Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2017-6230 Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated… Solo Access Point Firmware Mitigation only Fix from $1,9502018-02-14 CRITICAL 9.8 CVE-2018-6911EPSS 13% The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argume… Webaccess No fix yet Fix from $2,3002018-02-13 HIGH 7.2 CVE-2018-6926 In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linu… Misp Patch available Fix from $1,9502018-02-12 CRITICAL 9.8 CVE-2018-1000042 Security Onion Solutions Squert version 1.3.0 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS … Squert after 1.6.7 Fix from $2,3002018-02-09 CRITICAL 9.8 CVE-2018-1000043 Security Onion Solutions Squert version 1.0.1 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS … Squert after 1.6.7 Fix from $2,3002018-02-09 HIGH 8.8 CVE-2018-1000019 OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command injection by an authenticated a… Openemr Patch available Fix from $1,9502018-02-09 MEDIUM 6.8 CVE-2018-0512 Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands… Hdl Xr Firmware after 2.01 Fix from $1,6002018-02-08 CRITICAL 9.8 CVE-2018-0514 MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. Mp Form Mail Cgi after 2.0.13 Fix from $2,3002018-02-08 MEDIUM 6.8 CVE-2018-6791 An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $(… Debian Linux 5.12.0+ Fix from $1,6002018-02-07 MEDIUM 6.7 CVE-2018-1184 An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint vers… Emc Recoverpoint 5.0.1.3 / 5.1.1+ Fix from $1,6002018-02-03 MEDIUM 6.7 CVE-2018-1185EPSS 6% An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint vers… Emc Recoverpoint 5.0.1.3 / 5.1.1+ Fix from $1,6002018-02-03 HIGH 8.8 CVE-2018-6388EPSS 6% iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharacters in … Ib Wra150n Firmware No fix yet Fix from $1,9502018-01-29 HIGH 7.8 CVE-2018-6353 The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1) social-engineering attacks … Electrum after 2.9.4 Fix from $1,9502018-01-27 CRITICAL 9.8 CVE-2018-0506 Nootka 1.4.4 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. Nootka after 1.4.4 Fix from $2,3002018-01-26 HIGH 8.8 CVE-2017-1000393 Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could configure a launch method called 'L… Jenkins after 2.83 Fix from $1,9502018-01-26 HIGH 8.8 CVE-2017-1000502 Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the m… Ec2 after 1.37 Fix from $1,9502018-01-24 HIGH 8.8 CVE-2018-1000006EPSS 85% GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically E… Electron after 1.7.10 Fix from $1,9502018-01-24 CRITICAL 9.8 CVE-2017-16608 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not… Enterprise Manager 7.2.766+ Fix from $2,3002018-01-23 CRITICAL 9.8 CVE-2017-17407 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager v7.2.699 build… Enterprise Manager Mitigation only Fix from $2,3002018-01-23 HIGH 8.8 CVE-2017-16602 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build … Enterprise Manager Mitigation only Fix from $1,9502018-01-23 HIGH 8.8 CVE-2016-10709EPSS 34% pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph param… Pfsense after 2.2.6 Fix from $1,9502018-01-22 HIGH 7.8 CVE-2017-15108 spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the … Debian Linux after 0.17.0 Fix from $1,9502018-01-20 CRITICAL 9.8 CVE-2017-14094EPSS 19% A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command executio… Smart Protection Server after 3.2 Fix from $2,3002018-01-19 CRITICAL 9.8 CVE-2017-18044EPSS 70% A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside t… Commvault after 11.0 Fix from $2,3002018-01-19 HIGH 8.8 CVE-2018-0099 A vulnerability in the web management GUI of the Cisco D9800 Network Transport Receiver could allow an authenticated, remote attacker to perform a co… D9800 Firmware No fix yet Fix from $1,9502018-01-18 MEDIUM 6.7 CVE-2018-0115 A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series routers could allow an authenticated, local attacker to exe… Staros Mitigation only Fix from $1,6002018-01-18 HIGH 8.8 CVE-2018-5371EPSS 42% diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote… Dsl 2540u Firmware No fix yet Fix from $1,9502018-01-12 CRITICAL 9.8 CVE-2018-5347EPSS 54% Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because… Personal Cloud Firmware No fix yet Fix from $2,3002018-01-12 CRITICAL 9.8 CVE-2017-18025 cgi-bin/drknow.cgi in Innotube ITGuard-Manager 0.0.0.1 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the usern… Itguard Manager No fix yet Fix from $2,3002018-01-09 HIGH 8.8 CVE-2017-16666EPSS 80% Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name of an uploaded PCAP file. N… Xplico 1.2.1+ Fix from $1,9502018-01-05