Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,180 CVEs tagged with CWE-781,976 Critical, 3,126 High, 890 Medium, 188 Low, 0 Unrated.

CVE-2017-9757

Published Jun 19, 2017

IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell. This can be exploited directly by authenticated use…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9736

Published Jun 17, 2017

SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-6683

Published Jun 13, 2017

A vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrary commands as the tomcat user…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6682

Published Jun 13, 2017

A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the Linux tomcat user on an affec…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2824

Published May 24, 2017

An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection re…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8799

Published May 5, 2017

Untrusted input execution via igetwild in all iRODS versions before 4.1.11 and 4.2.1 allows other iRODS users (potentially anonymous) to execute remote shell commands via iRODS vi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-8768

Published May 4, 2017

Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS command execution with a URL sub…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7981

Published Apr 29, 2017

Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used wi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2112

Published Apr 28, 2017

TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmwa…

CVSS 8.8 · High

CVE-2017-2096

Published Apr 28, 2017

smalruby-editor v0.4.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-3506

Published Apr 24, 2017

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1…

CVSS 7.4 · High
evidence mentions
5
Buzz score
55.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2017-8051

Published Apr 21, 2017

Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 5,901-5,925 of 6,180 CVEsPage 237 of 248