Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Product Information Management CRITICAL 9.8
CVE-2017-1000009

Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.

Patch available
Fix from $2,300 2017-07-17
Advanced Threat Defense CRITICAL 9.8
CVE-2017-4053

Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users …

Patch available
Fix from $2,300 2017-07-12
Nfsen CRITICAL 9.9
CVE-2017-7175EPSS 7%

NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom outp…

Fix: after 1.3.7
Fix from $2,300 2017-07-10
Hem Gw16a Firmware CRITICAL 9.8
CVE-2017-2237

Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allo…

Fix: after 1.2.0
Fix from $2,300 2017-07-07
Home Spot Cube 2 Firmware HIGH 8.0
CVE-2017-2183

HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via Clock Settings.

Mitigation only
Fix from $1,950 2017-07-07
Home Spot Cube 2 Firmware HIGH 8.8
CVE-2017-2185

HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via WebUI.

Mitigation only
Fix from $1,950 2017-07-07
Staros HIGH 8.2
CVE-2017-6707

A vulnerability in the CLI command-parsing code of the Cisco StarOS operating system for Cisco ASR 5000 Series 11.0 through 21.0, 5500 Series, and 57…

Mitigation only
Fix from $1,950 2017-07-06
Elastic Services Controller HIGH 8.8
CVE-2017-6712

A vulnerability in certain commands of Cisco Elastic Services Controller could allow an authenticated, remote attacker to elevate privileges to root …

Mitigation only
Fix from $1,950 2017-07-06
Ultra Services Framework Staging Server CRITICAL 9.8
CVE-2017-6714

A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to execute arb…

Fix: after 5.0.2
Fix from $2,300 2017-07-06
Security Guardium CRITICAL 9.9
CVE-2017-1253

IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted re…

Mitigation only
Fix from $2,300 2017-07-05
Rut900 Firmware CRITICAL 9.8
CVE-2017-8116

The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary…

Fix: after 00.03.265
Fix from $2,300 2017-07-03
C1 Indoor Hd Camera Firmware HIGH 8.8
CVE-2017-2844

In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a …

Mitigation only
Fix from $1,950 2017-06-29
C1 Indoor Hd Camera Firmware HIGH 8.8
CVE-2017-2845EPSS 7%

An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firm…

Mitigation only
Fix from $1,950 2017-06-29
C1 Indoor Hd Camera Firmware HIGH 8.8
CVE-2017-2846

In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a …

Mitigation only
Fix from $1,950 2017-06-29
C1 Indoor Hd Camera Firmware HIGH 8.8
CVE-2017-2847

In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a …

Mitigation only
Fix from $1,950 2017-06-29
C1 Indoor Hd Camera Firmware HIGH 8.8
CVE-2017-2848

In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a …

Mitigation only
Fix from $1,950 2017-06-29
C1 Indoor Hd Camera Firmware HIGH 8.8
CVE-2017-2849

In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a …

Mitigation only
Fix from $1,950 2017-06-29
C1 Indoor Hd Camera Firmware HIGH 8.8
CVE-2017-2850

In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a …

Mitigation only
Fix from $1,950 2017-06-29
C1 Indoor Hd Camera Firmware HIGH 8.8
CVE-2017-2841EPSS 6%

An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firm…

Mitigation only
Fix from $1,950 2017-06-27
C1 Indoor Hd Camera Firmware HIGH 8.8
CVE-2017-2842

In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for …

Mitigation only
Fix from $1,950 2017-06-27
C1 Indoor Hd Camera Firmware HIGH 8.8
CVE-2017-2843

In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for …

Mitigation only
Fix from $1,950 2017-06-27
Network Camera Ib8369 Firmware CRITICAL 9.8
CVE-2017-9828EPSS 82%

'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remo…

Mitigation only
Fix from $2,300 2017-06-23
C1 Indoor Hd Camera Firmware HIGH 8.8
CVE-2017-2827EPSS 8%

An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firm…

No fix yet
Fix from $1,950 2017-06-21
C1 Indoor Hd Camera Firmware HIGH 8.8
CVE-2017-2828EPSS 8%

An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firm…

No fix yet
Fix from $1,950 2017-06-21
Ipfire HIGH 8.8
CVE-2017-9757EPSS 39%

IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell. This can be exploited…

Fix: after 2.19
Fix from $1,950 2017-06-19
Spip CRITICAL 9.8
CVE-2017-9736

SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote …

Patch available
Fix from $2,300 2017-06-17
Elastic Services Controller HIGH 8.8
CVE-2017-6682

A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the…

Mitigation only
Fix from $1,950 2017-06-13
Elastic Services Controller HIGH 8.8
CVE-2017-6683EPSS 6%

A vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrar…

Mitigation only
Fix from $1,950 2017-06-13
Wfs Sr01 Firmware CRITICAL 9.8
CVE-2016-7806

I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors.

Fix: after 1.10
Fix from $2,300 2017-06-09
Ts Wrlp Firmware HIGH 7.2
CVE-2016-7819

I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator r…

Fix: after 1.01.02
Fix from $1,950 2017-06-09