Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
MEDIUM 6.7 CVE-2016-6649 EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vul… Recoverpoint For Virtual Machines after 4.4.1.0 Fix from $1,6002017-02-03 MEDIUM 6.3 CVE-2016-9873 EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has a DQL Injection Vulnerability that could potentially be exploited by malicious us… Documentum D2 Mitigation only Fix from $1,6002017-02-03 HIGH 8.1 CVE-2016-0396 IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileg… Bigfix Platform Patch available Fix from $1,9502017-02-01 HIGH 8.8 CVE-2016-6270EPSS 6% The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile Infrastructure before 5.1 all… Virtual Mobile Infrastructure No fix yet Fix from $1,9502017-01-30 CRITICAL 9.8 CVE-2016-10182EPSS 9% An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters. Dwr 932b Firmware No fix yet Fix from $2,3002017-01-30 HIGH 7.2 CVE-2016-9553EPSS 19% The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. … Web Appliance No fix yet Fix from $1,9502017-01-28 HIGH 7.2 CVE-2016-9554EPSS 25% The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web ad… Web Appliance No fix yet Fix from $1,9502017-01-28 HIGH 7.8 CVE-2015-8971 Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the… Debian Linux Patch available Fix from $1,9502017-01-23 HIGH 8.8 CVE-2015-3441 The Parental Control panel in Genexis devices with DRGOS before 1.14.1 allows remote authenticated users to execute arbitrary CLI commands via the (1… Drgos after 1.14 Fix from $1,9502017-01-05 CRITICAL 9.8 CVE-2016-7399 scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attac… Netbackup Appliance Firmware Patch available Fix from $2,3002017-01-04 CRITICAL 9.8 CVE-2016-10107EPSS 11% Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header. Mycloud Nas No fix yet Fix from $2,3002017-01-03 CRITICAL 9.8 CVE-2016-10108EPSS 97% Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg … Mycloud Nas No fix yet Fix from $2,3002017-01-03 CRITICAL 9.8 CVE-2016-10034EPSS 38% The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework befor… Zend Framework after 2.4.10 Fix from $2,3002016-12-30 CRITICAL 9.8 CVE-2016-10045EPSS 98% The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute ar… WordPress 5.2.20+ Fix from $2,3002016-12-30 CRITICAL 9.8 CVE-2016-10074EPSS 42% The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail… Swiftmailer after 5.4.4 Fix from $2,3002016-12-30 HIGH 7.2 CVE-2016-6656 An issue was discovered in Pivotal Greenplum before 4.3.10.0. Creation of external tables using GPHDFS protocol has a vulnerability whereby arbitrary… Greenplum after 4.3.9.1 Fix from $1,9502016-12-16 CRITICAL 9.8 CVE-2016-1000156 Mailcwp remote file upload vulnerability incomplete fix v1.100 Mailcwp after 1.100 Fix from $2,3002016-12-14 HIGH 8.8 CVE-2016-6609 An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature… phpMyAdmin Patch available Fix from $1,9502016-12-11 CRITICAL 9.8 CVE-2016-9835 Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to laun… Zikula Application Framework Patch available Fix from $2,3002016-12-05 CRITICAL 9.8 CVE-2015-8969 git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the st… Git Fastclone 1.0.5+ Fix from $2,3002016-11-03 HIGH 8.8 CVE-2015-8968EPSS 5% git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone fr… Git Fastclone 1.0.1+ Fix from $1,9502016-11-03 HIGH 7.8 CVE-2016-0328 IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to… Security Guardium Database Activity Monitor Patch available Fix from $1,9502016-10-22 HIGH 8.8 CVE-2016-0326 IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iF… Rational Collaborative Lifecycle Management Patch available Fix from $1,9502016-10-22 HIGH 8.8 CVE-2016-0236 IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authent… Security Guardium Database Activity Monitor Patch available Fix from $1,9502016-10-21 HIGH 7.8 CVE-2016-0920 Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted … Avamar Server after 7.3.0 Fix from $1,9502016-09-21 HIGH 7.8 CVE-2016-6367 KEVEPSS 23% Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges v… Adaptive Security Appliance Software 8.4 / 9.0+ Fix from $1,9502016-08-18 HIGH 8.8 CVE-2016-2875 IBM Security QRadar SIEM 7.1.x and 7.2.x before 7.2.7 allows remote authenticated users to execute arbitrary OS commands as root via unspecified vect… Qradar Security Information And Event Manager Patch available Fix from $1,9502016-08-08 CRITICAL 9.8 CVE-2016-5640EPSS 18% Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to … Airmedia Am 100 Firmware after 1.2.1 Fix from $2,3002016-08-03 HIGH 8.0 CVE-2016-4822 Corega CG-WLBARGL devices allow remote authenticated users to execute arbitrary commands via unspecified vectors. Cg Wlbargl Firmware Mitigation only Fix from $1,9502016-06-25 CRITICAL 9.8 CVE-2016-1388 Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Network Analysis Module (vNAM) be… Network Analysis Module Mitigation only Fix from $2,3002016-06-03