Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Dir 850l Firmware CRITICAL 9.8
CVE-2017-14429

The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows …

No fix yet
Fix from $2,300 2017-09-13
Eyesofnetwork HIGH 7.2
CVE-2017-14405

The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote command execution via shell metacharacters in a hosts_cacti array parameter to modul…

No fix yet
Fix from $1,950 2017-09-13
Ios Xe MEDIUM 6.7
CVE-2017-6796

A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an authentica…

Mitigation only
Fix from $1,600 2017-09-07
Wifi Repeater Firmware HIGH 8.8
CVE-2017-13713EPSS 9%

T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user parameter to cgi-bin/webupg.

No fix yet
Fix from $1,950 2017-09-07
Opendreambox CRITICAL 9.8
CVE-2017-14135EPSS 22%

enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to execute arbitra…

No fix yet
Fix from $2,300 2017-09-04
Td5336 Firmware CRITICAL 9.8
CVE-2017-14127

Command Injection in the Ping Module in the Web Interface on Technicolor TD5336 OI_Fw_v7 devices allows remote attackers to execute arbitrary OS comm…

Mitigation only
Fix from $2,300 2017-09-04
Eyesofnetwork HIGH 8.8
CVE-2017-14118

In the EyesOfNetwork web interface (aka eonweb) 5.1-0, module\tool_all\tools\interface.php does not properly restrict exec calls, which allows remote…

No fix yet
Fix from $1,950 2017-09-03
Eyesofnetwork HIGH 8.8
CVE-2017-14119

In the EyesOfNetwork web interface (aka eonweb) 5.1-0, module\tool_all\tools\snmpwalk.php does not properly restrict popen calls, which allows remote…

No fix yet
Fix from $1,950 2017-09-03
Asterisk CRITICAL 9.8
CVE-2017-14100EPSS 15%

In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cer…

Patch available
Fix from $2,300 2017-09-02
Phpfilemanager HIGH 8.8
CVE-2015-5958EPSS 27%

phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.

No fix yet
Fix from $1,950 2017-08-31
Foxit Reader HIGH 8.8
CVE-2017-10951

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is req…

Mitigation only
Fix from $1,950 2017-08-29
Scr02hd Firmware CRITICAL 9.8
CVE-2017-10832

"Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Fix: after 1.0.3.1000
Fix from $2,300 2017-08-29
Bash HIGH 7.5
CVE-2016-0634EPSS 6%

The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in…

Patch available
Fix from $1,950 2017-08-28
Codiad CRITICAL 9.8
CVE-2017-11366EPSS 8%

components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded …

Fix: after 2.8.3
Fix from $2,300 2017-08-21
Wcr 1166ds Firmware MEDIUM 6.8
CVE-2017-10811

Buffalo WCR-1166DS devices with firmware 1.30 and earlier allow an attacker to execute arbitrary OS commands via unspecified vectors.

Mitigation only
Fix from $1,600 2017-08-18
Virtual Network Function Element Manager HIGH 8.1
CVE-2017-6710

A vulnerability in the Cisco Virtual Network Function (VNF) Element Manager could allow an authenticated, remote attacker to elevate privileges and r…

Fix: after 5.1.3
Fix from $1,950 2017-08-17
Office HIGH 7.8
CVE-2017-11150

Command injection vulnerability in Document.php in Synology Office 2.2.0-1502 and 2.2.1-1506 allows remote authenticated users to execute arbitrary c…

Mitigation only
Fix from $1,950 2017-08-14
Electron HIGH 8.1
CVE-2017-12581EPSS 7%

GitHub Electron before 1.6.8 allows remote command execution because of a nodeIntegration bypass vulnerability. This also affects all applications th…

Fix: after 1.6.7
Fix from $1,950 2017-08-06
Gigacc Office MEDIUM 5.5
CVE-2016-7844

GigaCC OFFICE ver.2.3 and earlier allows remote attackers to execute arbitrary OS commands via specially crafted mail template.

Fix: after 2.3
Fix from $1,600 2017-08-02
Wn Ax1167gr Firmware HIGH 8.8
CVE-2017-2281

WN-AX1167GR firmware version 3.00 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

Mitigation only
Fix from $1,950 2017-08-02
Deep Discovery Director CRITICAL 9.8
CVE-2017-11381

A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the p…

Patch available
Fix from $2,300 2017-08-01
Dpc3939 Firmware CRITICAL 9.8
CVE-2017-9483

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows Network Processor (NP) Linux users…

No fix yet
Fix from $2,300 2017-07-31
Appuse HIGH 7.8
CVE-2017-11566

AppUse 4.0 allows shell command injection via a proxy field.

Mitigation only
Fix from $1,950 2017-07-25
Bu 2015 Firmware CRITICAL 9.8
CVE-2015-2279EPSS 18%

cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows remote attackers to execute …

No fix yet
Fix from $2,300 2017-07-25
Skyipcam1620w Wireless N Mpeg4 3gpp Firmware HIGH 8.8
CVE-2015-2280EPSS 17%

snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote auth…

No fix yet
Fix from $1,950 2017-07-25
Residential Gateway Firmware CRITICAL 9.8
CVE-2017-11588

On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V…

Mitigation only
Fix from $2,300 2017-07-24
Wg C10 Firmware HIGH 7.2
CVE-2017-2275

WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

Fix: after 3.0.79
Fix from $1,950 2017-07-22
Load Balancer Adc HIGH 8.8
CVE-2017-6320EPSS 11%

A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1.006 (201…

Fix: after 6.0.1.006
Fix from $1,950 2017-07-18
Mq Appliance HIGH 8.8
CVE-2017-1318

IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command exec…

Mitigation only
Fix from $1,950 2017-07-18
Cobian Backup HIGH 8.1
CVE-2017-11318

Cobian Backup 11 client allows man-in-the-middle attackers to add and execute new backup tasks when the master server is spoofed. In addition, the at…

No fix yet
Fix from $1,950 2017-07-17