Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2017-2824EPSS 26%
An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets ca…
Zabbix
No fix yet
CRITICAL 9.8
CVE-2017-5173EPSS 30%
An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An i…
Ip Camera G Cam Efd 2250 Firmware
No fix yet
CRITICAL 9.8
CVE-2017-8799
Untrusted input execution via igetwild in all iRODS versions before 4.1.11 and 4.2.1 allows other iRODS users (potentially anonymous) to execute remo…
Irods
after 4.1.10
CRITICAL 9.8
CVE-2017-8768EPSS 8%
Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS co…
Sourcetree
after 2.5c
HIGH 8.8
CVE-2017-7981EPSS 16%
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the pro…
Tuleap
9.7+
MEDIUM 6.8
CVE-2017-2152
WNC01WH firmware 1.0.0.9 and earlier allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.
Wnc01wh Firmware
after 1.0.0.9
HIGH 8.8
CVE-2017-2112
TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.…
Ts Ptcam\/poe Firmware
after 1.18
HIGH 8.8
CVE-2017-2128
Security guide for website operators allows remote attackers to execute arbitrary OS commands via specially crafted saved data.
Introduction To Safe Website Operation
Mitigation only
HIGH 7.2
CVE-2017-2141
WN-G300R3 firmware 1.03 and earlier allows attackers with administrator rights to execute arbitrary OS commands via unspecified vectors.
Wn G300r3 Firmware
after 1.03
CRITICAL 9.8
CVE-2017-2096EPSS 6%
smalruby-editor v0.4.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Smalruby Editor
after 0.4.0
CRITICAL 9.9
CVE-2017-8220EPSS 37%
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by plac…
C2 Firmware
after 0.9.1_4.2_v0032.0_build_160706
HIGH 7.4
CVE-2017-3506 KEVEPSS 96%
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected …
Weblogic Server
Patch available
CRITICAL 9.8
CVE-2017-8051EPSS 16%
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of …
Appliance
Patch available
CRITICAL 9.1
CVE-2016-8721
An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running…
Awk 3131a Firmware
No fix yet
HIGH 7.8
CVE-2017-7690
Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary with a Trojan horse program.
Proxifier
2.19.2+
HIGH 8.8
CVE-2016-5313
Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.
Web Gateway
after 5.2.2
HIGH 7.8
CVE-2017-6597
A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewa…
Unified Computing System
Mitigation only
HIGH 7.8
CVE-2017-6600
A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisc…
Firepower Extensible Operating System
Mitigation only
HIGH 7.1
CVE-2017-6601
A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisc…
Firepower Extensible Operating System
Mitigation only
MEDIUM 6.4
CVE-2017-6606
A vulnerability in a startup script of Cisco IOS XE Software could allow an unauthenticated attacker with physical access to the targeted system to e…
Ios Xe
Mitigation only
HIGH 7.8
CVE-2016-10320
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web appl…
Textract
after 1.4.0
HIGH 8.8
CVE-2017-6884 KEVEPSS 38%
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the …
Emg2926 Firmware
Mitigation only
HIGH 7.2
CVE-2016-9091EPSS 10%
Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command inje…
Advanced Secure Gateway
after 6.6.5.2
HIGH 8.8
CVE-2017-7413EPSS 40%
In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenti…
Groupware
after 5.2.17
HIGH 7.5
CVE-2017-7414
In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP featur…
Groupware
Mitigation only
CRITICAL 9.8
CVE-2017-6182EPSS 17%
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote comman…
Web Appliance
after 4.3.1.1
HIGH 7.8
CVE-2017-5330
ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications.
Fedora
after 16.12
HIGH 8.8
CVE-2017-6087EPSS 7%
EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] p…
Eonweb
after 5.0-0
CRITICAL 9.8
CVE-2017-6359EPSS 27%
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.
Qts
after 4.2.4
CRITICAL 9.8
CVE-2017-6360EPSS 66%
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
Qts
after 4.2.4