Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-1000219
npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user
Windows Cpu
No fix yet
MEDIUM 6.7
CVE-2017-12305
A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka …
Ip Phone 8800 Series Firmware
Mitigation only
HIGH 7.2
CVE-2017-12636EPSS 90%
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-leve…
Couchdb
1.7.0+
HIGH 8.8
CVE-2017-1453
IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a spe…
Security Access Manager 9.0 Firmware
Mitigation only
HIGH 7.8
CVE-2017-16667
backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to so…
Backintime
1.1.24+
HIGH 7.2
CVE-2017-16641
lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=s…
Cacti
Patch available
HIGH 8.8
CVE-2017-2917
An exploitable vulnerability exists in the notifications functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packet…
Circle With Disney Firmware
No fix yet
HIGH 8.8
CVE-2017-2866
An exploitable vulnerability exists in the /api/CONFIG/backup functionality of Circle with Disney. Specially crafted network packets can cause an OS …
Circle With Disney Firmware
No fix yet
HIGH 8.8
CVE-2017-2890
An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network …
Circle With Disney Firmware
Mitigation only
HIGH 7.8
CVE-2017-12243EPSS 77%
A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower…
Unified Computing System Manager Firmware
Mitigation only
HIGH 8.8
CVE-2017-10953
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is req…
Foxit Reader
Patch available
HIGH 8.8
CVE-2017-9377
A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An a…
Clickshare Csm 1 Firmware
1.7.0.3 / 1.10.0.10+
HIGH 7.8
CVE-2017-15924
In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration req…
Debian Linux
Patch available
HIGH 7.2
CVE-2017-7341
An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file m…
Fortiwlc
after 8.3.2
HIGH 8.8
CVE-2017-10955EPSS 7%
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication…
Data Protection Advisor
Mitigation only
CRITICAL 9.8
CVE-2017-3761
The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this …
Service Framework
Patch available
HIGH 8.8
CVE-2017-6223
Ruckus Wireless Zone Director Controller firmware releases ZD9.9.x, ZD9.10.x, ZD9.13.0.x less than 9.13.0.0.232 contain OS Command Injection vulnerab…
Zonedirector Firmware
Mitigation only
HIGH 8.8
CVE-2017-6224
Ruckus Wireless Zone Director Controller firmware releases ZD9.x, ZD10.0.0.x, ZD10.0.1.x (less than 10.0.1.0.17 MR1 release) and Ruckus Wireless Unle…
Zonedirector Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-15226
Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because beginIndex and endIndex are used directly in a popen ca…
Nbg6716 Firmware
No fix yet
CRITICAL 9.8
CVE-2017-1000116EPSS 6%
Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
Debian Linux
4.3+
HIGH 8.2
CVE-2017-11322EPSS 5%
The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) meta…
Ucopia Wireless Appliance
after 5.1.7
HIGH 7.2
CVE-2017-11321EPSS 8%
The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admin' privileges via shell metac…
Wireless Appliance
after 5.1.7
HIGH 8.8
CVE-2017-14867EPSS 36%
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support sub…
Git
after 2.10.4
HIGH 8.8
CVE-2017-14001EPSS 6%
An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior. An OS command injec…
Asterisk Gui
after 2.1.0
HIGH 8.1
CVE-2017-14705EPSS 7%
DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters can be inserted into the type…
I Suite
Patch available
HIGH 8.8
CVE-2017-11395EPSS 14%
Command injection vulnerability in Trend Micro Smart Protection Server (Standalone) 3.1 and 3.2 server administration UI allows attackers with authen…
Smart Protection Server
Patch available
CRITICAL 9.8
CVE-2015-3431
Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injecti…
Pydio
after 6.0.6
HIGH 8.8
CVE-2017-14500
Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsbeuter 0.3 through 2.9 allows …
Newsbeuter
Patch available
CRITICAL 9.8
CVE-2017-9328EPSS 7%
Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as r…
Terramaster Operating System
after 3.0.33
MEDIUM 6.8
CVE-2017-10813
CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
Wlr 300 Nm Firmware
after 1.90