Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Music Station CRITICAL 9.8
CVE-2017-13069

QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earli…

Fix: after 5.0.7
Fix from $2,300 2017-10-06
System Update HIGH 7.8
CVE-2015-6971

Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUSer…

Fix: after 5.06.0034
Fix from $1,950 2017-10-03
Fusionserver Ch121 V3 CRITICAL 9.8
CVE-2015-7841

The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V1…

Mitigation only
Fix from $2,300 2017-10-03
Security Identity Governance And Intelligence HIGH 8.8
CVE-2017-1407

IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. …

Patch available
Fix from $1,950 2017-09-28
Fedora HIGH 7.8
CVE-2015-5704

scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.

Fix: after 2.15.6
Fix from $1,950 2017-09-25
Mobile Security HIGH 8.8
CVE-2017-14081EPSS 17%

Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arb…

Fix: after 9.7
Fix from $1,950 2017-09-22
Maximo Asset Management MEDIUM 5.5
CVE-2017-1352

IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user …

Mitigation only
Fix from $1,600 2017-09-12
Meeting Server MEDIUM 6.7
CVE-2017-6794

A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and…

Mitigation only
Fix from $1,600 2017-09-07
Crs Retail Store HIGH 7.8
CVE-2015-2210

The help window in Epicor CRS Retail Store before 3.2.03.01.008 allows local users to execute arbitrary code by injecting Javascript into the window …

Fix: after 3.2.03.01.008
Fix from $1,950 2017-09-06
File Transfer Appliance CRITICAL 9.8
CVE-2015-2857EPSS 84%

Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token p…

Fix: after 9_11_200
Fix from $2,300 2017-08-22
Message Gateway HIGH 8.8
CVE-2017-6327 KEVEPSS 35%

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual m…

Fix: 10.6.3-267+
Fix from $1,950 2017-08-11
Extplorer HIGH 7.2
CVE-2017-12756

Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.

Fix: after 2.1.9
Fix from $1,950 2017-08-09
Interscan Messaging Security Virtual Appliance HIGH 8.8
CVE-2017-11391EPSS 62%

Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2017-08-03
Interscan Messaging Security Virtual Appliance HIGH 8.8
CVE-2017-11392EPSS 34%

Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2017-08-03
Curam Social Program Management HIGH 8.8
CVE-2014-8903

IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to loa…

Mitigation only
Fix from $1,950 2017-08-02
Dx 350 Firmware CRITICAL 9.8
CVE-2017-9980

In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web interface allows performing comman…

No fix yet
Fix from $2,300 2017-07-21
Elux CRITICAL 9.8
CVE-2017-7977

The Screensavercc component in eLux RP before 5.5.0 allows attackers to bypass intended configuration restrictions and execute arbitrary commands wit…

Fix: 5.5.0+
Fix from $2,300 2017-07-19
Junos HIGH 8.8
CVE-2017-2349

A command injection vulnerability in the IDP feature of Juniper Networks Junos OS on SRX series devices potentially allows a user with login access t…

Mitigation only
Fix from $1,950 2017-07-17
Advanced Threat Defense HIGH 8.8
CVE-2017-4054

Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to…

Patch available
Fix from $1,950 2017-07-12
Vnx2 Firmware CRITICAL 9.8
CVE-2017-4984EPSS 7%

In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may be able t…

Mitigation only
Fix from $2,300 2017-06-19
Qts CRITICAL 10.0
CVE-2017-7876

This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the is…

Fix: after 4.2.6
Fix from $2,300 2017-06-15
Cf Mysql Release CRITICAL 9.8
CVE-2016-6655

An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31. A comman…

Fix: after 244
Fix from $2,300 2017-06-13
Horizon View CRITICAL 9.8
CVE-2017-4918

VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exp…

Mitigation only
Fix from $2,300 2017-06-08
Picocom CRITICAL 9.8
CVE-2015-9059

picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line is executed by /bin/sh unsaf…

Fix: after 1.8
Fix from $2,300 2017-05-28
Open Source Security Information Management HIGH 7.2
CVE-2015-4046

The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array par…

Fix: after 5.0
Fix from $1,950 2017-05-23
Nx Os HIGH 7.8
CVE-2017-6649

A vulnerability in the CLI of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local …

Mitigation only
Fix from $1,950 2017-05-22
Nx Os HIGH 7.8
CVE-2017-6650

A vulnerability in the Telnet CLI command of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authen…

Mitigation only
Fix from $1,950 2017-05-22
Sennet Multitask Meter HIGH 8.8
CVE-2017-6048EPSS 16%

A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior,…

Fix: after 5.37c-1.43c
Fix from $1,950 2017-05-19
Photo Station CRITICAL 9.8
CVE-2016-10329EPSS 41%

Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell …

Fix: after 6.5.2-3225
Fix from $2,300 2017-05-12
Network Camera Firmware HIGH 8.8
CVE-2015-8257EPSS 18%

The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app pa…

No fix yet
Fix from $1,950 2017-05-02