Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Rv110w Firmware HIGH 8.8
CVE-2018-0424

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, …

Fix: 1.0.3.44+
Fix from $1,950 2018-10-05
Karo CRITICAL 9.8
CVE-2014-10075

The karo gem 2.3.8 for Ruby allows Remote command injection via the host field.

No fix yet
Fix from $2,300 2018-10-05
Music Station CRITICAL 9.8
CVE-2018-0718

Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run arbitrary…

Fix: after 5.1.2
Fix from $2,300 2018-09-14
Ps CRITICAL 9.8
CVE-2018-16460

A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.

Fix: 1.0.0+
Fix from $2,300 2018-09-07
Webfocus HIGH 8.8
CVE-2016-9044

An exploitable command execution vulnerability exists in Information Builders WebFOCUS Business Intelligence Portal 8.1 . A specially crafted web par…

Mitigation only
Fix from $1,950 2018-09-07
Egg Scripts CRITICAL 9.8
CVE-2018-3786EPSS 12%

A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line argument.

Fix: 2.8.1+
Fix from $2,300 2018-08-24
Esp 200 Firmware HIGH 8.8
CVE-2018-15356

An authenticated attacker can execute arbitrary code using command ejection in Eltex ESP-200 firmware version 1.2.0.

Mitigation only
Fix from $1,950 2018-08-17
Application Policy Infrastructure Controller Enterprise Module HIGH 8.8
CVE-2018-0427EPSS 6%

A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to perf…

Mitigation only
Fix from $1,950 2018-08-15
Helpdesk CRITICAL 9.8
CVE-2018-0714

Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 2…

Fix: after 1.1.21
Fix from $2,300 2018-08-13
Activesupport CRITICAL 9.8
CVE-2018-3779EPSS 6%

active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An at…

No fix yet
Fix from $2,300 2018-08-10
Global Management System CRITICAL 9.8
CVE-2018-9866

A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance…

Fix: after 8.1
Fix from $2,300 2018-08-03
Ansible CRITICAL 9.1
CVE-2016-8628

Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create speci…

Fix: 2.2.0+
Fix from $2,300 2018-07-31
Whereis CRITICAL 9.8
CVE-2018-3772

Concatenating unsanitized user input in the `whereis` npm module < 0.4.1 allowed an attacker to execute arbitrary commands. The `whereis` module is d…

Fix: 0.4.1+
Fix from $2,300 2018-07-30
Vbond Orchestrator HIGH 7.2
CVE-2018-0344

A vulnerability in the vManage dashboard for the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remo…

Fix: 18.3.0+
Fix from $1,950 2018-07-18
Vbond Orchestrator HIGH 7.8
CVE-2018-0347

A vulnerability in the Zero Touch Provisioning (ZTP) subsystem of the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject ar…

Fix: 18.3.0+
Fix from $1,950 2018-07-18
Vbond Orchestrator HIGH 7.2
CVE-2018-0348

A vulnerability in the CLI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed …

Fix: 18.3.0+
Fix from $1,950 2018-07-18
Vbond Orchestrator HIGH 8.8
CVE-2018-0350

A vulnerability in the VPN subsystem configuration in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary com…

Fix: 18.3.0+
Fix from $1,950 2018-07-18
Vbond Orchestrator HIGH 7.8
CVE-2018-0351

A vulnerability in the command-line tcpdump utility in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbitrary com…

Fix: 18.3.0+
Fix from $1,950 2018-07-18
Ip Phone Multiplatform Firmware HIGH 8.8
CVE-2018-0341EPSS 6%

A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11.2(1) could allow an authentic…

Mitigation only
Fix from $1,950 2018-07-16
Rp Ac52 Firmware CRITICAL 9.8
CVE-2016-6558

A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface…

Fix: after 1.0.1.1s
Fix from $2,300 2018-07-13
Wireless Display Adapter Firmware MEDIUM 5.5
CVE-2018-8306

A command injection vulnerability exists in the Microsoft Wireless Display Adapter (MWDA) when the Microsoft Wireless Display Adapter does not proper…

Patch available
Fix from $1,600 2018-07-11
U.motion Builder CRITICAL 9.8
CVE-2018-7785

In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.

Fix: 1.3.4+
Fix from $2,300 2018-07-03
Idrac6 Modular HIGH 8.8
CVE-2018-1212

The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulner…

Fix: 2.91+
Fix from $1,950 2018-07-02
Idrac7 Firmware HIGH 8.8
CVE-2018-1244

Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP a…

Fix: 2.60.60.60 / 3.21.21.21+
Fix from $1,950 2018-07-02
Secure Messaging Gateway HIGH 7.2
CVE-2018-12465EPSS 79%

An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker auth…

Fix: 471+
Fix from $1,950 2018-06-29
Qts CRITICAL 9.8
CVE-2018-0712

Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier…

Fix: after 4.3.4
Fix from $2,300 2018-06-21
Data Virtualization HIGH 8.8
CVE-2018-5428

The version control adapters component of TIBCO Data Virtualization (formerly known as Cisco Information Server) contains vulnerabilities that may al…

Mitigation only
Fix from $1,950 2018-06-20
Sysconfig HIGH 8.1
CVE-2011-4182

Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. …

Fix: after 0.83.7
Fix from $1,950 2018-06-12
Opensuse HIGH 7.8
CVE-2014-5220

The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local a…

Fix: 3.3.3+
Fix from $1,950 2018-06-08
Diskstation Manager HIGH 7.2
CVE-2017-12075

Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to execute ar…

Fix: 6.2-23739+
Fix from $1,950 2018-06-08