Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.8 CVE-2017-1000473 Linux Dash up to version v2 is vulnerable to multiple command injection vulnerabilities in the way module names are parsed and then executed resultin… Linux Dash 2.0+ Fix from $1,9502018-01-03 CRITICAL 9.8 CVE-2017-1000487EPSS 6% Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings. Debian Linux 3.0.16+ Fix from $2,3002018-01-03 CRITICAL 9.8 CVE-2014-8389EPSS 51% cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with… Bu 3026 Firmware No fix yet Fix from $2,3002017-12-28 HIGH 8.8 CVE-2017-17888EPSS 28% cgi-bin/write.cgi in Anti-Web through 3.8.7, as used on NetBiter / HMS, Ouman EH-net, Alliance System WS100 --> AWU 500, Sauter ERW100F001, Carlo Gav… Antiweb after 3.8.7 Fix from $1,9502017-12-27 CRITICAL 9.8 CVE-2017-17411EPSS 88% This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to … Wvbr0 Firmware 1.0.41+ Fix from $2,3002017-12-21 HIGH 8.8 CVE-2017-5255EPSS 75% In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows an… Epmp 1000 Firmware after 3.5 Fix from $1,9502017-12-20 HIGH 8.8 CVE-2017-15049EPSS 17% The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, … Zoom 2.0.115900.1201+ Fix from $1,9502017-12-19 HIGH 8.8 CVE-2017-17757 TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of a… Tl Wvr450l Firmware No fix yet Fix from $1,9502017-12-19 HIGH 8.8 CVE-2017-17758 TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of a… Tl Wvr450l Firmware No fix yet Fix from $1,9502017-12-19 CRITICAL 9.8 CVE-2017-17105EPSS 85% Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote comma… Pr115 204 P Rs Firmware No fix yet Fix from $2,3002017-12-19 HIGH 8.8 CVE-2017-15103EPSS 5% A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted r… Enterprise Linux Patch available Fix from $1,9502017-12-18 CRITICAL 9.8 CVE-2017-10904 Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors. Qt 5.9.0+ Fix from $2,3002017-12-16 HIGH 8.8 CVE-2017-17405EPSS 74% Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to… Ruby after 2.4.2 Fix from $1,9502017-12-15 HIGH 8.8 CVE-2017-16921EPSS 20% In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged … Debian Linux Patch available Fix from $1,9502017-12-08 CRITICAL 9.8 CVE-2017-17458EPSS 6% In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a … Debian Linux 4.4.1+ Fix from $2,3002017-12-07 CRITICAL 9.0 CVE-2017-17055EPSS 9% Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack invol… Artica Proxy 3.06.112911+ Fix from $2,3002017-12-07 CRITICAL 9.8 CVE-2016-1253 The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote … Most 5.0.0a-2.2 / 5.0.0a-2.3+ Fix from $2,3002017-12-05 CRITICAL 9.8 CVE-2017-10902 PTW-WMS1 firmware version 2.000.012 allows remote attackers to execute arbitrary OS commands via unspecified vectors. Ptw Wms1 Firmware Mitigation only Fix from $2,3002017-12-01 HIGH 7.8 CVE-2017-1000159 Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91. Evince 3.25.91+ Fix from $1,9502017-11-27 CRITICAL 9.8 CVE-2017-1000214 GitPHP by xiphux is vulnerable to OS Command Injections Gitphp Patch available Fix from $2,3002017-11-27 HIGH 8.8 CVE-2017-16957EPSS 6% TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface … Tl Wvr300 Firmware No fix yet Fix from $1,9502017-11-27 HIGH 8.8 CVE-2017-16958 TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bind… Tl Wvr300 Firmware No fix yet Fix from $1,9502017-11-27 HIGH 8.8 CVE-2017-16960 TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bind… Tl Er5510g Mitigation only Fix from $1,9502017-11-27 CRITICAL 9.8 CVE-2017-16934EPSS 13% The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?conten… Web Server No fix yet Fix from $2,3002017-11-24 CRITICAL 9.8 CVE-2017-16926EPSS 6% Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can be exploited by an attacker … Ohcount No fix yet Fix from $2,3002017-11-22 HIGH 8.8 CVE-2017-16923 Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac1… Ac9 Firmware No fix yet Fix from $1,9502017-11-21 CRITICAL 9.8 CVE-2017-1000215EPSS 6% ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution Xrootd after 4.6.0 Fix from $2,3002017-11-17 HIGH 8.8 CVE-2017-1000203 ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution Root after 6.9.03 Fix from $1,9502017-11-17 CRITICAL 9.8 CVE-2017-1000235 I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised. I\, Librarian after 4.6 Fix from $2,3002017-11-17 CRITICAL 9.8 CVE-2017-1000220EPSS 5% soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution Pidusage after 1.1.4 Fix from $2,3002017-11-17