Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2017-12078
Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenticated users to execute arbitr…
Router Manager
1.1.6-6931+
CRITICAL 9.8
CVE-2017-16100EPSS 5%
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
Dns Sync
after 0.1.1
CRITICAL 9.8
CVE-2018-3746
The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim'…
Pdfinfojs
after 0.3.6
HIGH 7.8
CVE-2016-7076
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library functi…
Sudo
after 1.8.18
HIGH 7.5
CVE-2018-1111EPSS 98%
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integratio…
Fedora
No fix yet
MEDIUM 6.7
CVE-2018-0324
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to p…
Network Functions Virtualization Infrastructure
Mitigation only
CRITICAL 9.8
CVE-2014-5014
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid c…
Wordpress Flash Uploader
3.1.3+
HIGH 7.2
CVE-2017-2832EPSS 6%
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firm…
C1 Firmware
No fix yet
HIGH 7.5
CVE-2017-2833
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firm…
C1 Firmware
No fix yet
CRITICAL 9.8
CVE-2014-6120EPSS 5%
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.…
Rational Appscan Source
Mitigation only
CRITICAL 9.8
CVE-2014-8888EPSS 5%
The remote administration interface in D-Link DIR-815 devices with firmware before 2.03.B02 allows remote attackers to execute arbitrary commands via…
Dir 815 Firmware
Mitigation only
HIGH 8.8
CVE-2014-6633
The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.2.3 allow…
Tryton
2.4.15 / 2.6.14+
CRITICAL 9.8
CVE-2014-3114
The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to execute arbitrary commands via…
Ezpz One Click Backup
after 12.03.10
HIGH 8.8
CVE-2017-7161
An issue was discovered in certain Apple products. Safari before 11.0.2 is affected. The issue involves the "WebKit Web Inspector" component. It allo…
Safari
11.0.2+
CRITICAL 9.8
CVE-2017-0915EPSS 6%
Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execu…
GitLab
after 10.3.3
CRITICAL 9.8
CVE-2017-0916EPSS 6%
Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting …
GitLab
after 10.3.3
MEDIUM 6.7
CVE-2018-0224
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, …
Staros
Mitigation only
MEDIUM 6.7
CVE-2018-0217
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, …
Asr 5000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-5439
A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attacker may be able to execute arb…
Emerge E3 Firmware
after 0.32-07e
HIGH 8.8
CVE-2016-8523EPSS 17%
A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.
Smart Storage Administrator
2.60.18.0+
MEDIUM 5.3
CVE-2017-1720
IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC.…
Notes
Patch available
HIGH 8.8
CVE-2016-5397EPSS 7%
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affe…
Thrift
after 0.9.3
HIGH 7.8
CVE-2014-1834
The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in…
Echor
Mitigation only
HIGH 8.8
CVE-2017-14592EPSS 6%
Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit …
Sourcetree
2.7+
HIGH 8.8
CVE-2017-14593EPSS 6%
Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commi…
Sourcetree
2.4.7.0+
HIGH 8.8
CVE-2016-0324
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execu…
Security Identity Manager Virtual Appliance
Patch available
CRITICAL 9.8
CVE-2018-0007
An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may…
Junos
Mitigation only
CRITICAL 9.8
CVE-2017-15940
The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x…
Pan Os
6.1.19 / 7.0.19+
HIGH 8.8
CVE-2017-15889EPSS 72%
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arb…
Diskstation Manager
5.2-5967-5+
MEDIUM 6.7
CVE-2017-12352
A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an …
Application Policy Infrastructure Controller
Mitigation only