Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Router Manager HIGH 7.2
CVE-2017-12078

Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenticated users to execute arbitr…

Fix: 1.1.6-6931+
Fix from $1,950 2018-06-08
Dns Sync CRITICAL 9.8
CVE-2017-16100EPSS 5%

dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.

Fix: after 0.1.1
Fix from $2,300 2018-06-07
Pdfinfojs CRITICAL 9.8
CVE-2018-3746

The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim'…

Fix: after 0.3.6
Fix from $2,300 2018-06-01
Sudo HIGH 7.8
CVE-2016-7076

sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library functi…

Fix: after 1.8.18
Fix from $1,950 2018-05-29
Fedora HIGH 7.5
CVE-2018-1111EPSS 98%

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integratio…

No fix yet
Fix from $1,950 2018-05-17
Network Functions Virtualization Infrastructure MEDIUM 6.7
CVE-2018-0324

A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to p…

Mitigation only
Fix from $1,600 2018-05-17
Wordpress Flash Uploader CRITICAL 9.8
CVE-2014-5014

The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid c…

Fix: 3.1.3+
Fix from $2,300 2018-04-25
C1 Firmware HIGH 7.2
CVE-2017-2832EPSS 6%

An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firm…

No fix yet
Fix from $1,950 2018-04-24
C1 Firmware HIGH 7.5
CVE-2017-2833

An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firm…

No fix yet
Fix from $1,950 2018-04-24
Rational Appscan Source CRITICAL 9.8
CVE-2014-6120EPSS 5%

IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.…

Mitigation only
Fix from $2,300 2018-04-12
Dir 815 Firmware CRITICAL 9.8
CVE-2014-8888EPSS 5%

The remote administration interface in D-Link DIR-815 devices with firmware before 2.03.B02 allows remote attackers to execute arbitrary commands via…

Mitigation only
Fix from $2,300 2018-04-12
Tryton HIGH 8.8
CVE-2014-6633

The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.2.3 allow…

Fix: 2.4.15 / 2.6.14+
Fix from $1,950 2018-04-12
Ezpz One Click Backup CRITICAL 9.8
CVE-2014-3114

The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to execute arbitrary commands via…

Fix: after 12.03.10
Fix from $2,300 2018-04-10
Safari HIGH 8.8
CVE-2017-7161

An issue was discovered in certain Apple products. Safari before 11.0.2 is affected. The issue involves the "WebKit Web Inspector" component. It allo…

Fix: 11.0.2+
Fix from $1,950 2018-04-03
GitLab CRITICAL 9.8
CVE-2017-0915EPSS 6%

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execu…

Fix: after 10.3.3
Fix from $2,300 2018-03-21
GitLab CRITICAL 9.8
CVE-2017-0916EPSS 6%

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting …

Fix: after 10.3.3
Fix from $2,300 2018-03-21
Staros MEDIUM 6.7
CVE-2018-0224

A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, …

Mitigation only
Fix from $1,600 2018-03-08
Asr 5000 Firmware MEDIUM 6.7
CVE-2018-0217

A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, …

Mitigation only
Fix from $1,600 2018-03-08
Emerge E3 Firmware CRITICAL 9.8
CVE-2018-5439

A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attacker may be able to execute arb…

Fix: after 0.32-07e
Fix from $2,300 2018-02-19
Smart Storage Administrator HIGH 8.8
CVE-2016-8523EPSS 17%

A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.

Fix: 2.60.18.0+
Fix from $1,950 2018-02-15
Notes MEDIUM 5.3
CVE-2017-1720

IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC.…

Patch available
Fix from $1,600 2018-02-13
Thrift HIGH 8.8
CVE-2016-5397EPSS 7%

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affe…

Fix: after 0.9.3
Fix from $1,950 2018-02-12
Echor HIGH 7.8
CVE-2014-1834

The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in…

Mitigation only
Fix from $1,950 2018-02-02
Sourcetree HIGH 8.8
CVE-2017-14592EPSS 6%

Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit …

Fix: 2.7+
Fix from $1,950 2018-01-26
Sourcetree HIGH 8.8
CVE-2017-14593EPSS 6%

Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commi…

Fix: 2.4.7.0+
Fix from $1,950 2018-01-26
Security Identity Manager Virtual Appliance HIGH 8.8
CVE-2016-0324

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execu…

Patch available
Fix from $1,950 2018-01-12
Junos CRITICAL 9.8
CVE-2018-0007

An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may…

Mitigation only
Fix from $2,300 2018-01-10
Pan Os CRITICAL 9.8
CVE-2017-15940

The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x…

Fix: 6.1.19 / 7.0.19+
Fix from $2,300 2017-12-11
Diskstation Manager HIGH 8.8
CVE-2017-15889EPSS 72%

Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arb…

Fix: 5.2-5967-5+
Fix from $1,950 2017-12-04
Application Policy Infrastructure Controller MEDIUM 6.7
CVE-2017-12352

A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an …

Mitigation only
Fix from $1,600 2017-11-30