Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2019-5425 In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the SSH interface bypassing the C… Edgeswitch X after 1.1.0 Fix from $1,9502019-04-10 HIGH 8.8 CVE-2019-10631 Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary … Nas326 Firmware after 5.21 Fix from $1,9502019-04-09 HIGH 7.2 CVE-2019-11001 KEVEPSS 38% On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to … Rlc 410w Firmware after 1.0.227 Fix from $1,9502019-04-08 CRITICAL 9.8 CVE-2019-6552 Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-suppli… Webaccess after 8.3.5 Fix from $2,3002019-04-05 HIGH 7.2 CVE-2019-9193EPSS 92% In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute a… PostgreSQL after 11.2 Fix from $1,9502019-04-01 CRITICAL 9.8 CVE-2018-17565 Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary s… Gxp1610 Firmware Mitigation only Fix from $2,3002019-04-01 HIGH 8.8 CVE-2018-17990 An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp allows a remote authenticated… Dsl 3782 Firmware No fix yet Fix from $1,9502019-04-01 HIGH 8.8 CVE-2018-5757EPSS 8% An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a paramet… 420hd Ip Phone Firmware No fix yet Fix from $1,9502019-04-01 HIGH 8.8 CVE-2018-13284 Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitra… Diskstation Manager 5.2-5967-8 / 6.0.3-8754-8+ Fix from $1,9502019-04-01 HIGH 8.8 CVE-2018-13285 Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to execute arbitrary O… Router Manager 1.1.7-6941-1+ Fix from $1,9502019-04-01 CRITICAL 9.8 CVE-2019-10655EPSS 15% Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unau… Gac2500 Firmware 1.0.3.51 / 1.0.3.219+ Fix from $2,3002019-03-30 HIGH 8.8 CVE-2019-10656 Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a … Gwn7000 Firmware 1.0.6.32+ Fix from $1,9502019-03-30 MEDIUM 6.5 CVE-2019-10657 Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply … Gwn7610 Firmware 1.0.6.32 / 1.0.8.18+ Fix from $1,6002019-03-30 HIGH 8.8 CVE-2019-10658 Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a … Gwn7610 Firmware 1.0.8.18+ Fix from $1,9502019-03-30 HIGH 8.8 CVE-2019-10659 Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharact… Gxv3370 Firmware 1.0.1.41 / 1.0.3.6+ Fix from $1,9502019-03-30 HIGH 8.8 CVE-2019-10660 Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/s… Gxv3611ir Hd Firmware 1.0.3.23+ Fix from $1,9502019-03-30 HIGH 8.8 CVE-2019-10662EPSS 44% Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConf… Ucm6204 Firmware 1.0.19.20+ Fix from $1,9502019-03-30 HIGH 7.8 CVE-2019-1745 A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated pr… Ios Xe Patch available Fix from $1,9502019-03-28 CRITICAL 9.8 CVE-2019-10061 utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user in… Node Opencv 6.1.0+ Fix from $2,3002019-03-26 HIGH 7.8 CVE-2018-3969 An exploitable vulnerability exists in the verified boot protection of the CUJO Smart Firewall. It is possible to add arbitrary shell commands into t… Smart Firewall No fix yet Fix from $1,9502019-03-21 HIGH 7.8 CVE-2019-7383 An issue was discovered on Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W devices with firmware V1.1-R2.1_TRUNK-20181105.bin. A shell command inje… Cumilon Isg 600c Firmware No fix yet Fix from $1,9502019-03-21 HIGH 7.8 CVE-2019-7384 An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with th… Iscom Ht803g U Firmware No fix yet Fix from $1,9502019-03-21 HIGH 7.8 CVE-2019-7385EPSS 12% An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with th… Iscom Ht803g U Firmware No fix yet Fix from $1,9502019-03-21 HIGH 8.1 CVE-2019-5414 If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec fu… Kill Port 1.3.2+ Fix from $1,9502019-03-21 CRITICAL 9.8 CVE-2018-20218EPSS 11% An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without… Enc 400 Hdmi Firmware after 2.56 Fix from $2,3002019-03-21 HIGH 8.8 CVE-2018-20323EPSS 54% www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitrary OS commands. Mailcleaner No fix yet Fix from $1,9502019-03-21 HIGH 8.1 CVE-2018-20106 In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backtic… Yast2 Printer after 4.0.2 Fix from $1,9502019-03-15 HIGH 7.8 CVE-2019-9785 gitnote 3.1.0 allows remote attackers to execute arbitrary code via a crafted Markdown file, as demonstrated by a javascript:window.parent.top.requir… Gitnote No fix yet Fix from $1,9502019-03-14 HIGH 7.8 CVE-2018-1998 IBM WebSphere MQ 8.0.0.0 through 9.1.1 could allow a local user to inject code that could be executed with root privileges. This is due to an incompl… Websphere Mq after 9.1.0.1 Fix from $1,9502019-03-11 MEDIUM 6.7 CVE-2019-1612 A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera… Nx Os 7.0+ Fix from $1,6002019-03-11