Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2017-1000219 npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user Windows Cpu No fix yet Fix from $2,3002017-11-17 MEDIUM 6.7 CVE-2017-12305 A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka … Ip Phone 8800 Series Firmware Mitigation only Fix from $1,6002017-11-16 HIGH 7.2 CVE-2017-12636EPSS 90% CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-leve… Couchdb 1.7.0+ Fix from $1,9502017-11-14 HIGH 8.8 CVE-2017-1453 IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a spe… Security Access Manager 9.0 Firmware Mitigation only Fix from $1,9502017-11-13 HIGH 7.8 CVE-2017-16667 backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to so… Backintime 1.1.24+ Fix from $1,9502017-11-08 HIGH 7.2 CVE-2017-16641 lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=s… Cacti Patch available Fix from $1,9502017-11-07 HIGH 8.8 CVE-2017-2917 An exploitable vulnerability exists in the notifications functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packet… Circle With Disney Firmware No fix yet Fix from $1,9502017-11-07 HIGH 8.8 CVE-2017-2866 An exploitable vulnerability exists in the /api/CONFIG/backup functionality of Circle with Disney. Specially crafted network packets can cause an OS … Circle With Disney Firmware No fix yet Fix from $1,9502017-11-07 HIGH 8.8 CVE-2017-2890 An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network … Circle With Disney Firmware Mitigation only Fix from $1,9502017-11-07 HIGH 7.8 CVE-2017-12243EPSS 77% A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower… Unified Computing System Manager Firmware Mitigation only Fix from $1,9502017-11-02 HIGH 8.8 CVE-2017-10953 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is req… Foxit Reader Patch available Fix from $1,9502017-10-31 HIGH 8.8 CVE-2017-9377 A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An a… Clickshare Csm 1 Firmware 1.7.0.3 / 1.10.0.10+ Fix from $1,9502017-10-30 HIGH 7.8 CVE-2017-15924 In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration req… Debian Linux Patch available Fix from $1,9502017-10-27 HIGH 7.2 CVE-2017-7341 An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file m… Fortiwlc after 8.3.2 Fix from $1,9502017-10-26 HIGH 8.8 CVE-2017-10955EPSS 7% This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication… Data Protection Advisor Mitigation only Fix from $1,9502017-10-19 CRITICAL 9.8 CVE-2017-3761 The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this … Service Framework Patch available Fix from $2,3002017-10-17 HIGH 8.8 CVE-2017-6223 Ruckus Wireless Zone Director Controller firmware releases ZD9.9.x, ZD9.10.x, ZD9.13.0.x less than 9.13.0.0.232 contain OS Command Injection vulnerab… Zonedirector Firmware Mitigation only Fix from $1,9502017-10-13 HIGH 8.8 CVE-2017-6224 Ruckus Wireless Zone Director Controller firmware releases ZD9.x, ZD10.0.0.x, ZD10.0.1.x (less than 10.0.1.0.17 MR1 release) and Ruckus Wireless Unle… Zonedirector Firmware Mitigation only Fix from $1,9502017-10-13 CRITICAL 9.8 CVE-2017-15226 Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because beginIndex and endIndex are used directly in a popen ca… Nbg6716 Firmware No fix yet Fix from $2,3002017-10-10 CRITICAL 9.8 CVE-2017-1000116EPSS 6% Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks. Debian Linux 4.3+ Fix from $2,3002017-10-05 HIGH 8.2 CVE-2017-11322EPSS 5% The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) meta… Ucopia Wireless Appliance after 5.1.7 Fix from $1,9502017-10-03 HIGH 7.2 CVE-2017-11321EPSS 8% The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admin' privileges via shell metac… Wireless Appliance after 5.1.7 Fix from $1,9502017-10-03 HIGH 8.8 CVE-2017-14867EPSS 36% Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support sub… Git after 2.10.4 Fix from $1,9502017-09-29 HIGH 8.8 CVE-2017-14001EPSS 6% An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior. An OS command injec… Asterisk Gui after 2.1.0 Fix from $1,9502017-09-26 HIGH 8.1 CVE-2017-14705EPSS 7% DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters can be inserted into the type… I Suite Patch available Fix from $1,9502017-09-22 HIGH 8.8 CVE-2017-11395EPSS 14% Command injection vulnerability in Trend Micro Smart Protection Server (Standalone) 3.1 and 3.2 server administration UI allows attackers with authen… Smart Protection Server Patch available Fix from $1,9502017-09-22 CRITICAL 9.8 CVE-2015-3431 Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injecti… Pydio after 6.0.6 Fix from $2,3002017-09-19 HIGH 8.8 CVE-2017-14500 Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsbeuter 0.3 through 2.9 allows … Newsbeuter Patch available Fix from $1,9502017-09-17 CRITICAL 9.8 CVE-2017-9328EPSS 7% Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as r… Terramaster Operating System after 3.0.33 Fix from $2,3002017-09-15 MEDIUM 6.8 CVE-2017-10813 CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. Wlr 300 Nm Firmware after 1.90 Fix from $1,6002017-09-15