Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.7
CVE-2019-1609
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…
Nx Os
6.2 / 7.0+
HIGH 8.8
CVE-2018-20236EPSS 6%
There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker co…
Sourcetree
3.0.10+
HIGH 8.8
CVE-2019-3919
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent by a remo…
I 240w Q Gpon Ont Firmware
No fix yet
HIGH 8.8
CVE-2019-3920
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP request …
I 240w Q Gpon Ont Firmware
No fix yet
HIGH 8.8
CVE-2013-2516
Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variable that is passed to the shell.
Fileutils
after 0.7
CRITICAL 9.8
CVE-2016-1000282EPSS 13%
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to comman…
Haraka
after 2.8.8
HIGH 7.8
CVE-2019-1000018
rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp p…
Debian Linux
No fix yet
HIGH 7.3
CVE-2018-19015
An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially…
Cx Supervisor
after 3.42
HIGH 7.5
CVE-2019-6986
SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression de…
Vitro
Patch available
HIGH 7.8
CVE-2019-1646
A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device c…
Vedge 100 Firmware
18.4.0+
MEDIUM 5.0
CVE-2018-19013
An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a specially…
Cx Supervisor
after 3.42
HIGH 8.1
CVE-2018-5403
Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authenti…
Securesphere
No fix yet
HIGH 7.8
CVE-2018-5412
Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.
Securesphere
No fix yet
HIGH 7.3
CVE-2017-15403
Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to…
Chrome
61.0.3163.113+
HIGH 8.8
CVE-2019-0541 KEVEPSS 53%
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution V…
Internet Explorer
Patch available
CRITICAL 9.8
CVE-2018-17172
The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and…
Altalink C8030 Firmware
100.001.028.05200 / 100.002.028.05200+
HIGH 7.5
CVE-2018-19911
FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or …
Freeswitch
after 1.8.2
CRITICAL 9.8
CVE-2018-14746
Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier…
Qts
Mitigation only
HIGH 8.8
CVE-2018-14893
A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web applic…
Nsa325 V2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-16461
A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range option…
Libnmap
0.4.16+
CRITICAL 10.0
CVE-2018-16462EPSS 7%
A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a…
Apex Publish Static Files
2.0.1+
HIGH 7.8
CVE-2016-10729
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binar…
Enterprise Linux
No fix yet
CRITICAL 9.8
CVE-2018-17445EPSS 11%
A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
Netscaler Sd Wan
after 10.0.4
CRITICAL 9.8
CVE-2018-14649EPSS 12%
It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This is done by sett…
Enterprise Linux Desktop
Patch available
MEDIUM 6.7
CVE-2018-0477
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux s…
Ios Xe
Mitigation only
MEDIUM 6.7
CVE-2018-0481
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux s…
Ios Xe
Mitigation only
HIGH 8.8
CVE-2018-0454
A vulnerability in the web-based management interface of Cisco Cloud Services Platform 2100 could allow an authenticated, remote attacker to perform …
Cloud Services Platform 2100 Firmware
Mitigation only
HIGH 8.8
CVE-2018-0430
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote a…
Unified Computing System
Mitigation only
HIGH 8.8
CVE-2018-0431
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote a…
Unified Computing System
Mitigation only
HIGH 7.8
CVE-2018-0433
A vulnerability in the command-line interface (CLI) in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbitrary com…
Vedge 100 Firmware
18.3.0+