Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Disk Backup CRITICAL 9.8
CVE-2018-11143EPSS 37%

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46).

Fix: 4.0.3.1+
Fix from $2,300 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11144

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 2 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11145

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 3 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11146

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 4 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11147

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 5 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11148

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 6 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11149

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 7 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11150

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 8 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 7.2
CVE-2018-11151

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 9 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11152

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 10 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11153

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 11 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11154

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 12 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Pdf Image CRITICAL 9.8
CVE-2018-3757

Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.

Patch available
Fix from $2,300 2018-06-01
Pdfinfojs CRITICAL 9.8
CVE-2018-3746

The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim'…

Fix: after 0.3.6
Fix from $2,300 2018-06-01
Shell Quote CRITICAL 9.8
CVE-2016-10541

The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend o…

Fix: 1.6.1+
Fix from $2,300 2018-05-31
Kace System Management Appliance HIGH 8.8
CVE-2018-11132EPSS 18%

In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs da…

No fix yet
Fix from $1,950 2018-05-31
Kace System Management Appliance CRITICAL 9.8
CVE-2018-11138 KEVEPSS 92%

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be a…

Mitigation only
Fix from $2,300 2018-05-31
Kace System Management Appliance HIGH 8.8
CVE-2018-11139EPSS 43%

The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and…

No fix yet
Fix from $1,950 2018-05-31
Recoverpoint CRITICAL 9.8
CVE-2018-1235EPSS 43%

Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unaut…

Fix: 5.1.1.3 / 5.1.2+
Fix from $2,300 2018-05-29
Recoverpoint MEDIUM 6.5
CVE-2018-1242

Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contains a command injection vulnerability in the B…

Fix: 5.1.1.3 / 5.1.2+
Fix from $1,600 2018-05-29
Email Encryption Gateway HIGH 8.8
CVE-2018-10354EPSS 13%

A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbit…

Fix: after 5.5
Fix from $1,950 2018-05-23
Connect CRITICAL 9.1
CVE-2018-4923EPSS 9%

Adobe Connect versions 9.7 and earlier have an exploitable OS Command Injection. Successful exploitation could lead to arbitrary file deletion.

Fix: after 9.7
Fix from $2,300 2018-05-19
Dreamweaver CRITICAL 9.8
CVE-2018-4924EPSS 14%

Adobe Dreamweaver CC versions 18.0 and earlier have an OS Command Injection vulnerability. Successful exploitation could lead to arbitrary code execu…

Fix: after 18.0
Fix from $2,300 2018-05-19
Dir 550a Firmware HIGH 8.8
CVE-2018-10967

On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be e…

Fix: after 2.10kr
Fix from $1,950 2018-05-18
Fl Switch 3005 Firmware CRITICAL 9.1
CVE-2018-10730

All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection.

Fix: after 1.33
Fix from $2,300 2018-05-17
Fedora HIGH 7.5
CVE-2018-1111EPSS 98%

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integratio…

No fix yet
Fix from $1,950 2018-05-17
Enterprise Nfv Infrastructure Software HIGH 8.8
CVE-2018-0279

A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote…

Fix: 3.6.3+
Fix from $1,950 2018-05-17
Network Functions Virtualization Infrastructure MEDIUM 6.7
CVE-2018-0324

A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to p…

Mitigation only
Fix from $1,600 2018-05-17
Edr 810 Firmware HIGH 8.8
CVE-2017-12120

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…

No fix yet
Fix from $1,950 2018-05-14
Edr 810 Firmware HIGH 8.8
CVE-2017-12121

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…

No fix yet
Fix from $1,950 2018-05-14