Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Edr 810 Firmware HIGH 8.8
CVE-2017-12125

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…

No fix yet
Fix from $1,950 2018-05-14
Edr 810 Firmware HIGH 8.8
CVE-2017-14432

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…

No fix yet
Fix from $1,950 2018-05-14
Edr 810 Firmware HIGH 8.8
CVE-2017-14433

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…

No fix yet
Fix from $1,950 2018-05-14
Edr 810 Firmware HIGH 8.8
CVE-2017-14434

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…

No fix yet
Fix from $1,950 2018-05-14
Sd 320an Firmware HIGH 7.4
CVE-2018-6021

Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call parameter that is not properly san…

Fix: after 2.01
Fix from $1,950 2018-05-09
Mysql Multi Master Replication Manager CRITICAL 9.8
CVE-2017-14474EPSS 6%

In the MMM::Agent::Helpers::_execute function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1, a specially crafted MMM protocol mess…

No fix yet
Fix from $2,300 2018-05-09
Mysql Multi Master Replication Manager CRITICAL 9.8
CVE-2017-14475EPSS 6%

In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafte…

No fix yet
Fix from $2,300 2018-05-09
Mysql Multi Master Replication Manager CRITICAL 9.8
CVE-2017-14476EPSS 6%

In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially craf…

No fix yet
Fix from $2,300 2018-05-09
Mysql Multi Master Replication Manager CRITICAL 9.8
CVE-2017-14477EPSS 6%

In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially craf…

No fix yet
Fix from $2,300 2018-05-09
Mysql Multi Master Replication Manager CRITICAL 9.8
CVE-2017-14478EPSS 6%

In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially craf…

No fix yet
Fix from $2,300 2018-05-09
Mysql Multi Master Replication Manager CRITICAL 9.8
CVE-2017-14479EPSS 6%

In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially cr…

No fix yet
Fix from $2,300 2018-05-09
Mysql Multi Master Replication Manager CRITICAL 9.8
CVE-2017-14480EPSS 6%

In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially cr…

No fix yet
Fix from $2,300 2018-05-09
Mysql Multi Master Replication Manager CRITICAL 9.8
CVE-2017-14481EPSS 6%

In the MMM::Agent::Helpers::Network::send_arp function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially cr…

No fix yet
Fix from $2,300 2018-05-09
Vgo Firmware HIGH 8.8
CVE-2018-8866

In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker on an adjacent network could perform command injection.

Fix: 3.0.3.52164+
Fix from $1,950 2018-05-09
Emc Unity Operating Environment HIGH 7.2
CVE-2018-1239

Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are affected by multiple OS command injection vulnerabilities. A remote …

Fix: 4.3.0.1522077968+
Fix from $1,950 2018-05-08
Gpon Router Firmware CRITICAL 9.8
CVE-2018-10562 KEVEPSS 100%

An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponFo…

Mitigation only
Fix from $2,300 2018-05-04
Dcs 5009 Firmware HIGH 8.8
CVE-2017-17020EPSS 15%

On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware…

Fix: after 1.14.09
Fix from $1,950 2018-05-01
Dir 615 Firmware HIGH 7.2
CVE-2018-10431

D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen.

No fix yet
Fix from $1,950 2018-04-26
Debian Linux HIGH 7.8
CVE-2018-3836

An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argumen…

No fix yet
Fix from $1,950 2018-04-24
N750 Firmware CRITICAL 9.8
CVE-2018-1143EPSS 55%

A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to two…

No fix yet
Fix from $2,300 2018-04-19
N750 Firmware CRITICAL 9.8
CVE-2018-1144EPSS 7%

A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to pro…

No fix yet
Fix from $2,300 2018-04-19
Spotify HIGH 8.8
CVE-2018-1167

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336. User interaction…

Mitigation only
Fix from $1,950 2018-04-19
Nagios Xi HIGH 8.8
CVE-2018-8735EPSS 64%

Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the t…

Fix: 5.4.13+
Fix from $1,950 2018-04-18
Awk 3131a Firmware CRITICAL 9.8
CVE-2017-14459EPSS 13%

An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11…

Mitigation only
Fix from $2,300 2018-04-11
Lxr CRITICAL 9.8
CVE-2018-0545

LXR version 1.0.0 to 2.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Fix: after 2.3.0
Fix from $2,300 2018-04-09
Wzr 1750dhp2 Firmware HIGH 8.8
CVE-2018-0556

Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

Fix: after 2.30
Fix from $1,950 2018-04-09
Rt Ac66u Firmware CRITICAL 9.8
CVE-2018-9285

Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.38…

Fix: 3.0.0.4.382.39935 / 3.0.0.4.384.10007+
Fix from $2,300 2018-04-04
Ios Xe HIGH 7.8
CVE-2018-0194

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into th…

Fix: 16.3.1+
Fix from $1,950 2018-04-02
Ios Xe HIGH 7.8
CVE-2018-0193

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into th…

Fix: 16.3.1+
Fix from $1,950 2018-03-28
Ios Xe HIGH 7.8
CVE-2018-0176

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Lin…

Mitigation only
Fix from $1,950 2018-03-28