Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Northstar Controller MEDIUM 5.3
CVE-2017-2324

A command injection vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-base…

Fix: after 2.1.0
Fix from $1,600 2017-04-24
Wnap320 Firmware CRITICAL 9.8
CVE-2016-1555 KEVEPSS 98%

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802…

Fix: after 3.3.2
Fix from $2,300 2017-04-21
Log \& Event Manager CRITICAL 10.0
CVE-2017-7722EPSS 13%

In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password…

Patch available
Fix from $2,300 2017-04-12
Homelynk Controller Lss100100 Firmware CRITICAL 9.8
CVE-2017-7689EPSS 6%

A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.

Fix: 1.5.0+
Fix from $2,300 2017-04-11
Enterprise Linux Desktop HIGH 7.0
CVE-2016-4444

The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial wi…

Fix: after 3.2.22
Fix from $1,950 2017-04-11
Enterprise Linux Desktop HIGH 7.0
CVE-2016-4445

The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELin…

Fix: after 3.2.22
Fix from $1,950 2017-04-11
Enterprise Linux Desktop HIGH 7.0
CVE-2016-4446

The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a craft…

Patch available
Fix from $1,950 2017-04-11
Enterprise Linux Desktop HIGH 7.0
CVE-2016-4989

setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by (1) triggering an SELinux de…

Patch available
Fix from $1,950 2017-04-11
Photo Station HIGH 8.8
CVE-2016-10322

Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwar…

Fix: after 6.3-2954
Fix from $1,950 2017-04-10
Network Management Information System HIGH 7.5
CVE-2016-6534

Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script. Versions before 8.5.12G migh…

Fix: after 8.5.10g
Fix from $1,950 2017-04-10
Aleos Firmware CRITICAL 9.8
CVE-2016-5065

Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection.

No fix yet
Fix from $2,300 2017-04-10
Aleos Firmware HIGH 8.8
CVE-2016-5067

Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Hayes AT command injection.

No fix yet
Fix from $1,950 2017-04-10
Al3g Firmware CRITICAL 9.8
CVE-2016-10312

Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.0…

No fix yet
Fix from $2,300 2017-04-03
Oceanstor 5600 V3 Firmware HIGH 7.2
CVE-2016-8801

Huawei OceanStor 5600 V3 with V300R003C00C10 and earlier versions allows attackers with administrator privilege to inject a command into a specific c…

Mitigation only
Fix from $1,950 2017-04-02
Openstack CRITICAL 9.8
CVE-2008-7313

The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CV…

Fix: after 4.2.3
Fix from $2,300 2017-03-31
Openstack CRITICAL 9.8
CVE-2014-5008

Snoopy allows remote attackers to execute arbitrary commands.

Patch available
Fix from $2,300 2017-03-31
Openstack CRITICAL 9.8
CVE-2014-5009

Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.

Fix: after 4.2.3
Fix from $2,300 2017-03-31
Fedora HIGH 7.8
CVE-2014-9114

Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.

Fix: after 2.24.2-1
Fix from $1,950 2017-03-31
Web Appliance HIGH 7.2
CVE-2017-6183

In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers …

Fix: after 4.3.1.1
Fix from $1,950 2017-03-30
Junos Space HIGH 8.8
CVE-2016-4929

Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.

Fix: after 15.2
Fix from $1,950 2017-03-20
Epo Deep Command HIGH 8.8
CVE-2015-8988

Unquoted executable path vulnerability in Client Management and Gateway components in McAfee (now Intel Security) ePO Deep Command (eDC) 2.2 and 2.1 …

Patch available
Fix from $1,950 2017-03-14
Goahead HIGH 8.8
CVE-2017-5675

A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label…

No fix yet
Fix from $1,950 2017-03-13
Festivaltts4r CRITICAL 9.8
CVE-2016-10194

The festivaltts4r gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the (1) to_speech or (2)…

Patch available
Fix from $2,300 2017-03-03
Libmacgpg HIGH 7.8
CVE-2014-4677

The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local users to execute arbitrary comm…

Fix: after 0.6
Fix from $1,950 2017-02-22
Sonicwall Secure Remote Access Server CRITICAL 9.8
CVE-2016-9682EPSS 23%

The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrat…

No fix yet
Fix from $2,300 2017-02-22
Sonicwall Secure Remote Access Server CRITICAL 9.8
CVE-2016-9683EPSS 12%

The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative …

Mitigation only
Fix from $2,300 2017-02-22
Sonicwall Secure Remote Access Server CRITICAL 9.8
CVE-2016-9684EPSS 7%

The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative …

Mitigation only
Fix from $2,300 2017-02-22
Gateway Ecu MEDIUM 6.8
CVE-2016-9337

An issue was discovered in Tesla Motors Model S automobile, all firmware versions before version 7.1 (2.36.31) with web browser functionality enabled…

Mitigation only
Fix from $1,600 2017-02-13
Hspa 3g10wve Firmware CRITICAL 9.8
CVE-2015-6024EPSS 26%

ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to exec…

No fix yet
Fix from $2,300 2017-02-09
Entera Sms Gateway Firmware CRITICAL 9.8
CVE-2016-10098

An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arb…

Mitigation only
Fix from $2,300 2017-02-05