Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2017-13069 QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earli… Music Station after 5.0.7 Fix from $2,3002017-10-06 HIGH 7.8 CVE-2015-6971 Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUSer… System Update after 5.06.0034 Fix from $1,9502017-10-03 CRITICAL 9.8 CVE-2015-7841 The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V1… Fusionserver Ch121 V3 Mitigation only Fix from $2,3002017-10-03 HIGH 8.8 CVE-2017-1407 IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. … Security Identity Governance And Intelligence Patch available Fix from $1,9502017-09-28 HIGH 7.8 CVE-2015-5704 scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands. Fedora after 2.15.6 Fix from $1,9502017-09-25 HIGH 8.8 CVE-2017-14081EPSS 17% Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arb… Mobile Security after 9.7 Fix from $1,9502017-09-22 MEDIUM 5.5 CVE-2017-1352 IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user … Maximo Asset Management Mitigation only Fix from $1,6002017-09-12 MEDIUM 6.7 CVE-2017-6794 A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and… Meeting Server Mitigation only Fix from $1,6002017-09-07 HIGH 7.8 CVE-2015-2210 The help window in Epicor CRS Retail Store before 3.2.03.01.008 allows local users to execute arbitrary code by injecting Javascript into the window … Crs Retail Store after 3.2.03.01.008 Fix from $1,9502017-09-06 CRITICAL 9.8 CVE-2015-2857EPSS 84% Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token p… File Transfer Appliance after 9_11_200 Fix from $2,3002017-08-22 HIGH 8.8 CVE-2017-6327 KEVEPSS 35% The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual m… Message Gateway 10.6.3-267+ Fix from $1,9502017-08-11 HIGH 7.2 CVE-2017-12756 Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter. Extplorer after 2.1.9 Fix from $1,9502017-08-09 HIGH 8.8 CVE-2017-11391EPSS 62% Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary c… Interscan Messaging Security Virtual Appliance Mitigation only Fix from $1,9502017-08-03 HIGH 8.8 CVE-2017-11392EPSS 34% Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary c… Interscan Messaging Security Virtual Appliance Mitigation only Fix from $1,9502017-08-03 HIGH 8.8 CVE-2014-8903 IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to loa… Curam Social Program Management Mitigation only Fix from $1,9502017-08-02 CRITICAL 9.8 CVE-2017-9980 In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web interface allows performing comman… Dx 350 Firmware No fix yet Fix from $2,3002017-07-21 CRITICAL 9.8 CVE-2017-7977 The Screensavercc component in eLux RP before 5.5.0 allows attackers to bypass intended configuration restrictions and execute arbitrary commands wit… Elux 5.5.0+ Fix from $2,3002017-07-19 HIGH 8.8 CVE-2017-2349 A command injection vulnerability in the IDP feature of Juniper Networks Junos OS on SRX series devices potentially allows a user with login access t… Junos Mitigation only Fix from $1,9502017-07-17 HIGH 8.8 CVE-2017-4054 Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to… Advanced Threat Defense Patch available Fix from $1,9502017-07-12 CRITICAL 9.8 CVE-2017-4984EPSS 7% In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may be able t… Vnx2 Firmware Mitigation only Fix from $2,3002017-06-19 CRITICAL 10.0 CVE-2017-7876 This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the is… Qts after 4.2.6 Fix from $2,3002017-06-15 CRITICAL 9.8 CVE-2016-6655 An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31. A comman… Cf Mysql Release after 244 Fix from $2,3002017-06-13 CRITICAL 9.8 CVE-2017-4918 VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exp… Horizon View Mitigation only Fix from $2,3002017-06-08 CRITICAL 9.8 CVE-2015-9059 picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line is executed by /bin/sh unsaf… Picocom after 1.8 Fix from $2,3002017-05-28 HIGH 7.2 CVE-2015-4046 The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array par… Open Source Security Information Management after 5.0 Fix from $1,9502017-05-23 HIGH 7.8 CVE-2017-6649 A vulnerability in the CLI of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local … Nx Os Mitigation only Fix from $1,9502017-05-22 HIGH 7.8 CVE-2017-6650 A vulnerability in the Telnet CLI command of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authen… Nx Os Mitigation only Fix from $1,9502017-05-22 HIGH 8.8 CVE-2017-6048EPSS 16% A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior,… Sennet Multitask Meter after 5.37c-1.43c Fix from $1,9502017-05-19 CRITICAL 9.8 CVE-2016-10329EPSS 41% Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell … Photo Station after 6.5.2-3225 Fix from $2,3002017-05-12 HIGH 8.8 CVE-2015-8257EPSS 18% The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app pa… Network Camera Firmware No fix yet Fix from $1,9502017-05-02