Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Xcloner MEDIUM 6.5
CVE-2015-4336

cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing …

No fix yet
Fix from $1,600 2015-06-17
Ubuntu Linux HIGH 10.0
CVE-2015-3408EPSS 6%

Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled …

Fix: after 0.73
Fix from $1,950 2015-05-19
Autostart HIGH 9.3
CVE-2015-0538EPSS 7%

ftagent.exe in EMC AutoStart 5.4.x and 5.5.x before 5.5.0.508 HF4 allows remote attackers to execute arbitrary commands via crafted packets.

Fix: after 5.5.0
Fix from $1,950 2015-05-07
Sync HIGH 9.3
CVE-2015-2846

BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link.

Mitigation only
Fix from $1,950 2015-04-13
Cassandra HIGH 7.5
CVE-2015-0225EPSS 7%

The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI in…

No fix yet
Fix from $1,950 2015-04-03
Fedora HIGH 10.0
CVE-2015-1815EPSS 16%

The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via …

Fix: after 3.2.21
Fix from $1,950 2015-03-30
Triton MEDIUM 6.5
CVE-2015-2746EPSS 25%

The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliance…

Fix: after 7.7
Fix from $1,600 2015-03-26
Ubuntu Linux HIGH 7.5
CVE-2015-2265

The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via cons…

Fix: after 1.0.65
Fix from $1,950 2015-03-24
Fedora HIGH 7.5
CVE-2015-0778

osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.

Fix: after 0.150
Fix from $1,950 2015-03-16
Phpmoadmin HIGH 7.5
CVE-2015-2208EPSS 62%

The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the obje…

No fix yet
Fix from $1,950 2015-03-12
Sharelatex MEDIUM 6.5
CVE-2015-0934

Common LaTeX Service Interface (CLSI) before 0.1.3, as used in ShareLaTeX before 0.1.3, allows remote authenticated users to execute arbitrary code v…

Fix: after 0.1.2
Fix from $1,600 2015-03-04
Dns Sync HIGH 10.0
CVE-2014-9682

The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first a…

Fix: after 0.1.0
Fix from $1,950 2015-02-28
Dir 645 Firmware HIGH 8.8
CVE-2015-2051 KEVEPSS 97%

The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDev…

Fix: 1.05b01+
Fix from $1,950 2015-02-23
Fedora MEDIUM 6.5
CVE-2014-8630

Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execu…

Fix: after 4.0.16
Fix from $1,600 2015-02-01
Xdg Utils MEDIUM 6.8
CVE-2014-9622

Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execu…

No fix yet
Fix from $1,600 2015-01-21
Mime Support HIGH 7.5
CVE-2014-7209

run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metach…

Fix: after 3.52-1
Fix from $1,950 2015-01-06
Mediawiki HIGH 7.5
CVE-2014-9277

The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 all…

Fix: after 1.19.21
Fix from $1,950 2015-01-04
Ipcop MEDIUM 6.5
CVE-2013-7418

cgi-bin/iptablesgui.cgi in IPCop (aka IPCop Firewall) before 2.1.5 allows remote authenticated users to execute arbitrary code via shell metacharacte…

Fix: after 2.1.4
Fix from $1,600 2015-01-02
Nginx MEDIUM 6.8
CVE-2014-3556EPSS 8%

The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not p…

Fix: 1.6.1 / 1.7.4+
Fix from $1,600 2014-12-29
Videowhisper Live Streaming Integration HIGH 10.0
CVE-2014-1905EPSS 10%

Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow…

Fix: after 4.27.4
Fix from $1,950 2014-12-29
Redmine Git Hosting Plugin HIGH 7.5
CVE-2013-4663

git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters i…

No fix yet
Fix from $1,950 2014-12-28
Proclima HIGH 9.0
CVE-2014-9188EPSS 6%

Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code vi…

Fix: after 6.0.1
Fix from $1,950 2014-12-27
Gparted HIGH 7.2
CVE-2014-7208

GParted before 0.15.0 allows local users to execute arbitrary commands with root privileges via shell metacharacters in a crafted filesystem label.

Fix: 0.15.0+
Fix from $1,950 2014-12-19
Web Gateway MEDIUM 6.5
CVE-2014-7285EPSS 50%

The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by…

Fix: after 5.2.1
Fix from $1,600 2014-12-17
Zenoss Core MEDIUM 6.8
CVE-2014-6260

Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute arbitrary c…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Bittorrent MEDIUM 6.8
CVE-2014-8515

The web interface in BitTorrent allows remote attackers to execute arbitrary commands by leveraging knowledge of the pairing values and a crafted req…

Mitigation only
Fix from $1,600 2014-12-12
Dl 8000 Remote Terminal Unit Firmware HIGH 10.0
CVE-2013-2810EPSS 6%

Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 a…

Fix: after 3.50
Fix from $1,950 2014-12-08
Debian Linux HIGH 7.5
CVE-2014-8990EPSS 5%

default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.

Fix: after 2.1.5
Fix from $1,950 2014-12-05
Td5130 Router Firmware HIGH 7.5
CVE-2014-9144EPSS 9%

Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (…

No fix yet
Fix from $1,950 2014-12-05
Canto Curses HIGH 7.5
CVE-2013-7416

canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a …

Fix: after 0.9.0
Fix from $1,950 2014-12-03