Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.8 CVE-2018-0182 Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into th… Ios Xe 16.3.1+ Fix from $1,9502018-03-28 MEDIUM 6.7 CVE-2018-0183 A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell … Ios Xe 3.13.0as / 3.13.2as+ Fix from $1,6002018-03-28 MEDIUM 6.7 CVE-2018-0184 A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell … Ios Xe 3.8.6e / 3.13.9s+ Fix from $1,6002018-03-28 HIGH 7.8 CVE-2018-0185 Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into th… Ios Xe 16.3.1+ Fix from $1,9502018-03-28 HIGH 7.8 CVE-2018-0169 Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Lin… iOS Mitigation only Fix from $1,9502018-03-28 HIGH 7.5 CVE-2018-1238 Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA). This component is used for c… Emc Scaleio 2.5+ Fix from $1,9502018-03-27 CRITICAL 9.8 CVE-2018-0539 QQQ SYSTEMS version 2.24 allows an attacker to execute arbitrary commands via unspecified vectors. Qqq Systems No fix yet Fix from $2,3002018-03-22 HIGH 8.8 CVE-2011-3178 In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to e… Open Build Service 2.3.0+ Fix from $1,9502018-03-20 CRITICAL 9.8 CVE-2018-6231EPSS 7% A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could … Smart Protection Server after 3.3 Fix from $2,3002018-03-15 HIGH 7.8 CVE-2018-6222 Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to exe… Email Encryption Gateway Patch available Fix from $1,9502018-03-15 HIGH 8.8 CVE-2018-0523 Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. Wxr 1900dhp2 Firmware after 2.48 Fix from $1,9502018-03-09 CRITICAL 9.8 CVE-2018-7890EPSS 79% A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredent… Manageengine Applications Manager 13.6+ Fix from $2,3002018-03-08 CRITICAL 9.8 CVE-2017-7640 QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against th… Media Streaming Add On after 430.1.2.0 Fix from $2,3002018-03-08 MEDIUM 6.7 CVE-2018-0221 A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command… Identity Services Engine Mitigation only Fix from $1,6002018-03-08 MEDIUM 6.7 CVE-2018-0224 A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, … Staros Mitigation only Fix from $1,6002018-03-08 MEDIUM 5.3 CVE-2018-0214 A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary com… Identity Services Engine Mitigation only Fix from $1,6002018-03-08 MEDIUM 6.7 CVE-2018-0217 A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, … Asr 5000 Firmware Mitigation only Fix from $1,6002018-03-08 HIGH 8.8 CVE-2018-1000118 Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command e… Electron after 1.8.1 Fix from $1,9502018-03-07 CRITICAL 9.8 CVE-2018-6530 KEVEPSS 97% OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions… Dir 860l Firmware after 1.12b04 Fix from $2,3002018-03-06 CRITICAL 9.8 CVE-2018-7664 An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacters in the file_name parameter … Clipbucket after 4.0.0 Fix from $2,3002018-03-05 HIGH 8.8 CVE-2018-1169 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User interaction … Amazon Music Mitigation only Fix from $1,9502018-03-02 HIGH 7.8 CVE-2017-9274 A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files w… Obs Service Source Validator 0.7+ Fix from $1,9502018-03-01 HIGH 8.8 CVE-2015-4117EPSS 11% Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter … Control Panel 0.9.8-14+ Fix from $1,9502018-02-28 HIGH 8.8 CVE-2016-0291 IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report s… Bigfix Platform 9.1.8 / 9.2.8+ Fix from $1,9502018-02-28 HIGH 7.5 CVE-2018-7448EPSS 13% Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrar… Cms Made Simple No fix yet Fix from $1,9502018-02-26 CRITICAL 9.8 CVE-2018-7440 An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot roo… Debian Linux after 1.75.3 Fix from $2,3002018-02-23 HIGH 7.2 CVE-2018-7046EPSS 5% Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a … Xperience after 11.0 Fix from $1,9502018-02-20 HIGH 8.8 CVE-2018-7187EPSS 63% The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks fo… Go 1.9.5 / 1.10.1+ Fix from $1,9502018-02-16 HIGH 8.8 CVE-2017-14535EPSS 50% trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php. Trixbox No fix yet Fix from $1,9502018-02-16 HIGH 8.8 CVE-2017-6229 Ruckus Networks Unleashed AP firmware releases before 200.6.10.1.x and Ruckus Networks Zone Director firmware releases 10.1.0.0.x, 9.10.2.0.x, 9.12.3… R500 Firmware 200.6.10.1.0+ Fix from $1,9502018-02-14