Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Egg Scripts CRITICAL 9.8
CVE-2018-3786EPSS 12%

A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line argument.

Fix: 2.8.1+
Fix from $2,300 2018-08-24
Wireless Appliance Firmware HIGH 8.8
CVE-2018-15481

Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices using firmware version 5.1.x before 5.1.1…

Fix: after 5.1.13
Fix from $1,950 2018-08-21
Actiontec T2200h Firmware HIGH 8.8
CVE-2018-15553

fileshare.cmd on Telus Actiontec T2200H T2200H-31.128L.03 devices allows OS Command Injection via shell metacharacters in the smbdUserid or smbdPassw…

Mitigation only
Fix from $1,950 2018-08-20
Git Dummy Commit CRITICAL 9.8
CVE-2018-3785

A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter.

Patch available
Fix from $2,300 2018-08-17
Application Policy Infrastructure Controller Enterprise Module HIGH 8.8
CVE-2018-0427EPSS 6%

A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to perf…

Mitigation only
Fix from $1,950 2018-08-15
Openemr HIGH 8.8
CVE-2018-15154EPSS 10%

OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a…

Fix: 5.0.1.4+
Fix from $1,950 2018-08-15
Openemr HIGH 8.8
CVE-2018-15155EPSS 10%

OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a…

Fix: 5.0.1.4+
Fix from $1,950 2018-08-15
Openemr HIGH 8.8
CVE-2018-15156EPSS 10%

OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a…

Fix: 5.0.1.4+
Fix from $1,950 2018-08-15
Openemr HIGH 8.8
CVE-2018-15153EPSS 62%

OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a…

Fix: 5.0.1.4+
Fix from $1,950 2018-08-15
Snc Eb600 Firmware HIGH 7.2
CVE-2018-3937EPSS 10%

An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1…

No fix yet
Fix from $1,950 2018-08-14
Nvrmini Firmware CRITICAL 9.8
CVE-2018-14933 KEVEPSS 95%

upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir c…

Mitigation only
Fix from $2,300 2018-08-04
Cloud CRITICAL 9.8
CVE-2018-14417EPSS 90%

A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not…

Fix: 4.0.3+
Fix from $2,300 2018-08-04
Ocsinventory Ng HIGH 8.8
CVE-2018-12483

OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analy…

No fix yet
Fix from $1,950 2018-08-04
Debian Linux HIGH 7.8
CVE-2018-10900EPSS 5%

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can b…

Fix: 1.2.6+
Fix from $1,950 2018-07-26
Cloudforms HIGH 7.8
CVE-2018-10905

CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an…

Mitigation only
Fix from $1,950 2018-07-24
Vbond Orchestrator HIGH 7.2
CVE-2018-0348

A vulnerability in the CLI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed …

Fix: 18.3.0+
Fix from $1,950 2018-07-18
Vbond Orchestrator CRITICAL 9.8
CVE-2018-0349

A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating s…

Fix: 18.3.0+
Fix from $2,300 2018-07-18
Ubuntu Linux CRITICAL 9.8
CVE-2018-14354EPSS 6%

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquo…

Patch available
Fix from $2,300 2018-07-17
Ubuntu Linux CRITICAL 9.8
CVE-2018-14357

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquo…

Patch available
Fix from $2,300 2018-07-17
Q\'center HIGH 7.2
CVE-2018-0707EPSS 59%

Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to…

Fix: after 1.7.1063
Fix from $1,950 2018-07-17
Q\'center HIGH 8.8
CVE-2018-0708EPSS 26%

Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run …

Fix: after 1.7.1063
Fix from $1,950 2018-07-17
Q\'center HIGH 8.8
CVE-2018-0709EPSS 14%

Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitr…

Fix: after 1.7.1063
Fix from $1,950 2018-07-17
Q\'center HIGH 8.8
CVE-2018-0710EPSS 14%

Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitra…

Fix: after 1.7.1063
Fix from $1,950 2018-07-17
Ip Phone Multiplatform Firmware HIGH 8.8
CVE-2018-0341EPSS 6%

A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11.2(1) could allow an authentic…

Mitigation only
Fix from $1,950 2018-07-16
Xiaomi R3p Firmware CRITICAL 9.8
CVE-2018-14010

OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15, and R3D…

Fix: 2.12.15 / 2.14.5+
Fix from $2,300 2018-07-15
Xiaomi R3d Firmware CRITICAL 9.8
CVE-2018-14060

OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D before 2.26.4 devices allows an a…

Fix: 2.26.4+
Fix from $2,300 2018-07-15
Dge 100 Firmware CRITICAL 9.8
CVE-2018-5553

The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.…

Fix: after 1.3384.00049.001
Fix from $2,300 2018-07-10
Node Macaddress CRITICAL 9.8
CVE-2018-13797EPSS 7%

The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather …

Fix: 0.2.9+
Fix from $2,300 2018-07-10
C1 Lite Firmware HIGH 7.2
CVE-2018-6831

The setSystemTime function in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI985…

Fix: after 2.82.2.33
Fix from $1,950 2018-07-09
Diqee360 Firmware HIGH 7.5
CVE-2018-10987

An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated remote code execution vulnerabi…

Mitigation only
Fix from $1,950 2018-07-05