Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Recoverpoint For Virtual Machines MEDIUM 6.7
CVE-2016-6649

EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vul…

Fix: after 4.4.1.0
Fix from $1,600 2017-02-03
Documentum D2 MEDIUM 6.3
CVE-2016-9873

EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has a DQL Injection Vulnerability that could potentially be exploited by malicious us…

Mitigation only
Fix from $1,600 2017-02-03
Bigfix Platform HIGH 8.1
CVE-2016-0396

IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileg…

Patch available
Fix from $1,950 2017-02-01
Virtual Mobile Infrastructure HIGH 8.8
CVE-2016-6270EPSS 6%

The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile Infrastructure before 5.1 all…

No fix yet
Fix from $1,950 2017-01-30
Dwr 932b Firmware CRITICAL 9.8
CVE-2016-10182EPSS 9%

An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.

No fix yet
Fix from $2,300 2017-01-30
Web Appliance HIGH 7.2
CVE-2016-9553EPSS 19%

The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. …

No fix yet
Fix from $1,950 2017-01-28
Web Appliance HIGH 7.2
CVE-2016-9554EPSS 25%

The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web ad…

No fix yet
Fix from $1,950 2017-01-28
Debian Linux HIGH 7.8
CVE-2015-8971

Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the…

Patch available
Fix from $1,950 2017-01-23
Drgos HIGH 8.8
CVE-2015-3441

The Parental Control panel in Genexis devices with DRGOS before 1.14.1 allows remote authenticated users to execute arbitrary CLI commands via the (1…

Fix: after 1.14
Fix from $1,950 2017-01-05
Netbackup Appliance Firmware CRITICAL 9.8
CVE-2016-7399

scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attac…

Patch available
Fix from $2,300 2017-01-04
Mycloud Nas CRITICAL 9.8
CVE-2016-10107EPSS 11%

Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header.

No fix yet
Fix from $2,300 2017-01-03
Mycloud Nas CRITICAL 9.8
CVE-2016-10108EPSS 97%

Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg …

No fix yet
Fix from $2,300 2017-01-03
Zend Framework CRITICAL 9.8
CVE-2016-10034EPSS 38%

The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework befor…

Fix: after 2.4.10
Fix from $2,300 2016-12-30
WordPress CRITICAL 9.8
CVE-2016-10045EPSS 98%

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute ar…

Fix: 5.2.20+
Fix from $2,300 2016-12-30
Swiftmailer CRITICAL 9.8
CVE-2016-10074EPSS 42%

The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail…

Fix: after 5.4.4
Fix from $2,300 2016-12-30
Greenplum HIGH 7.2
CVE-2016-6656

An issue was discovered in Pivotal Greenplum before 4.3.10.0. Creation of external tables using GPHDFS protocol has a vulnerability whereby arbitrary…

Fix: after 4.3.9.1
Fix from $1,950 2016-12-16
Mailcwp CRITICAL 9.8
CVE-2016-1000156

Mailcwp remote file upload vulnerability incomplete fix v1.100

Fix: after 1.100
Fix from $2,300 2016-12-14
phpMyAdmin HIGH 8.8
CVE-2016-6609

An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature…

Patch available
Fix from $1,950 2016-12-11
Zikula Application Framework CRITICAL 9.8
CVE-2016-9835

Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to laun…

Patch available
Fix from $2,300 2016-12-05
Git Fastclone CRITICAL 9.8
CVE-2015-8969

git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the st…

Fix: 1.0.5+
Fix from $2,300 2016-11-03
Git Fastclone HIGH 8.8
CVE-2015-8968EPSS 5%

git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone fr…

Fix: 1.0.1+
Fix from $1,950 2016-11-03
Security Guardium Database Activity Monitor HIGH 7.8
CVE-2016-0328

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to…

Patch available
Fix from $1,950 2016-10-22
Rational Collaborative Lifecycle Management HIGH 8.8
CVE-2016-0326

IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iF…

Patch available
Fix from $1,950 2016-10-22
Security Guardium Database Activity Monitor HIGH 8.8
CVE-2016-0236

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authent…

Patch available
Fix from $1,950 2016-10-21
Avamar Server HIGH 7.8
CVE-2016-0920

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted …

Fix: after 7.3.0
Fix from $1,950 2016-09-21
Adaptive Security Appliance Software HIGH 7.8
CVE-2016-6367 KEVEPSS 23%

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges v…

Fix: 8.4 / 9.0+
Fix from $1,950 2016-08-18
Qradar Security Information And Event Manager HIGH 8.8
CVE-2016-2875

IBM Security QRadar SIEM 7.1.x and 7.2.x before 7.2.7 allows remote authenticated users to execute arbitrary OS commands as root via unspecified vect…

Patch available
Fix from $1,950 2016-08-08
Airmedia Am 100 Firmware CRITICAL 9.8
CVE-2016-5640EPSS 18%

Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to …

Fix: after 1.2.1
Fix from $2,300 2016-08-03
Cg Wlbargl Firmware HIGH 8.0
CVE-2016-4822

Corega CG-WLBARGL devices allow remote authenticated users to execute arbitrary commands via unspecified vectors.

Mitigation only
Fix from $1,950 2016-06-25
Network Analysis Module CRITICAL 9.8
CVE-2016-1388

Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Network Analysis Module (vNAM) be…

Mitigation only
Fix from $2,300 2016-06-03