Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2018-0424 A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, … Rv110w Firmware 1.0.3.44+ Fix from $1,9502018-10-05 CRITICAL 9.8 CVE-2014-10075 The karo gem 2.3.8 for Ruby allows Remote command injection via the host field. Karo No fix yet Fix from $2,3002018-10-05 CRITICAL 9.8 CVE-2018-0718 Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run arbitrary… Music Station after 5.1.2 Fix from $2,3002018-09-14 CRITICAL 9.8 CVE-2018-16460 A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID. Ps 1.0.0+ Fix from $2,3002018-09-07 HIGH 8.8 CVE-2016-9044 An exploitable command execution vulnerability exists in Information Builders WebFOCUS Business Intelligence Portal 8.1 . A specially crafted web par… Webfocus Mitigation only Fix from $1,9502018-09-07 CRITICAL 9.8 CVE-2018-3786EPSS 12% A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line argument. Egg Scripts 2.8.1+ Fix from $2,3002018-08-24 HIGH 8.8 CVE-2018-15356 An authenticated attacker can execute arbitrary code using command ejection in Eltex ESP-200 firmware version 1.2.0. Esp 200 Firmware Mitigation only Fix from $1,9502018-08-17 HIGH 8.8 CVE-2018-0427EPSS 6% A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to perf… Application Policy Infrastructure Controller Enterprise Module Mitigation only Fix from $1,9502018-08-15 CRITICAL 9.8 CVE-2018-0714 Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 2… Helpdesk after 1.1.21 Fix from $2,3002018-08-13 CRITICAL 9.8 CVE-2018-3779EPSS 6% active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An at… Activesupport No fix yet Fix from $2,3002018-08-10 CRITICAL 9.8 CVE-2018-9866 A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance… Global Management System after 8.1 Fix from $2,3002018-08-03 CRITICAL 9.1 CVE-2016-8628 Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create speci… Ansible 2.2.0+ Fix from $2,3002018-07-31 CRITICAL 9.8 CVE-2018-3772 Concatenating unsanitized user input in the `whereis` npm module < 0.4.1 allowed an attacker to execute arbitrary commands. The `whereis` module is d… Whereis 0.4.1+ Fix from $2,3002018-07-30 HIGH 7.2 CVE-2018-0344 A vulnerability in the vManage dashboard for the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remo… Vbond Orchestrator 18.3.0+ Fix from $1,9502018-07-18 HIGH 7.8 CVE-2018-0347 A vulnerability in the Zero Touch Provisioning (ZTP) subsystem of the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject ar… Vbond Orchestrator 18.3.0+ Fix from $1,9502018-07-18 HIGH 7.2 CVE-2018-0348 A vulnerability in the CLI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed … Vbond Orchestrator 18.3.0+ Fix from $1,9502018-07-18 HIGH 8.8 CVE-2018-0350 A vulnerability in the VPN subsystem configuration in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary com… Vbond Orchestrator 18.3.0+ Fix from $1,9502018-07-18 HIGH 7.8 CVE-2018-0351 A vulnerability in the command-line tcpdump utility in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbitrary com… Vbond Orchestrator 18.3.0+ Fix from $1,9502018-07-18 HIGH 8.8 CVE-2018-0341EPSS 6% A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11.2(1) could allow an authentic… Ip Phone Multiplatform Firmware Mitigation only Fix from $1,9502018-07-16 CRITICAL 9.8 CVE-2016-6558 A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface… Rp Ac52 Firmware after 1.0.1.1s Fix from $2,3002018-07-13 MEDIUM 5.5 CVE-2018-8306 A command injection vulnerability exists in the Microsoft Wireless Display Adapter (MWDA) when the Microsoft Wireless Display Adapter does not proper… Wireless Display Adapter Firmware Patch available Fix from $1,6002018-07-11 CRITICAL 9.8 CVE-2018-7785 In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass. U.motion Builder 1.3.4+ Fix from $2,3002018-07-03 HIGH 8.8 CVE-2018-1212 The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulner… Idrac6 Modular 2.91+ Fix from $1,9502018-07-02 HIGH 8.8 CVE-2018-1244 Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP a… Idrac7 Firmware 2.60.60.60 / 3.21.21.21+ Fix from $1,9502018-07-02 HIGH 7.2 CVE-2018-12465EPSS 79% An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker auth… Secure Messaging Gateway 471+ Fix from $1,9502018-06-29 CRITICAL 9.8 CVE-2018-0712 Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier… Qts after 4.3.4 Fix from $2,3002018-06-21 HIGH 8.8 CVE-2018-5428 The version control adapters component of TIBCO Data Virtualization (formerly known as Cisco Information Server) contains vulnerabilities that may al… Data Virtualization Mitigation only Fix from $1,9502018-06-20 HIGH 8.1 CVE-2011-4182 Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. … Sysconfig after 0.83.7 Fix from $1,9502018-06-12 HIGH 7.8 CVE-2014-5220 The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local a… Opensuse 3.3.3+ Fix from $1,9502018-06-08 HIGH 7.2 CVE-2017-12075 Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to execute ar… Diskstation Manager 6.2-23739+ Fix from $1,9502018-06-08