Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-11143EPSS 37%
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46).
Disk Backup
4.0.3.1+
HIGH 8.8
CVE-2018-11144
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 2 of 46).
Disk Backup
4.0.3.1+
HIGH 8.8
CVE-2018-11145
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 3 of 46).
Disk Backup
4.0.3.1+
HIGH 8.8
CVE-2018-11146
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 4 of 46).
Disk Backup
4.0.3.1+
HIGH 8.8
CVE-2018-11147
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 5 of 46).
Disk Backup
4.0.3.1+
HIGH 8.8
CVE-2018-11148
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 6 of 46).
Disk Backup
4.0.3.1+
HIGH 8.8
CVE-2018-11149
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 7 of 46).
Disk Backup
4.0.3.1+
HIGH 8.8
CVE-2018-11150
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 8 of 46).
Disk Backup
4.0.3.1+
HIGH 7.2
CVE-2018-11151
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 9 of 46).
Disk Backup
4.0.3.1+
HIGH 8.8
CVE-2018-11152
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 10 of 46).
Disk Backup
4.0.3.1+
HIGH 8.8
CVE-2018-11153
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 11 of 46).
Disk Backup
4.0.3.1+
HIGH 8.8
CVE-2018-11154
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 12 of 46).
Disk Backup
4.0.3.1+
CRITICAL 9.8
CVE-2018-3757
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.
Pdf Image
Patch available
CRITICAL 9.8
CVE-2018-3746
The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim'…
Pdfinfojs
after 0.3.6
CRITICAL 9.8
CVE-2016-10541
The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend o…
Shell Quote
1.6.1+
HIGH 8.8
CVE-2018-11132EPSS 18%
In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs da…
Kace System Management Appliance
No fix yet
CRITICAL 9.8
CVE-2018-11138 KEVEPSS 92%
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be a…
Kace System Management Appliance
Mitigation only
HIGH 8.8
CVE-2018-11139EPSS 43%
The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and…
Kace System Management Appliance
No fix yet
CRITICAL 9.8
CVE-2018-1235EPSS 43%
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unaut…
Recoverpoint
5.1.1.3 / 5.1.2+
MEDIUM 6.5
CVE-2018-1242
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contains a command injection vulnerability in the B…
Recoverpoint
5.1.1.3 / 5.1.2+
HIGH 8.8
CVE-2018-10354EPSS 13%
A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbit…
Email Encryption Gateway
after 5.5
CRITICAL 9.1
CVE-2018-4923EPSS 9%
Adobe Connect versions 9.7 and earlier have an exploitable OS Command Injection. Successful exploitation could lead to arbitrary file deletion.
Connect
after 9.7
CRITICAL 9.8
CVE-2018-4924EPSS 14%
Adobe Dreamweaver CC versions 18.0 and earlier have an OS Command Injection vulnerability. Successful exploitation could lead to arbitrary code execu…
Dreamweaver
after 18.0
HIGH 8.8
CVE-2018-10967
On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be e…
Dir 550a Firmware
after 2.10kr
CRITICAL 9.1
CVE-2018-10730
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection.
Fl Switch 3005 Firmware
after 1.33
HIGH 7.5
CVE-2018-1111EPSS 98%
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integratio…
Fedora
No fix yet
HIGH 8.8
CVE-2018-0279
A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote…
Enterprise Nfv Infrastructure Software
3.6.3+
MEDIUM 6.7
CVE-2018-0324
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to p…
Network Functions Virtualization Infrastructure
Mitigation only
HIGH 8.8
CVE-2017-12120
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…
Edr 810 Firmware
No fix yet
HIGH 8.8
CVE-2017-12121
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…
Edr 810 Firmware
No fix yet