VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

748 CVEsRSS

CVE-2022-25061Critical· 9.8PoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 59%via NVD
CVE-2022-25060Critical· 9.8⚠ ExploitedPoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 40%via NVD
CVE-2021-42912High· 8.8
4y ago

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, b…

▾ Twilightfiberhome · an5506-01-a_firmwareEPSS 10%via NVD
CVE-2020-25367Critical· 9.8
4y ago

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.

▾ Midnightdlink · dir-823g_firmwareEPSS 8.6%via NVD
CVE-2020-25368Critical· 9.8
4y ago

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.

▾ Midnightdlink · dir-823g_firmwareEPSS 8.6%via NVD
CVE-2021-1448High· 7.8
5y ago

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device that is …

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device that is …

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 0.30%via NVD
CVE-2020-21883High· 8.8
5y ago

Unibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerability in /tools/ping, which can leads to complete device takeover.

Unibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerability in /tools/ping, which can leads to complete device takeover.

▾ Twilightindionetworks · unibox_u50_firmwareEPSS 4.1%via NVD
CVE-2021-28927High· 7.8
5y ago

The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the accessibility_speak_windows function, which allows attackers who have write access on filesystems t…

The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the accessibility_speak_windows function, which allows attackers who have write access on filesystems t…

▾ Twilightlibretro · retroarchEPSS 1.3%via NVD
CVE-2020-27575High· 8.8
5y ago

Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability

Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrators are able to manage users. The edit users form contains a parameter vulnerable to comma…

▾ Twilightmaxum · rumpusEPSS 3.1%via NVD
CVE-2021-25298High· 8.8CISA KEVPoC
5y ago

Nagios XI version xi-5.7.5 is affected by OS command injection

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled …

▾ Abyssalnagios · nagios_xiEPSS 75%via NVD
CVE-2021-25297High· 8.8CISA KEVPoC
5y ago

Nagios XI version xi-5.7.5 is affected by OS command injection

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled inpu…

▾ Abyssalnagios · nagios_xiEPSS 57%via NVD
CVE-2018-19949Critical· 9.8CISA KEV0day
5y ago

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130…

▾ Hadalqnap · qtsEPSS 28%via NVD
CVE-2020-3167High· 7.8
6y ago

A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS)

A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 0.89%via NVD
CVE-2019-18184Critical· 9.8
6y ago

Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.

Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.

▾ Midnightcrestron · dmc-stro_firmwareEPSS 8.1%via NVD
CVE-2019-12699High· 7.8
6y ago

Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges

Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges. T…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 0.90%via NVD
CVE-2019-15107Critical· 9.8CISA KEVPoC
7y ago

An issue was discovered in Webmin <=1.920

An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

▾ Hadalwebmin · webminEPSS 100%via NVD
CVE-2019-1971Critical· 9.8
7y ago

A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges

A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vuln…

▾ Midnightcisco · enterprise_nfv_infrastructure_softwareEPSS 3.6%via NVD
CVE-2019-1960Medium· 4.4
7y ago

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information abo…

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.35%via NVD
CVE-2019-1959Medium· 4.4
7y ago

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information abo…

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.35%via NVD
CVE-2019-1709Medium· 6.0
7y ago

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could …

▾ Sunlitcisco · secure_firewall_management_centerEPSS 0.68%via NVD
CVE-2018-19908High· 8.8PoC
7y ago

An issue was discovered in MISP 2.4.9x before 2.4.99

An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulnerability can be abused by a malicious authenticated user …

▾ Midnightmisp-project · mispEPSS 17%via NVD
CVE-2018-0453High· 8.2
7y ago

A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) sensors could allow an authenticated, local attacker to execute specific CLI commands wi…

A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) sensors could allow an authenticated, local attacker to execute specific CLI commands wi…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 0.41%via NVD
CVE-2018-11138Critical· 9.8CISA KEVPoC
8y ago

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

▾ Hadalquest · kace_system_management_applianceEPSS 92%via NVD
CVE-2018-6926High· 7.2
8y ago

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site adm…

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site adm…

▾ Twilightmisp-project · mispEPSS 1.7%via NVD
CVE-2017-6884High· 8.8CISA KEVPoC
9y ago

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numer…

▾ Abyssalzyxel · emg2926_firmwareEPSS 34%via NVD
CVE-2017-3806Medium· 5.3
9y ago

A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to inject arbitrary shell commands that are ex…

A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to inject arbitrary shell commands that are ex…

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 0.34%via NVD
CVE-1999-0043Critical· 9.8
29y ago

Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.

Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.

▾ MidnightEPSS 45%via NVD
CVE-1999-0067Critical· 10.0
30y ago

phf CGI program allows remote command execution through shell metacharacters.

phf CGI program allows remote command execution through shell metacharacters.

▾ MidnightEPSS 87%via NVD
CWE-78 vulnerabilities (CVEs) — page 25 · VulnSea