Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2017-1000473
Linux Dash up to version v2 is vulnerable to multiple command injection vulnerabilities in the way module names are parsed and then executed resultin…
Linux Dash
2.0+
CRITICAL 9.8
CVE-2017-1000487EPSS 6%
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.
Debian Linux
3.0.16+
CRITICAL 9.8
CVE-2014-8389EPSS 51%
cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with…
Bu 3026 Firmware
No fix yet
HIGH 8.8
CVE-2017-17888EPSS 28%
cgi-bin/write.cgi in Anti-Web through 3.8.7, as used on NetBiter / HMS, Ouman EH-net, Alliance System WS100 --> AWU 500, Sauter ERW100F001, Carlo Gav…
Antiweb
after 3.8.7
CRITICAL 9.8
CVE-2017-17411EPSS 88%
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to …
Wvbr0 Firmware
1.0.41+
HIGH 8.8
CVE-2017-5255EPSS 75%
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows an…
Epmp 1000 Firmware
after 3.5
HIGH 8.8
CVE-2017-15049EPSS 17%
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, …
Zoom
2.0.115900.1201+
HIGH 8.8
CVE-2017-17757
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of a…
Tl Wvr450l Firmware
No fix yet
HIGH 8.8
CVE-2017-17758
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of a…
Tl Wvr450l Firmware
No fix yet
CRITICAL 9.8
CVE-2017-17105EPSS 85%
Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote comma…
Pr115 204 P Rs Firmware
No fix yet
HIGH 8.8
CVE-2017-15103EPSS 5%
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted r…
Enterprise Linux
Patch available
CRITICAL 9.8
CVE-2017-10904
Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Qt
5.9.0+
HIGH 8.8
CVE-2017-17405EPSS 74%
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to…
Ruby
after 2.4.2
HIGH 8.8
CVE-2017-16921EPSS 20%
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged …
Debian Linux
Patch available
CRITICAL 9.8
CVE-2017-17458EPSS 6%
In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a …
Debian Linux
4.4.1+
CRITICAL 9.0
CVE-2017-17055EPSS 9%
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack invol…
Artica Proxy
3.06.112911+
CRITICAL 9.8
CVE-2016-1253
The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote …
Most
5.0.0a-2.2 / 5.0.0a-2.3+
CRITICAL 9.8
CVE-2017-10902
PTW-WMS1 firmware version 2.000.012 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Ptw Wms1 Firmware
Mitigation only
HIGH 7.8
CVE-2017-1000159
Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.
Evince
3.25.91+
CRITICAL 9.8
CVE-2017-1000214
GitPHP by xiphux is vulnerable to OS Command Injections
Gitphp
Patch available
HIGH 8.8
CVE-2017-16957EPSS 6%
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface …
Tl Wvr300 Firmware
No fix yet
HIGH 8.8
CVE-2017-16958
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bind…
Tl Wvr300 Firmware
No fix yet
HIGH 8.8
CVE-2017-16960
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bind…
Tl Er5510g
Mitigation only
CRITICAL 9.8
CVE-2017-16934EPSS 13%
The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?conten…
Web Server
No fix yet
CRITICAL 9.8
CVE-2017-16926EPSS 6%
Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can be exploited by an attacker …
Ohcount
No fix yet
HIGH 8.8
CVE-2017-16923
Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac1…
Ac9 Firmware
No fix yet
CRITICAL 9.8
CVE-2017-1000215EPSS 6%
ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution
Xrootd
after 4.6.0
HIGH 8.8
CVE-2017-1000203
ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution
Root
after 6.9.03
CRITICAL 9.8
CVE-2017-1000235
I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.
I\, Librarian
after 4.6
CRITICAL 9.8
CVE-2017-1000220EPSS 5%
soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution
Pidusage
after 1.1.4