Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Zabbix HIGH 8.1
CVE-2017-2824EPSS 26%

An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets ca…

No fix yet
Fix from $1,950 2017-05-24
Ip Camera G Cam Efd 2250 Firmware CRITICAL 9.8
CVE-2017-5173EPSS 30%

An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An i…

No fix yet
Fix from $2,300 2017-05-19
Irods CRITICAL 9.8
CVE-2017-8799

Untrusted input execution via igetwild in all iRODS versions before 4.1.11 and 4.2.1 allows other iRODS users (potentially anonymous) to execute remo…

Fix: after 4.1.10
Fix from $2,300 2017-05-05
Sourcetree CRITICAL 9.8
CVE-2017-8768EPSS 8%

Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS co…

Fix: after 2.5c
Fix from $2,300 2017-05-04
Tuleap HIGH 8.8
CVE-2017-7981EPSS 16%

Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the pro…

Fix: 9.7+
Fix from $1,950 2017-04-29
Wnc01wh Firmware MEDIUM 6.8
CVE-2017-2152

WNC01WH firmware 1.0.0.9 and earlier allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.

Fix: after 1.0.0.9
Fix from $1,600 2017-04-28
Ts Ptcam\/poe Firmware HIGH 8.8
CVE-2017-2112

TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.…

Fix: after 1.18
Fix from $1,950 2017-04-28
Introduction To Safe Website Operation HIGH 8.8
CVE-2017-2128

Security guide for website operators allows remote attackers to execute arbitrary OS commands via specially crafted saved data.

Mitigation only
Fix from $1,950 2017-04-28
Wn G300r3 Firmware HIGH 7.2
CVE-2017-2141

WN-G300R3 firmware 1.03 and earlier allows attackers with administrator rights to execute arbitrary OS commands via unspecified vectors.

Fix: after 1.03
Fix from $1,950 2017-04-28
Smalruby Editor CRITICAL 9.8
CVE-2017-2096EPSS 6%

smalruby-editor v0.4.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Fix: after 0.4.0
Fix from $2,300 2017-04-28
C2 Firmware CRITICAL 9.9
CVE-2017-8220EPSS 37%

TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by plac…

Fix: after 0.9.1_4.2_v0032.0_build_160706
Fix from $2,300 2017-04-25
Weblogic Server HIGH 7.4
CVE-2017-3506 KEVEPSS 96%

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected …

Patch available
Fix from $1,950 2017-04-24
Appliance CRITICAL 9.8
CVE-2017-8051EPSS 16%

Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of …

Patch available
Fix from $2,300 2017-04-21
Awk 3131a Firmware CRITICAL 9.1
CVE-2016-8721

An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running…

No fix yet
Fix from $2,300 2017-04-20
Proxifier HIGH 7.8
CVE-2017-7690

Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary with a Trojan horse program.

Fix: 2.19.2+
Fix from $1,950 2017-04-14
Web Gateway HIGH 8.8
CVE-2016-5313

Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.

Fix: after 5.2.2
Fix from $1,950 2017-04-12
Unified Computing System HIGH 7.8
CVE-2017-6597

A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewa…

Mitigation only
Fix from $1,950 2017-04-07
Firepower Extensible Operating System HIGH 7.8
CVE-2017-6600

A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisc…

Mitigation only
Fix from $1,950 2017-04-07
Firepower Extensible Operating System HIGH 7.1
CVE-2017-6601

A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisc…

Mitigation only
Fix from $1,950 2017-04-07
Ios Xe MEDIUM 6.4
CVE-2017-6606

A vulnerability in a startup script of Cisco IOS XE Software could allow an unauthenticated attacker with physical access to the targeted system to e…

Mitigation only
Fix from $1,600 2017-04-07
Textract HIGH 7.8
CVE-2016-10320

textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web appl…

Fix: after 1.4.0
Fix from $1,950 2017-04-06
Emg2926 Firmware HIGH 8.8
CVE-2017-6884 KEVEPSS 38%

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the …

Mitigation only
Fix from $1,950 2017-04-06
Advanced Secure Gateway HIGH 7.2
CVE-2016-9091EPSS 10%

Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command inje…

Fix: after 6.6.5.2
Fix from $1,950 2017-04-05
Groupware HIGH 8.8
CVE-2017-7413EPSS 40%

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenti…

Fix: after 5.2.17
Fix from $1,950 2017-04-04
Groupware HIGH 7.5
CVE-2017-7414

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP featur…

Mitigation only
Fix from $1,950 2017-04-04
Web Appliance CRITICAL 9.8
CVE-2017-6182EPSS 17%

In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote comman…

Fix: after 4.3.1.1
Fix from $2,300 2017-03-30
Fedora HIGH 7.8
CVE-2017-5330

ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications.

Fix: after 16.12
Fix from $1,950 2017-03-27
Eonweb HIGH 8.8
CVE-2017-6087EPSS 7%

EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] p…

Fix: after 5.0-0
Fix from $1,950 2017-03-24
Qts CRITICAL 9.8
CVE-2017-6359EPSS 27%

QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.

Fix: after 4.2.4
Fix from $2,300 2017-03-23
Qts CRITICAL 9.8
CVE-2017-6360EPSS 66%

QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.

Fix: after 4.2.4
Fix from $2,300 2017-03-23