Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2017-12125 An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P… Edr 810 Firmware No fix yet Fix from $1,9502018-05-14 HIGH 8.8 CVE-2017-14432 An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P… Edr 810 Firmware No fix yet Fix from $1,9502018-05-14 HIGH 8.8 CVE-2017-14433 An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P… Edr 810 Firmware No fix yet Fix from $1,9502018-05-14 HIGH 8.8 CVE-2017-14434 An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P… Edr 810 Firmware No fix yet Fix from $1,9502018-05-14 HIGH 7.4 CVE-2018-6021 Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call parameter that is not properly san… Sd 320an Firmware after 2.01 Fix from $1,9502018-05-09 CRITICAL 9.8 CVE-2017-14474EPSS 6% In the MMM::Agent::Helpers::_execute function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1, a specially crafted MMM protocol mess… Mysql Multi Master Replication Manager No fix yet Fix from $2,3002018-05-09 CRITICAL 9.8 CVE-2017-14475EPSS 6% In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafte… Mysql Multi Master Replication Manager No fix yet Fix from $2,3002018-05-09 CRITICAL 9.8 CVE-2017-14476EPSS 6% In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially craf… Mysql Multi Master Replication Manager No fix yet Fix from $2,3002018-05-09 CRITICAL 9.8 CVE-2017-14477EPSS 6% In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially craf… Mysql Multi Master Replication Manager No fix yet Fix from $2,3002018-05-09 CRITICAL 9.8 CVE-2017-14478EPSS 6% In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially craf… Mysql Multi Master Replication Manager No fix yet Fix from $2,3002018-05-09 CRITICAL 9.8 CVE-2017-14479EPSS 6% In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially cr… Mysql Multi Master Replication Manager No fix yet Fix from $2,3002018-05-09 CRITICAL 9.8 CVE-2017-14480EPSS 6% In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially cr… Mysql Multi Master Replication Manager No fix yet Fix from $2,3002018-05-09 CRITICAL 9.8 CVE-2017-14481EPSS 6% In the MMM::Agent::Helpers::Network::send_arp function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially cr… Mysql Multi Master Replication Manager No fix yet Fix from $2,3002018-05-09 HIGH 8.8 CVE-2018-8866 In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker on an adjacent network could perform command injection. Vgo Firmware 3.0.3.52164+ Fix from $1,9502018-05-09 HIGH 7.2 CVE-2018-1239 Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are affected by multiple OS command injection vulnerabilities. A remote … Emc Unity Operating Environment 4.3.0.1522077968+ Fix from $1,9502018-05-08 CRITICAL 9.8 CVE-2018-10562 KEVEPSS 100% An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponFo… Gpon Router Firmware Mitigation only Fix from $2,3002018-05-04 HIGH 8.8 CVE-2017-17020EPSS 15% On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware… Dcs 5009 Firmware after 1.14.09 Fix from $1,9502018-05-01 HIGH 7.2 CVE-2018-10431 D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen. Dir 615 Firmware No fix yet Fix from $1,9502018-04-26 HIGH 7.8 CVE-2018-3836 An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argumen… Debian Linux No fix yet Fix from $1,9502018-04-24 CRITICAL 9.8 CVE-2018-1143EPSS 55% A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to two… N750 Firmware No fix yet Fix from $2,3002018-04-19 CRITICAL 9.8 CVE-2018-1144EPSS 7% A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to pro… N750 Firmware No fix yet Fix from $2,3002018-04-19 HIGH 8.8 CVE-2018-1167 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336. User interaction… Spotify Mitigation only Fix from $1,9502018-04-19 HIGH 8.8 CVE-2018-8735EPSS 64% Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the t… Nagios Xi 5.4.13+ Fix from $1,9502018-04-18 CRITICAL 9.8 CVE-2017-14459EPSS 13% An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11… Awk 3131a Firmware Mitigation only Fix from $2,3002018-04-11 CRITICAL 9.8 CVE-2018-0545 LXR version 1.0.0 to 2.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors. Lxr after 2.3.0 Fix from $2,3002018-04-09 HIGH 8.8 CVE-2018-0556 Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. Wzr 1750dhp2 Firmware after 2.30 Fix from $1,9502018-04-09 CRITICAL 9.8 CVE-2018-9285 Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.38… Rt Ac66u Firmware 3.0.0.4.382.39935 / 3.0.0.4.384.10007+ Fix from $2,3002018-04-04 HIGH 7.8 CVE-2018-0194 Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into th… Ios Xe 16.3.1+ Fix from $1,9502018-04-02 HIGH 7.8 CVE-2018-0193 Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into th… Ios Xe 16.3.1+ Fix from $1,9502018-03-28 HIGH 7.8 CVE-2018-0176 Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Lin… Ios Xe Mitigation only Fix from $1,9502018-03-28