Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Debian Linux CRITICAL 9.8
CVE-2015-0857EPSS 5%

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within…

Mitigation only
Fix from $2,300 2016-05-06
Struts HIGH 8.1
CVE-2016-3081EPSS 93%

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec…

Patch available
Fix from $1,950 2016-04-26
Syslink Sl 1000 Modular Gateway Firmware HIGH 8.8
CVE-2016-2332

flu.cgi in the web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 allows remote authenticat…

Mitigation only
Fix from $1,950 2016-04-25
Vertica CRITICAL 9.8
CVE-2016-2002

The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2…

Fix: 7.0.2.12 / 7.1.2-12+
Fix from $2,300 2016-04-20
Debian Linux HIGH 8.8
CVE-2016-2056EPSS 55%

xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the …

Patch available
Fix from $1,950 2016-04-13
Ldap Studio HIGH 7.8
CVE-2015-5349

The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers …

Mitigation only
Fix from $1,950 2016-04-11
Uma Em5000 Firmware CRITICAL 9.8
CVE-2016-2397EPSS 6%

The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deseri…

Mitigation only
Fix from $2,300 2016-02-17
Analyzer CRITICAL 9.9
CVE-2016-2396

The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authen…

Mitigation only
Fix from $2,300 2016-02-17
Ups Snmp Web Adapter Firmware HIGH 8.8
CVE-2016-0861EPSS 14%

General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrar…

Fix: after 4.7
Fix from $1,950 2016-02-05
Colorscore CRITICAL 10.0
CVE-2015-7541

The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent atta…

Fix: after 0.0.4
Fix from $2,300 2016-01-08
Tivoli Monitoring HIGH 8.5
CVE-2015-5003

The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arb…

Mitigation only
Fix from $1,950 2016-01-03
Android MEDIUM 5.1
CVE-2015-6613

Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port, and consequently gain privi…

Fix: 5.1.1+
Fix from $1,600 2015-11-03
General Parallel File System HIGH 7.2
CVE-2015-4974

IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to…

Patch available
Fix from $1,950 2015-10-26
Log And Event Manager HIGH 7.5
CVE-2015-7839EPSS 7%

SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebr…

Mitigation only
Fix from $1,950 2015-10-15
Qradar Security Information And Event Manager HIGH 9.0
CVE-2015-4930

IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root…

Patch available
Fix from $1,950 2015-10-04
Qradar Security Information And Event Manager HIGH 9.0
CVE-2015-2011

The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to exec…

Patch available
Fix from $1,950 2015-10-04
Endian Firewall HIGH 10.0
CVE-2015-5082EPSS 70%

Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW_PASSWORD_1 or (2) NEW_PASSWO…

Fix: after 2.5.1
Fix from $1,950 2015-09-28
Web Gateway HIGH 8.3
CVE-2015-6547

The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute…

Fix: after 5.2.2
Fix from $1,950 2015-09-20
Openshift MEDIUM 6.5
CVE-2015-5274

rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to th…

Mitigation only
Fix from $1,600 2015-09-18
Video Station HIGH 10.0
CVE-2015-6912EPSS 12%

Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage …

Fix: after 1.5-0757
Fix from $1,950 2015-09-11
Pacemaker\/corosync Configuration System HIGH 8.5
CVE-2015-5190

The pcsd web UI in PCS 0.9.139 and earlier allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL.

Fix: after 0.9.139
Fix from $1,950 2015-09-03
Bittorrent HIGH 9.3
CVE-2015-5474

BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bitto…

Mitigation only
Fix from $1,950 2015-08-13
Netscaler Application Delivery Controller Firmware HIGH 9.0
CVE-2015-5080

The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56…

Mitigation only
Fix from $1,950 2015-07-16
Centreon MEDIUM 6.5
CVE-2015-1561EPSS 9%

The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed …

Fix: after 2.5.4
Fix from $1,600 2015-07-14
Xcs MEDIUM 6.5
CVE-2015-5453EPSS 57%

Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id par…

No fix yet
Fix from $1,600 2015-07-08
Isilon Onefs HIGH 9.0
CVE-2015-4525

The log-gather implementation in the web administration interface in EMC Isilon OneFS 6.5.x.x through 7.1.1.x before 7.1.1.5 and 7.2.0.x before 7.2.0…

Fix: after 7.1.1.0
Fix from $1,950 2015-07-04
Mac Os X HIGH 7.2
CVE-2015-3678

AppleThunderboltEDMService in Apple OS X before 10.10.4 allows local users to gain privileges or cause a denial of service (memory corruption) via un…

Fix: after 10.10.3
Fix from $1,950 2015-07-03
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2015-1986EPSS 8%

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a …

Mitigation only
Fix from $1,950 2015-06-30
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2015-1949EPSS 6%

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands with SYSTEM privileges via …

Mitigation only
Fix from $1,950 2015-06-30
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2015-1938EPSS 6%

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a …

Mitigation only
Fix from $1,950 2015-06-30