Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Nx Os MEDIUM 6.3
CVE-2017-12329

A vulnerability in the CLI of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an authenticated, local attack…

Mitigation only
Fix from $1,600 2017-11-30
Nx Os MEDIUM 6.3
CVE-2017-12330

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vul…

Mitigation only
Fix from $1,600 2017-11-30
Nx Os MEDIUM 6.3
CVE-2017-12335

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vul…

Mitigation only
Fix from $1,600 2017-11-30
Nx Os MEDIUM 5.7
CVE-2017-12339

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vul…

Mitigation only
Fix from $1,600 2017-11-30
Unified Computing System MEDIUM 6.7
CVE-2017-12341

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An atta…

Mitigation only
Fix from $1,600 2017-11-30
Fusionsphere Openstack HIGH 7.2
CVE-2017-8188

FusionSphere OpenStack V100R006C00SPC102(NFV)has a command injection vulnerability. Due to lack of validation, an attacker with high privilege may in…

Mitigation only
Fix from $1,950 2017-11-22
Fusionsphere Openstack HIGH 8.0
CVE-2017-8193

The FusionSphere OpenStack V100R006C00SPC102(NFV) has a command injection vulnerability. Due to the insufficient input validation on one port, an aut…

Mitigation only
Fix from $1,950 2017-11-22
Fusionsphere HIGH 7.2
CVE-2017-8197

FusionSphere V100R006C00SPC102(NFV) has a command injection vulnerability. An authenticated, remote attacker could craft packets with malicious strin…

Mitigation only
Fix from $1,950 2017-11-22
Fusionsphere Openstack HIGH 8.8
CVE-2017-8131

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation o…

Mitigation only
Fix from $1,950 2017-11-22
Fusionsphere Openstack HIGH 8.8
CVE-2017-8132

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation o…

Mitigation only
Fix from $1,950 2017-11-22
Neteco HIGH 8.8
CVE-2017-8133

Huawei iManager NetEco with software V600R008C00 and V600R008C10 has a command injection vulnerability. An authenticated, remote attacker could explo…

Mitigation only
Fix from $1,950 2017-11-22
Fusionsphere Openstack HIGH 8.8
CVE-2017-8134

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation o…

Mitigation only
Fix from $1,950 2017-11-22
Fusionsphere Openstack HIGH 8.8
CVE-2017-8135

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation o…

Mitigation only
Fix from $1,950 2017-11-22
Fusionsphere Openstack HIGH 8.8
CVE-2017-2718

FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validatio…

Mitigation only
Fix from $1,950 2017-11-22
Fusionsphere Openstack HIGH 8.8
CVE-2017-2719

FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validatio…

Mitigation only
Fix from $1,950 2017-11-22
Vcm5010 Firmware HIGH 7.2
CVE-2017-2736

VCM5010 with software versions earlier before V100R002C50SPC100 has a command injection vulnerability. This is due to insufficient validation of user…

Mitigation only
Fix from $1,950 2017-11-22
P8 Lite Firmware HIGH 7.8
CVE-2017-2692

The Keyguard application in ALE-L02C635B140 and earlier versions,ALE-L02C636B140 and earlier versions,ALE-L21C10B150 and earlier versions,ALE-L21C185…

Mitigation only
Fix from $1,950 2017-11-22
Video Station CRITICAL 9.8
CVE-2017-13071

QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3…

Mitigation only
Fix from $2,300 2017-11-22
Ip Phone 8800 Series Firmware MEDIUM 6.7
CVE-2017-12305

A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka …

Mitigation only
Fix from $1,600 2017-11-16
Net Ping External CRITICAL 9.8
CVE-2008-7319EPSS 6%

The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacter…

Fix: after 0.15
Fix from $2,300 2017-11-07
Circle With Disney Firmware MEDIUM 6.5
CVE-2017-12094

An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the …

No fix yet
Fix from $1,600 2017-11-07
Firepower Extensible Operating System HIGH 8.8
CVE-2017-12277

A vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security…

Fix: after 1.1.3
Fix from $1,950 2017-11-02
Eyou CRITICAL 9.8
CVE-2014-1203EPSS 16%

The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters i…

Fix: 3.6+
Fix from $2,300 2017-10-24
Codem Transcode HIGH 8.1
CVE-2013-7377

The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST reques…

Mitigation only
Fix from $1,950 2017-10-23
Node Printer CRITICAL 9.8
CVE-2014-3741

The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attackers to execute arbitrary comm…

Fix: after 0.0.1
Fix from $2,300 2017-10-23
Znid 2426a Firmware HIGH 8.8
CVE-2014-9118EPSS 53%

The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters…

No fix yet
Fix from $1,950 2017-10-17
Form Manager CRITICAL 9.8
CVE-2015-7806EPSS 6%

Eval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7.3 for WordPress allows remote…

No fix yet
Fix from $2,300 2017-10-17
Junos HIGH 7.8
CVE-2016-4922

Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a way that can allow unauthorized access to the oper…

Mitigation only
Fix from $1,950 2017-10-13
Blackarmor Nas 220 Firmware CRITICAL 9.8
CVE-2013-6924EPSS 15%

Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip…

No fix yet
Fix from $2,300 2017-10-11
Ui\ CRITICAL 9.8
CVE-2008-7315

UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.

No fix yet
Fix from $2,300 2017-10-10