Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Solo Access Point Firmware HIGH 8.8
CVE-2017-6230

Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated…

Mitigation only
Fix from $1,950 2018-02-14
Webaccess CRITICAL 9.8
CVE-2018-6911EPSS 13%

The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argume…

No fix yet
Fix from $2,300 2018-02-13
Misp HIGH 7.2
CVE-2018-6926

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linu…

Patch available
Fix from $1,950 2018-02-12
Squert CRITICAL 9.8
CVE-2018-1000042

Security Onion Solutions Squert version 1.3.0 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS …

Fix: after 1.6.7
Fix from $2,300 2018-02-09
Squert CRITICAL 9.8
CVE-2018-1000043

Security Onion Solutions Squert version 1.0.1 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS …

Fix: after 1.6.7
Fix from $2,300 2018-02-09
Openemr HIGH 8.8
CVE-2018-1000019

OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command injection by an authenticated a…

Patch available
Fix from $1,950 2018-02-09
Hdl Xr Firmware MEDIUM 6.8
CVE-2018-0512

Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands…

Fix: after 2.01
Fix from $1,600 2018-02-08
Mp Form Mail Cgi CRITICAL 9.8
CVE-2018-0514

MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Fix: after 2.0.13
Fix from $2,300 2018-02-08
Debian Linux MEDIUM 6.8
CVE-2018-6791

An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $(…

Fix: 5.12.0+
Fix from $1,600 2018-02-07
Emc Recoverpoint MEDIUM 6.7
CVE-2018-1184

An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint vers…

Fix: 5.0.1.3 / 5.1.1+
Fix from $1,600 2018-02-03
Emc Recoverpoint MEDIUM 6.7
CVE-2018-1185EPSS 6%

An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint vers…

Fix: 5.0.1.3 / 5.1.1+
Fix from $1,600 2018-02-03
Ib Wra150n Firmware HIGH 8.8
CVE-2018-6388EPSS 6%

iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharacters in …

No fix yet
Fix from $1,950 2018-01-29
Electrum HIGH 7.8
CVE-2018-6353

The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1) social-engineering attacks …

Fix: after 2.9.4
Fix from $1,950 2018-01-27
Nootka CRITICAL 9.8
CVE-2018-0506

Nootka 1.4.4 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Fix: after 1.4.4
Fix from $2,300 2018-01-26
Jenkins HIGH 8.8
CVE-2017-1000393

Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could configure a launch method called 'L…

Fix: after 2.83
Fix from $1,950 2018-01-26
Ec2 HIGH 8.8
CVE-2017-1000502

Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the m…

Fix: after 1.37
Fix from $1,950 2018-01-24
Electron HIGH 8.8
CVE-2018-1000006EPSS 85%

GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically E…

Fix: after 1.7.10
Fix from $1,950 2018-01-24
Enterprise Manager CRITICAL 9.8
CVE-2017-16608

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not…

Fix: 7.2.766+
Fix from $2,300 2018-01-23
Enterprise Manager CRITICAL 9.8
CVE-2017-17407

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager v7.2.699 build…

Mitigation only
Fix from $2,300 2018-01-23
Enterprise Manager HIGH 8.8
CVE-2017-16602

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build …

Mitigation only
Fix from $1,950 2018-01-23
Pfsense HIGH 8.8
CVE-2016-10709EPSS 34%

pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph param…

Fix: after 2.2.6
Fix from $1,950 2018-01-22
Debian Linux HIGH 7.8
CVE-2017-15108

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the …

Fix: after 0.17.0
Fix from $1,950 2018-01-20
Smart Protection Server CRITICAL 9.8
CVE-2017-14094EPSS 19%

A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command executio…

Fix: after 3.2
Fix from $2,300 2018-01-19
Commvault CRITICAL 9.8
CVE-2017-18044EPSS 70%

A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside t…

Fix: after 11.0
Fix from $2,300 2018-01-19
D9800 Firmware HIGH 8.8
CVE-2018-0099

A vulnerability in the web management GUI of the Cisco D9800 Network Transport Receiver could allow an authenticated, remote attacker to perform a co…

No fix yet
Fix from $1,950 2018-01-18
Staros MEDIUM 6.7
CVE-2018-0115

A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series routers could allow an authenticated, local attacker to exe…

Mitigation only
Fix from $1,600 2018-01-18
Dsl 2540u Firmware HIGH 8.8
CVE-2018-5371EPSS 42%

diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote…

No fix yet
Fix from $1,950 2018-01-12
Personal Cloud Firmware CRITICAL 9.8
CVE-2018-5347EPSS 54%

Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because…

No fix yet
Fix from $2,300 2018-01-12
Itguard Manager CRITICAL 9.8
CVE-2017-18025

cgi-bin/drknow.cgi in Innotube ITGuard-Manager 0.0.0.1 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the usern…

No fix yet
Fix from $2,300 2018-01-09
Xplico HIGH 8.8
CVE-2017-16666EPSS 80%

Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name of an uploaded PCAP file. N…

Fix: 1.2.1+
Fix from $1,950 2018-01-05