Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Ios Xe HIGH 7.8
CVE-2018-0182

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into th…

Fix: 16.3.1+
Fix from $1,950 2018-03-28
Ios Xe MEDIUM 6.7
CVE-2018-0183

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell …

Fix: 3.13.0as / 3.13.2as+
Fix from $1,600 2018-03-28
Ios Xe MEDIUM 6.7
CVE-2018-0184

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell …

Fix: 3.8.6e / 3.13.9s+
Fix from $1,600 2018-03-28
Ios Xe HIGH 7.8
CVE-2018-0185

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into th…

Fix: 16.3.1+
Fix from $1,950 2018-03-28
iOS HIGH 7.8
CVE-2018-0169

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Lin…

Mitigation only
Fix from $1,950 2018-03-28
Emc Scaleio HIGH 7.5
CVE-2018-1238

Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA). This component is used for c…

Fix: 2.5+
Fix from $1,950 2018-03-27
Qqq Systems CRITICAL 9.8
CVE-2018-0539

QQQ SYSTEMS version 2.24 allows an attacker to execute arbitrary commands via unspecified vectors.

No fix yet
Fix from $2,300 2018-03-22
Open Build Service HIGH 8.8
CVE-2011-3178

In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to e…

Fix: 2.3.0+
Fix from $1,950 2018-03-20
Smart Protection Server CRITICAL 9.8
CVE-2018-6231EPSS 7%

A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could …

Fix: after 3.3
Fix from $2,300 2018-03-15
Email Encryption Gateway HIGH 7.8
CVE-2018-6222

Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to exe…

Patch available
Fix from $1,950 2018-03-15
Wxr 1900dhp2 Firmware HIGH 8.8
CVE-2018-0523

Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

Fix: after 2.48
Fix from $1,950 2018-03-09
Manageengine Applications Manager CRITICAL 9.8
CVE-2018-7890EPSS 79%

A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredent…

Fix: 13.6+
Fix from $2,300 2018-03-08
Media Streaming Add On CRITICAL 9.8
CVE-2017-7640

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against th…

Fix: after 430.1.2.0
Fix from $2,300 2018-03-08
Identity Services Engine MEDIUM 6.7
CVE-2018-0221

A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command…

Mitigation only
Fix from $1,600 2018-03-08
Staros MEDIUM 6.7
CVE-2018-0224

A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, …

Mitigation only
Fix from $1,600 2018-03-08
Identity Services Engine MEDIUM 5.3
CVE-2018-0214

A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary com…

Mitigation only
Fix from $1,600 2018-03-08
Asr 5000 Firmware MEDIUM 6.7
CVE-2018-0217

A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, …

Mitigation only
Fix from $1,600 2018-03-08
Electron HIGH 8.8
CVE-2018-1000118

Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command e…

Fix: after 1.8.1
Fix from $1,950 2018-03-07
Dir 860l Firmware CRITICAL 9.8
CVE-2018-6530 KEVEPSS 97%

OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions…

Fix: after 1.12b04
Fix from $2,300 2018-03-06
Clipbucket CRITICAL 9.8
CVE-2018-7664

An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacters in the file_name parameter …

Fix: after 4.0.0
Fix from $2,300 2018-03-05
Amazon Music HIGH 8.8
CVE-2018-1169

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User interaction …

Mitigation only
Fix from $1,950 2018-03-02
Obs Service Source Validator HIGH 7.8
CVE-2017-9274

A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files w…

Fix: 0.7+
Fix from $1,950 2018-03-01
Control Panel HIGH 8.8
CVE-2015-4117EPSS 11%

Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter …

Fix: 0.9.8-14+
Fix from $1,950 2018-02-28
Bigfix Platform HIGH 8.8
CVE-2016-0291

IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report s…

Fix: 9.1.8 / 9.2.8+
Fix from $1,950 2018-02-28
Cms Made Simple HIGH 7.5
CVE-2018-7448EPSS 13%

Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrar…

No fix yet
Fix from $1,950 2018-02-26
Debian Linux CRITICAL 9.8
CVE-2018-7440

An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot roo…

Fix: after 1.75.3
Fix from $2,300 2018-02-23
Xperience HIGH 7.2
CVE-2018-7046EPSS 5%

Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a …

Fix: after 11.0
Fix from $1,950 2018-02-20
Go HIGH 8.8
CVE-2018-7187EPSS 63%

The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks fo…

Fix: 1.9.5 / 1.10.1+
Fix from $1,950 2018-02-16
Trixbox HIGH 8.8
CVE-2017-14535EPSS 50%

trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.

No fix yet
Fix from $1,950 2018-02-16
R500 Firmware HIGH 8.8
CVE-2017-6229

Ruckus Networks Unleashed AP firmware releases before 200.6.10.1.x and Ruckus Networks Zone Director firmware releases 10.1.0.0.x, 9.10.2.0.x, 9.12.3…

Fix: 200.6.10.1.0+
Fix from $1,950 2018-02-14