Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2017-2324
A command injection vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-base…
Northstar Controller
after 2.1.0
CRITICAL 9.8
CVE-2016-1555 KEVEPSS 98%
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802…
Wnap320 Firmware
after 3.3.2
CRITICAL 10.0
CVE-2017-7722EPSS 13%
In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password…
Log \& Event Manager
Patch available
CRITICAL 9.8
CVE-2017-7689EPSS 6%
A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.
Homelynk Controller Lss100100 Firmware
1.5.0+
HIGH 7.0
CVE-2016-4444
The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial wi…
Enterprise Linux Desktop
after 3.2.22
HIGH 7.0
CVE-2016-4445
The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELin…
Enterprise Linux Desktop
after 3.2.22
HIGH 7.0
CVE-2016-4446
The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a craft…
Enterprise Linux Desktop
Patch available
HIGH 7.0
CVE-2016-4989
setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by (1) triggering an SELinux de…
Enterprise Linux Desktop
Patch available
HIGH 8.8
CVE-2016-10322
Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwar…
Photo Station
after 6.3-2954
HIGH 7.5
CVE-2016-6534
Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script. Versions before 8.5.12G migh…
Network Management Information System
after 8.5.10g
CRITICAL 9.8
CVE-2016-5065
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection.
Aleos Firmware
No fix yet
HIGH 8.8
CVE-2016-5067
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Hayes AT command injection.
Aleos Firmware
No fix yet
CRITICAL 9.8
CVE-2016-10312
Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.0…
Al3g Firmware
No fix yet
HIGH 7.2
CVE-2016-8801
Huawei OceanStor 5600 V3 with V300R003C00C10 and earlier versions allows attackers with administrator privilege to inject a command into a specific c…
Oceanstor 5600 V3 Firmware
Mitigation only
CRITICAL 9.8
CVE-2008-7313
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CV…
Openstack
after 4.2.3
CRITICAL 9.8
CVE-2014-5008
Snoopy allows remote attackers to execute arbitrary commands.
Openstack
Patch available
CRITICAL 9.8
CVE-2014-5009
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
Openstack
after 4.2.3
HIGH 7.8
CVE-2014-9114
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
Fedora
after 2.24.2-1
HIGH 7.2
CVE-2017-6183
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers …
Web Appliance
after 4.3.1.1
HIGH 8.8
CVE-2016-4929
Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.
Junos Space
after 15.2
HIGH 8.8
CVE-2015-8988
Unquoted executable path vulnerability in Client Management and Gateway components in McAfee (now Intel Security) ePO Deep Command (eDC) 2.2 and 2.1 …
Epo Deep Command
Patch available
HIGH 8.8
CVE-2017-5675
A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label…
Goahead
No fix yet
CRITICAL 9.8
CVE-2016-10194
The festivaltts4r gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the (1) to_speech or (2)…
Festivaltts4r
Patch available
HIGH 7.8
CVE-2014-4677
The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local users to execute arbitrary comm…
Libmacgpg
after 0.6
CRITICAL 9.8
CVE-2016-9682EPSS 23%
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrat…
Sonicwall Secure Remote Access Server
No fix yet
CRITICAL 9.8
CVE-2016-9683EPSS 12%
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative …
Sonicwall Secure Remote Access Server
Mitigation only
CRITICAL 9.8
CVE-2016-9684EPSS 7%
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative …
Sonicwall Secure Remote Access Server
Mitigation only
MEDIUM 6.8
CVE-2016-9337
An issue was discovered in Tesla Motors Model S automobile, all firmware versions before version 7.1 (2.36.31) with web browser functionality enabled…
Gateway Ecu
Mitigation only
CRITICAL 9.8
CVE-2015-6024EPSS 26%
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to exec…
Hspa 3g10wve Firmware
No fix yet
CRITICAL 9.8
CVE-2016-10098
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arb…
Entera Sms Gateway Firmware
Mitigation only