Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Linux Dash HIGH 7.8
CVE-2017-1000473

Linux Dash up to version v2 is vulnerable to multiple command injection vulnerabilities in the way module names are parsed and then executed resultin…

Fix: 2.0+
Fix from $1,950 2018-01-03
Debian Linux CRITICAL 9.8
CVE-2017-1000487EPSS 6%

Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.

Fix: 3.0.16+
Fix from $2,300 2018-01-03
Bu 3026 Firmware CRITICAL 9.8
CVE-2014-8389EPSS 51%

cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with…

No fix yet
Fix from $2,300 2017-12-28
Antiweb HIGH 8.8
CVE-2017-17888EPSS 28%

cgi-bin/write.cgi in Anti-Web through 3.8.7, as used on NetBiter / HMS, Ouman EH-net, Alliance System WS100 --> AWU 500, Sauter ERW100F001, Carlo Gav…

Fix: after 3.8.7
Fix from $1,950 2017-12-27
Wvbr0 Firmware CRITICAL 9.8
CVE-2017-17411EPSS 88%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to …

Fix: 1.0.41+
Fix from $2,300 2017-12-21
Epmp 1000 Firmware HIGH 8.8
CVE-2017-5255EPSS 75%

In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows an…

Fix: after 3.5
Fix from $1,950 2017-12-20
Zoom HIGH 8.8
CVE-2017-15049EPSS 17%

The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, …

Fix: 2.0.115900.1201+
Fix from $1,950 2017-12-19
Tl Wvr450l Firmware HIGH 8.8
CVE-2017-17757

TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of a…

No fix yet
Fix from $1,950 2017-12-19
Tl Wvr450l Firmware HIGH 8.8
CVE-2017-17758

TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of a…

No fix yet
Fix from $1,950 2017-12-19
Pr115 204 P Rs Firmware CRITICAL 9.8
CVE-2017-17105EPSS 85%

Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote comma…

No fix yet
Fix from $2,300 2017-12-19
Enterprise Linux HIGH 8.8
CVE-2017-15103EPSS 5%

A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted r…

Patch available
Fix from $1,950 2017-12-18
Qt CRITICAL 9.8
CVE-2017-10904

Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Fix: 5.9.0+
Fix from $2,300 2017-12-16
Ruby HIGH 8.8
CVE-2017-17405EPSS 74%

Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to…

Fix: after 2.4.2
Fix from $1,950 2017-12-15
Debian Linux HIGH 8.8
CVE-2017-16921EPSS 20%

In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged …

Patch available
Fix from $1,950 2017-12-08
Debian Linux CRITICAL 9.8
CVE-2017-17458EPSS 6%

In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a …

Fix: 4.4.1+
Fix from $2,300 2017-12-07
Artica Proxy CRITICAL 9.0
CVE-2017-17055EPSS 9%

Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack invol…

Fix: 3.06.112911+
Fix from $2,300 2017-12-07
Most CRITICAL 9.8
CVE-2016-1253

The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote …

Fix: 5.0.0a-2.2 / 5.0.0a-2.3+
Fix from $2,300 2017-12-05
Ptw Wms1 Firmware CRITICAL 9.8
CVE-2017-10902

PTW-WMS1 firmware version 2.000.012 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Mitigation only
Fix from $2,300 2017-12-01
Evince HIGH 7.8
CVE-2017-1000159

Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.

Fix: 3.25.91+
Fix from $1,950 2017-11-27
Gitphp CRITICAL 9.8
CVE-2017-1000214

GitPHP by xiphux is vulnerable to OS Command Injections

Patch available
Fix from $2,300 2017-11-27
Tl Wvr300 Firmware HIGH 8.8
CVE-2017-16957EPSS 6%

TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface …

No fix yet
Fix from $1,950 2017-11-27
Tl Wvr300 Firmware HIGH 8.8
CVE-2017-16958

TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bind…

No fix yet
Fix from $1,950 2017-11-27
Tl Er5510g HIGH 8.8
CVE-2017-16960

TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bind…

Mitigation only
Fix from $1,950 2017-11-27
Web Server CRITICAL 9.8
CVE-2017-16934EPSS 13%

The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?conten…

No fix yet
Fix from $2,300 2017-11-24
Ohcount CRITICAL 9.8
CVE-2017-16926EPSS 6%

Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can be exploited by an attacker …

No fix yet
Fix from $2,300 2017-11-22
Ac9 Firmware HIGH 8.8
CVE-2017-16923

Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac1…

No fix yet
Fix from $1,950 2017-11-21
Xrootd CRITICAL 9.8
CVE-2017-1000215EPSS 6%

ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution

Fix: after 4.6.0
Fix from $2,300 2017-11-17
Root HIGH 8.8
CVE-2017-1000203

ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution

Fix: after 6.9.03
Fix from $1,950 2017-11-17
I\, Librarian CRITICAL 9.8
CVE-2017-1000235

I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.

Fix: after 4.6
Fix from $2,300 2017-11-17
Pidusage CRITICAL 9.8
CVE-2017-1000220EPSS 5%

soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution

Fix: after 1.1.4
Fix from $2,300 2017-11-17