Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Windows Cpu CRITICAL 9.8
CVE-2017-1000219

npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user

No fix yet
Fix from $2,300 2017-11-17
Ip Phone 8800 Series Firmware MEDIUM 6.7
CVE-2017-12305

A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka …

Mitigation only
Fix from $1,600 2017-11-16
Couchdb HIGH 7.2
CVE-2017-12636EPSS 90%

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-leve…

Fix: 1.7.0+
Fix from $1,950 2017-11-14
Security Access Manager 9.0 Firmware HIGH 8.8
CVE-2017-1453

IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a spe…

Mitigation only
Fix from $1,950 2017-11-13
Backintime HIGH 7.8
CVE-2017-16667

backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to so…

Fix: 1.1.24+
Fix from $1,950 2017-11-08
Cacti HIGH 7.2
CVE-2017-16641

lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=s…

Patch available
Fix from $1,950 2017-11-07
Circle With Disney Firmware HIGH 8.8
CVE-2017-2917

An exploitable vulnerability exists in the notifications functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packet…

No fix yet
Fix from $1,950 2017-11-07
Circle With Disney Firmware HIGH 8.8
CVE-2017-2866

An exploitable vulnerability exists in the /api/CONFIG/backup functionality of Circle with Disney. Specially crafted network packets can cause an OS …

No fix yet
Fix from $1,950 2017-11-07
Circle With Disney Firmware HIGH 8.8
CVE-2017-2890

An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network …

Mitigation only
Fix from $1,950 2017-11-07
Unified Computing System Manager Firmware HIGH 7.8
CVE-2017-12243EPSS 77%

A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower…

Mitigation only
Fix from $1,950 2017-11-02
Foxit Reader HIGH 8.8
CVE-2017-10953

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is req…

Patch available
Fix from $1,950 2017-10-31
Clickshare Csm 1 Firmware HIGH 8.8
CVE-2017-9377

A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An a…

Fix: 1.7.0.3 / 1.10.0.10+
Fix from $1,950 2017-10-30
Debian Linux HIGH 7.8
CVE-2017-15924

In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration req…

Patch available
Fix from $1,950 2017-10-27
Fortiwlc HIGH 7.2
CVE-2017-7341

An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file m…

Fix: after 8.3.2
Fix from $1,950 2017-10-26
Data Protection Advisor HIGH 8.8
CVE-2017-10955EPSS 7%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication…

Mitigation only
Fix from $1,950 2017-10-19
Service Framework CRITICAL 9.8
CVE-2017-3761

The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this …

Patch available
Fix from $2,300 2017-10-17
Zonedirector Firmware HIGH 8.8
CVE-2017-6223

Ruckus Wireless Zone Director Controller firmware releases ZD9.9.x, ZD9.10.x, ZD9.13.0.x less than 9.13.0.0.232 contain OS Command Injection vulnerab…

Mitigation only
Fix from $1,950 2017-10-13
Zonedirector Firmware HIGH 8.8
CVE-2017-6224

Ruckus Wireless Zone Director Controller firmware releases ZD9.x, ZD10.0.0.x, ZD10.0.1.x (less than 10.0.1.0.17 MR1 release) and Ruckus Wireless Unle…

Mitigation only
Fix from $1,950 2017-10-13
Nbg6716 Firmware CRITICAL 9.8
CVE-2017-15226

Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because beginIndex and endIndex are used directly in a popen ca…

No fix yet
Fix from $2,300 2017-10-10
Debian Linux CRITICAL 9.8
CVE-2017-1000116EPSS 6%

Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.

Fix: 4.3+
Fix from $2,300 2017-10-05
Ucopia Wireless Appliance HIGH 8.2
CVE-2017-11322EPSS 5%

The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) meta…

Fix: after 5.1.7
Fix from $1,950 2017-10-03
Wireless Appliance HIGH 7.2
CVE-2017-11321EPSS 8%

The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admin' privileges via shell metac…

Fix: after 5.1.7
Fix from $1,950 2017-10-03
Git HIGH 8.8
CVE-2017-14867EPSS 36%

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support sub…

Fix: after 2.10.4
Fix from $1,950 2017-09-29
Asterisk Gui HIGH 8.8
CVE-2017-14001EPSS 6%

An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior. An OS command injec…

Fix: after 2.1.0
Fix from $1,950 2017-09-26
I Suite HIGH 8.1
CVE-2017-14705EPSS 7%

DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters can be inserted into the type…

Patch available
Fix from $1,950 2017-09-22
Smart Protection Server HIGH 8.8
CVE-2017-11395EPSS 14%

Command injection vulnerability in Trend Micro Smart Protection Server (Standalone) 3.1 and 3.2 server administration UI allows attackers with authen…

Patch available
Fix from $1,950 2017-09-22
Pydio CRITICAL 9.8
CVE-2015-3431

Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injecti…

Fix: after 6.0.6
Fix from $2,300 2017-09-19
Newsbeuter HIGH 8.8
CVE-2017-14500

Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsbeuter 0.3 through 2.9 allows …

Patch available
Fix from $1,950 2017-09-17
Terramaster Operating System CRITICAL 9.8
CVE-2017-9328EPSS 7%

Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as r…

Fix: after 3.0.33
Fix from $2,300 2017-09-15
Wlr 300 Nm Firmware MEDIUM 6.8
CVE-2017-10813

CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

Fix: after 1.90
Fix from $1,600 2017-09-15