Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
MEDIUM 6.5 CVE-2015-4336 cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing … Xcloner No fix yet Fix from $1,6002015-06-17 HIGH 10.0 CVE-2015-3408EPSS 6% Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled … Ubuntu Linux after 0.73 Fix from $1,9502015-05-19 HIGH 9.3 CVE-2015-0538EPSS 7% ftagent.exe in EMC AutoStart 5.4.x and 5.5.x before 5.5.0.508 HF4 allows remote attackers to execute arbitrary commands via crafted packets. Autostart after 5.5.0 Fix from $1,9502015-05-07 HIGH 9.3 CVE-2015-2846 BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link. Sync Mitigation only Fix from $1,9502015-04-13 HIGH 7.5 CVE-2015-0225EPSS 7% The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI in… Cassandra No fix yet Fix from $1,9502015-04-03 HIGH 10.0 CVE-2015-1815EPSS 16% The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via … Fedora after 3.2.21 Fix from $1,9502015-03-30 MEDIUM 6.5 CVE-2015-2746EPSS 25% The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliance… Triton after 7.7 Fix from $1,6002015-03-26 HIGH 7.5 CVE-2015-2265 The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via cons… Ubuntu Linux after 1.0.65 Fix from $1,9502015-03-24 HIGH 7.5 CVE-2015-0778 osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file. Fedora after 0.150 Fix from $1,9502015-03-16 HIGH 7.5 CVE-2015-2208EPSS 62% The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the obje… Phpmoadmin No fix yet Fix from $1,9502015-03-12 MEDIUM 6.5 CVE-2015-0934 Common LaTeX Service Interface (CLSI) before 0.1.3, as used in ShareLaTeX before 0.1.3, allows remote authenticated users to execute arbitrary code v… Sharelatex after 0.1.2 Fix from $1,6002015-03-04 HIGH 10.0 CVE-2014-9682 The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first a… Dns Sync after 0.1.0 Fix from $1,9502015-02-28 HIGH 8.8 CVE-2015-2051 KEVEPSS 97% The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDev… Dir 645 Firmware 1.05b01+ Fix from $1,9502015-02-23 MEDIUM 6.5 CVE-2014-8630 Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execu… Fedora after 4.0.16 Fix from $1,6002015-02-01 MEDIUM 6.8 CVE-2014-9622 Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execu… Xdg Utils No fix yet Fix from $1,6002015-01-21 HIGH 7.5 CVE-2014-7209 run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metach… Mime Support after 3.52-1 Fix from $1,9502015-01-06 HIGH 7.5 CVE-2014-9277 The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 all… Mediawiki after 1.19.21 Fix from $1,9502015-01-04 MEDIUM 6.5 CVE-2013-7418 cgi-bin/iptablesgui.cgi in IPCop (aka IPCop Firewall) before 2.1.5 allows remote authenticated users to execute arbitrary code via shell metacharacte… Ipcop after 2.1.4 Fix from $1,6002015-01-02 MEDIUM 6.8 CVE-2014-3556EPSS 8% The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not p… Nginx 1.6.1 / 1.7.4+ Fix from $1,6002014-12-29 HIGH 10.0 CVE-2014-1905EPSS 10% Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow… Videowhisper Live Streaming Integration after 4.27.4 Fix from $1,9502014-12-29 HIGH 7.5 CVE-2013-4663 git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters i… Redmine Git Hosting Plugin No fix yet Fix from $1,9502014-12-28 HIGH 9.0 CVE-2014-9188EPSS 6% Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code vi… Proclima after 6.0.1 Fix from $1,9502014-12-27 HIGH 7.2 CVE-2014-7208 GParted before 0.15.0 allows local users to execute arbitrary commands with root privileges via shell metacharacters in a crafted filesystem label. Gparted 0.15.0+ Fix from $1,9502014-12-19 MEDIUM 6.5 CVE-2014-7285EPSS 50% The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by… Web Gateway after 5.2.1 Fix from $1,6002014-12-17 MEDIUM 6.8 CVE-2014-6260 Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute arbitrary c… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 MEDIUM 6.8 CVE-2014-8515 The web interface in BitTorrent allows remote attackers to execute arbitrary commands by leveraging knowledge of the pairing values and a crafted req… Bittorrent Mitigation only Fix from $1,6002014-12-12 HIGH 10.0 CVE-2013-2810EPSS 6% Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 a… Dl 8000 Remote Terminal Unit Firmware after 3.50 Fix from $1,9502014-12-08 HIGH 7.5 CVE-2014-8990EPSS 5% default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename. Debian Linux after 2.1.5 Fix from $1,9502014-12-05 HIGH 7.5 CVE-2014-9144EPSS 9% Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (… Td5130 Router Firmware No fix yet Fix from $1,9502014-12-05 HIGH 7.5 CVE-2013-7416 canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a … Canto Curses after 0.9.0 Fix from $1,9502014-12-03