Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Nx Os MEDIUM 6.7
CVE-2019-1609

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…

Fix: 6.2 / 7.0+
Fix from $1,600 2019-03-08
Sourcetree HIGH 8.8
CVE-2018-20236EPSS 6%

There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker co…

Fix: 3.0.10+
Fix from $1,950 2019-03-08
I 240w Q Gpon Ont Firmware HIGH 8.8
CVE-2019-3919

The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent by a remo…

No fix yet
Fix from $1,950 2019-03-05
I 240w Q Gpon Ont Firmware HIGH 8.8
CVE-2019-3920

The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP request …

No fix yet
Fix from $1,950 2019-03-05
Fileutils HIGH 8.8
CVE-2013-2516

Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variable that is passed to the shell.

Fix: after 0.7
Fix from $1,950 2019-02-15
Haraka CRITICAL 9.8
CVE-2016-1000282EPSS 13%

Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to comman…

Fix: after 2.8.8
Fix from $2,300 2019-02-05
Debian Linux HIGH 7.8
CVE-2019-1000018

rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp p…

No fix yet
Fix from $1,950 2019-02-04
Cx Supervisor HIGH 7.3
CVE-2018-19015

An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially…

Fix: after 3.42
Fix from $1,950 2019-01-28
Vitro HIGH 7.5
CVE-2019-6986

SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression de…

Patch available
Fix from $1,950 2019-01-28
Vedge 100 Firmware HIGH 7.8
CVE-2019-1646

A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device c…

Fix: 18.4.0+
Fix from $1,950 2019-01-24
Cx Supervisor MEDIUM 5.0
CVE-2018-19013

An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a specially…

Fix: after 3.42
Fix from $1,600 2019-01-22
Securesphere HIGH 8.1
CVE-2018-5403

Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authenti…

No fix yet
Fix from $1,950 2019-01-10
Securesphere HIGH 7.8
CVE-2018-5412

Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.

No fix yet
Fix from $1,950 2019-01-10
Chrome HIGH 7.3
CVE-2017-15403

Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to…

Fix: 61.0.3163.113+
Fix from $1,950 2019-01-09
Internet Explorer HIGH 8.8
CVE-2019-0541 KEVEPSS 53%

A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution V…

Patch available
Fix from $1,950 2019-01-08
Altalink C8030 Firmware CRITICAL 9.8
CVE-2018-17172

The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and…

Fix: 100.001.028.05200 / 100.002.028.05200+
Fix from $2,300 2019-01-03
Freeswitch HIGH 7.5
CVE-2018-19911

FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or …

Fix: after 1.8.2
Fix from $1,950 2018-12-06
Qts CRITICAL 9.8
CVE-2018-14746

Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier…

Mitigation only
Fix from $2,300 2018-11-28
Nsa325 V2 Firmware HIGH 8.8
CVE-2018-14893

A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web applic…

No fix yet
Fix from $1,950 2018-11-27
Libnmap CRITICAL 9.8
CVE-2018-16461

A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range option…

Fix: 0.4.16+
Fix from $2,300 2018-10-30
Apex Publish Static Files CRITICAL 10.0
CVE-2018-16462EPSS 7%

A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a…

Fix: 2.0.1+
Fix from $2,300 2018-10-30
Enterprise Linux HIGH 7.8
CVE-2016-10729

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binar…

No fix yet
Fix from $1,950 2018-10-24
Netscaler Sd Wan CRITICAL 9.8
CVE-2018-17445EPSS 11%

A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

Fix: after 10.0.4
Fix from $2,300 2018-10-23
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-14649EPSS 12%

It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This is done by sett…

Patch available
Fix from $2,300 2018-10-09
Ios Xe MEDIUM 6.7
CVE-2018-0477

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux s…

Mitigation only
Fix from $1,600 2018-10-05
Ios Xe MEDIUM 6.7
CVE-2018-0481

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux s…

Mitigation only
Fix from $1,600 2018-10-05
Cloud Services Platform 2100 Firmware HIGH 8.8
CVE-2018-0454

A vulnerability in the web-based management interface of Cisco Cloud Services Platform 2100 could allow an authenticated, remote attacker to perform …

Mitigation only
Fix from $1,950 2018-10-05
Unified Computing System HIGH 8.8
CVE-2018-0430

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote a…

Mitigation only
Fix from $1,950 2018-10-05
Unified Computing System HIGH 8.8
CVE-2018-0431

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote a…

Mitigation only
Fix from $1,950 2018-10-05
Vedge 100 Firmware HIGH 7.8
CVE-2018-0433

A vulnerability in the command-line interface (CLI) in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbitrary com…

Fix: 18.3.0+
Fix from $1,950 2018-10-05