Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 7.2 CVE-2017-12078 Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenticated users to execute arbitr… Router Manager 1.1.6-6931+ Fix from $1,9502018-06-08 CRITICAL 9.8 CVE-2017-16100EPSS 5% dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible. Dns Sync after 0.1.1 Fix from $2,3002018-06-07 CRITICAL 9.8 CVE-2018-3746 The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim'… Pdfinfojs after 0.3.6 Fix from $2,3002018-06-01 HIGH 7.8 CVE-2016-7076 sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library functi… Sudo after 1.8.18 Fix from $1,9502018-05-29 HIGH 7.5 CVE-2018-1111EPSS 98% DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integratio… Fedora No fix yet Fix from $1,9502018-05-17 MEDIUM 6.7 CVE-2018-0324 A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to p… Network Functions Virtualization Infrastructure Mitigation only Fix from $1,6002018-05-17 CRITICAL 9.8 CVE-2014-5014 The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid c… Wordpress Flash Uploader 3.1.3+ Fix from $2,3002018-04-25 HIGH 7.2 CVE-2017-2832EPSS 6% An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firm… C1 Firmware No fix yet Fix from $1,9502018-04-24 HIGH 7.5 CVE-2017-2833 An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firm… C1 Firmware No fix yet Fix from $1,9502018-04-24 CRITICAL 9.8 CVE-2014-6120EPSS 5% IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.… Rational Appscan Source Mitigation only Fix from $2,3002018-04-12 CRITICAL 9.8 CVE-2014-8888EPSS 5% The remote administration interface in D-Link DIR-815 devices with firmware before 2.03.B02 allows remote attackers to execute arbitrary commands via… Dir 815 Firmware Mitigation only Fix from $2,3002018-04-12 HIGH 8.8 CVE-2014-6633 The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.2.3 allow… Tryton 2.4.15 / 2.6.14+ Fix from $1,9502018-04-12 CRITICAL 9.8 CVE-2014-3114 The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to execute arbitrary commands via… Ezpz One Click Backup after 12.03.10 Fix from $2,3002018-04-10 HIGH 8.8 CVE-2017-7161 An issue was discovered in certain Apple products. Safari before 11.0.2 is affected. The issue involves the "WebKit Web Inspector" component. It allo… Safari 11.0.2+ Fix from $1,9502018-04-03 CRITICAL 9.8 CVE-2017-0915EPSS 6% Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execu… GitLab after 10.3.3 Fix from $2,3002018-03-21 CRITICAL 9.8 CVE-2017-0916EPSS 6% Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting … GitLab after 10.3.3 Fix from $2,3002018-03-21 MEDIUM 6.7 CVE-2018-0224 A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, … Staros Mitigation only Fix from $1,6002018-03-08 MEDIUM 6.7 CVE-2018-0217 A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, … Asr 5000 Firmware Mitigation only Fix from $1,6002018-03-08 CRITICAL 9.8 CVE-2018-5439 A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attacker may be able to execute arb… Emerge E3 Firmware after 0.32-07e Fix from $2,3002018-02-19 HIGH 8.8 CVE-2016-8523EPSS 17% A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found. Smart Storage Administrator 2.60.18.0+ Fix from $1,9502018-02-15 MEDIUM 5.3 CVE-2017-1720 IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC.… Notes Patch available Fix from $1,6002018-02-13 HIGH 8.8 CVE-2016-5397EPSS 7% The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affe… Thrift after 0.9.3 Fix from $1,9502018-02-12 HIGH 7.8 CVE-2014-1834 The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in… Echor Mitigation only Fix from $1,9502018-02-02 HIGH 8.8 CVE-2017-14592EPSS 6% Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit … Sourcetree 2.7+ Fix from $1,9502018-01-26 HIGH 8.8 CVE-2017-14593EPSS 6% Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commi… Sourcetree 2.4.7.0+ Fix from $1,9502018-01-26 HIGH 8.8 CVE-2016-0324 IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execu… Security Identity Manager Virtual Appliance Patch available Fix from $1,9502018-01-12 CRITICAL 9.8 CVE-2018-0007 An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may… Junos Mitigation only Fix from $2,3002018-01-10 CRITICAL 9.8 CVE-2017-15940 The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x… Pan Os 6.1.19 / 7.0.19+ Fix from $2,3002017-12-11 HIGH 8.8 CVE-2017-15889EPSS 72% Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arb… Diskstation Manager 5.2-5967-5+ Fix from $1,9502017-12-04 MEDIUM 6.7 CVE-2017-12352 A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an … Application Policy Infrastructure Controller Mitigation only Fix from $1,6002017-11-30