2019-10149 KEVEPSS 100% A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c … Ubuntu Linux after 4.91 Fix from $2,3002019-06-05 HIGH 8.6 CVE-2019-12735EPSS 19% getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a model… Vim 0.3.6 / 8.1.1365+ Fix from $1,9502019-06-05 HIGH 8.8 CVE-2019-12739 lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a R… Extract 1.2.0+ Fix from $1,9502019-06-05 CRITICAL 9.8 CVE-2019-10883EPSS 65% Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection. Citrix Sd Wan Center 10.0.7 / 10.2.1+ Fix from $2,3002019-06-03 HIGH 8.8 CVE-2019-6739EPSS 10% This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711. User interac… Antimalware Mitigation only Fix from $1,9502019-06-03