Vulnerabilities (CVE)

Filtered by CWE-78
Total 4316 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-25066 1 Ajenti 1 Ajenti 2024-11-21 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipulation leads to privilege escalation. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.1.32 is able to address this issue. The name of the patch is 7aa146b724e0e20cfee2c71ca78fafbf53a8767c. It is recommended to upgrade the affected component.
CVE-2019-25065 1 Opennetadmin 1 Opennetadmin 2024-11-21 7.5 HIGH 6.3 MEDIUM
A vulnerability was found in OpenNetAdmin 18.1.1. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2019-20807 6 Apple, Canonical, Debian and 3 more 7 Mac Os X, Ubuntu Linux, Debian Linux and 4 more 2024-11-21 4.6 MEDIUM 5.3 MEDIUM
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
CVE-2019-20761 1 Netgear 2 R7800, R7800 Firmware 2024-11-21 5.2 MEDIUM 8.0 HIGH
NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.
CVE-2019-20757 1 Netgear 2 R7800, R7800 Firmware 2024-11-21 5.2 MEDIUM 6.8 MEDIUM
NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.
CVE-2019-20745 1 Netgear 4 Wac505, Wac505 Firmware, Wac510 and 1 more 2024-11-21 5.2 MEDIUM 6.8 MEDIUM
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 5.0.10.2 and WAC510 before 5.0.10.2.
CVE-2019-20711 1 Netgear 6 D3600, D3600 Firmware, D6000 and 3 more 2024-11-21 5.2 MEDIUM 8.0 HIGH
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
CVE-2019-20710 1 Netgear 6 D3600, D3600 Firmware, D6000 and 3 more 2024-11-21 5.2 MEDIUM 8.0 HIGH
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
CVE-2019-20709 1 Netgear 6 D3600, D3600 Firmware, D6000 and 3 more 2024-11-21 5.2 MEDIUM 8.0 HIGH
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
CVE-2019-20708 1 Netgear 6 D3600, D3600 Firmware, D6000 and 3 more 2024-11-21 5.2 MEDIUM 8.0 HIGH
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
CVE-2019-20707 1 Netgear 4 R7800, R7800 Firmware, Xr500 and 1 more 2024-11-21 5.2 MEDIUM 8.0 HIGH
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.
CVE-2019-20706 1 Netgear 4 R7800, R7800 Firmware, Xr500 and 1 more 2024-11-21 5.2 MEDIUM 8.0 HIGH
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.
CVE-2019-20705 1 Netgear 6 D3600, D3600 Firmware, D6000 and 3 more 2024-11-21 5.2 MEDIUM 8.0 HIGH
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
CVE-2019-20704 1 Netgear 6 D3600, D3600 Firmware, D6000 and 3 more 2024-11-21 5.2 MEDIUM 8.0 HIGH
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
CVE-2019-20703 1 Netgear 6 D3600, D3600 Firmware, D6000 and 3 more 2024-11-21 5.2 MEDIUM 8.0 HIGH
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
CVE-2019-20702 1 Netgear 6 D3600, D3600 Firmware, D6000 and 3 more 2024-11-21 5.2 MEDIUM 8.0 HIGH
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
CVE-2019-20701 1 Netgear 6 D3600, D3600 Firmware, D6000 and 3 more 2024-11-21 5.2 MEDIUM 8.0 HIGH
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
CVE-2019-20504 1 Quest 1 Kace Systems Management 2024-11-21 7.5 HIGH 9.8 CRITICAL
service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.
CVE-2019-20501 1 Dlink 2 Dwl-2600ap, Dwl-2600ap Firmware 2024-11-21 7.2 HIGH 7.8 HIGH
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web interface, using shell metacharacters in the admin.cgi?action=upgrade firmwareRestore or firmwareServerip parameter.
CVE-2019-20499 1 Dlink 2 Dwl-2600ap, Dwl-2600ap Firmware 2024-11-21 7.2 HIGH 7.8 HIGH
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_restore configRestore or configServerip parameter.