Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2018-0182
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into th…
Ios Xe
16.3.1+
MEDIUM 6.7
CVE-2018-0183
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell …
Ios Xe
3.13.0as / 3.13.2as+
MEDIUM 6.7
CVE-2018-0184
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell …
Ios Xe
3.8.6e / 3.13.9s+
HIGH 7.8
CVE-2018-0185
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into th…
Ios Xe
16.3.1+
HIGH 7.8
CVE-2018-0169
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Lin…
iOS
Mitigation only
HIGH 7.5
CVE-2018-1238
Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA). This component is used for c…
Emc Scaleio
2.5+
CRITICAL 9.8
CVE-2018-0539
QQQ SYSTEMS version 2.24 allows an attacker to execute arbitrary commands via unspecified vectors.
Qqq Systems
No fix yet
HIGH 8.8
CVE-2011-3178
In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to e…
Open Build Service
2.3.0+
CRITICAL 9.8
CVE-2018-6231EPSS 7%
A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could …
Smart Protection Server
after 3.3
HIGH 7.8
CVE-2018-6222
Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to exe…
Email Encryption Gateway
Patch available
HIGH 8.8
CVE-2018-0523
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
Wxr 1900dhp2 Firmware
after 2.48
CRITICAL 9.8
CVE-2018-7890EPSS 79%
A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredent…
Manageengine Applications Manager
13.6+
CRITICAL 9.8
CVE-2017-7640
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against th…
Media Streaming Add On
after 430.1.2.0
MEDIUM 6.7
CVE-2018-0221
A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command…
Identity Services Engine
Mitigation only
MEDIUM 6.7
CVE-2018-0224
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, …
Staros
Mitigation only
MEDIUM 5.3
CVE-2018-0214
A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary com…
Identity Services Engine
Mitigation only
MEDIUM 6.7
CVE-2018-0217
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, …
Asr 5000 Firmware
Mitigation only
HIGH 8.8
CVE-2018-1000118
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command e…
Electron
after 1.8.1
CRITICAL 9.8
CVE-2018-6530 KEVEPSS 97%
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions…
Dir 860l Firmware
after 1.12b04
CRITICAL 9.8
CVE-2018-7664
An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacters in the file_name parameter …
Clipbucket
after 4.0.0
HIGH 8.8
CVE-2018-1169
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User interaction …
Amazon Music
Mitigation only
HIGH 7.8
CVE-2017-9274
A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files w…
Obs Service Source Validator
0.7+
HIGH 8.8
CVE-2015-4117EPSS 11%
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter …
Control Panel
0.9.8-14+
HIGH 8.8
CVE-2016-0291
IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report s…
Bigfix Platform
9.1.8 / 9.2.8+
HIGH 7.5
CVE-2018-7448EPSS 13%
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrar…
Cms Made Simple
No fix yet
CRITICAL 9.8
CVE-2018-7440
An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot roo…
Debian Linux
after 1.75.3
HIGH 7.2
CVE-2018-7046EPSS 5%
Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a …
Xperience
after 11.0
HIGH 8.8
CVE-2018-7187EPSS 63%
The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks fo…
Go
1.9.5 / 1.10.1+
HIGH 8.8
CVE-2017-14535EPSS 50%
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.
Trixbox
No fix yet
HIGH 8.8
CVE-2017-6229
Ruckus Networks Unleashed AP firmware releases before 200.6.10.1.x and Ruckus Networks Zone Director firmware releases 10.1.0.0.x, 9.10.2.0.x, 9.12.3…
R500 Firmware
200.6.10.1.0+