Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Qts CRITICAL 9.8
CVE-2017-6361EPSS 57%

QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.

Fix: after 4.2.4
Fix from $2,300 2017-03-23
Ossim HIGH 8.4
CVE-2017-6970

AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an NfSen soc…

Fix: after 5.3.6
Fix from $1,950 2017-03-22
Interscan Messaging Security Virtual Appliance HIGH 8.8
CVE-2017-6398EPSS 54%

An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal comman…

No fix yet
Fix from $1,950 2017-03-14
Dgn2200 Series Firmware HIGH 8.8
CVE-2017-6334 KEVEPSS 72%

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell…

Fix: after 10.0.0.50
Fix from $1,950 2017-03-06
Dgn2200 Firmware CRITICAL 9.8
CVE-2017-6077 KEVEPSS 68%

ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell meta…

Fix: after 10.0.0.50
Fix from $2,300 2017-02-22
Secure Firewall Threat Defense MEDIUM 5.3
CVE-2017-3806

A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance cou…

Mitigation only
Fix from $1,600 2017-02-03
Security Guardium HIGH 7.8
CVE-2016-6065

IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.

Patch available
Fix from $1,950 2017-02-01
Web Panel CRITICAL 10.0
CVE-2016-10043EPSS 9%

An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be vulnerable to O…

Mitigation only
Fix from $2,300 2017-01-31
Webex Meetings Server HIGH 7.2
CVE-2017-3796

A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute predetermined shell commands on other hosts. …

Mitigation only
Fix from $1,950 2017-01-26
phpMyAdmin HIGH 7.5
CVE-2016-6631

An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI appli…

Patch available
Fix from $1,950 2016-12-11
Qradar Security Information And Event Manager HIGH 7.5
CVE-2016-2876

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier fo…

Fix: after 7.1.0
Fix from $1,950 2016-11-30
Security Access Manager CRITICAL 9.1
CVE-2016-3028

IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authent…

Mitigation only
Fix from $2,300 2016-11-25
Rational Team Concert MEDIUM 6.3
CVE-2016-0325

IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; R…

Mitigation only
Fix from $1,600 2016-11-24
Telepresence Tc Software MEDIUM 5.5
CVE-2016-6459

Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could allow an authenticated, local attacker to execute a …

Mitigation only
Fix from $1,600 2016-11-19
Wireless H500 HIGH 8.8
CVE-2016-1000216EPSS 7%

Ruckus Wireless H500 web management interface authenticated command injection

No fix yet
Fix from $1,950 2016-10-10
iOS HIGH 7.8
CVE-2016-6414

iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the…

Mitigation only
Fix from $1,950 2016-09-22
Cloud Services Platform 2100 HIGH 7.2
CVE-2016-6373

The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root…

Mitigation only
Fix from $1,950 2016-09-22
Fortiwan HIGH 8.8
CVE-2016-4965

Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary…

Fix: after 4.2.4
Fix from $1,950 2016-09-21
Webex Meetings Server HIGH 8.1
CVE-2016-1482

Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into an application script, aka Bug…

Mitigation only
Fix from $1,950 2016-09-17
Happy Wardrobe HIGH 7.8
CVE-2016-4853

AKABEi SOFT2 games allow remote attackers to execute arbitrary OS commands via crafted saved data, as demonstrated by Happy Wardrobe.

Mitigation only
Fix from $1,950 2016-09-02
Nvrmini 2 HIGH 8.8
CVE-2016-5679EPSS 14%

cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary…

No fix yet
Fix from $1,950 2016-08-31
Telepresence Video Communication Server HIGH 8.8
CVE-2016-1468

The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbi…

Mitigation only
Fix from $1,950 2016-08-08
Rv110w Wireless N Vpn Firewall Firmware HIGH 7.8
CVE-2015-6396

The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via cra…

No fix yet
Fix from $1,950 2016-08-08
Trex CRITICAL 9.8
CVE-2016-6147

An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDadm privileges via unspecified…

No fix yet
Fix from $2,300 2016-08-05
James Server HIGH 8.1
CVE-2015-7611EPSS 69%

Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified v…

No fix yet
Fix from $1,950 2016-06-07
Unified Computing System Platform Emulator HIGH 7.8
CVE-2016-1339

Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted argument…

Mitigation only
Fix from $1,950 2016-04-16
Unified Computing System Central Software CRITICAL 9.8
CVE-2016-1352

Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP…

Mitigation only
Fix from $2,300 2016-04-14
Pan Os CRITICAL 9.8
CVE-2016-3655

The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remo…

Fix: 5.0.18 / 5.1.11+
Fix from $2,300 2016-04-12
Application Control Engine Software HIGH 8.8
CVE-2016-1297

The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated users to bypass intended RBAC res…

Mitigation only
Fix from $1,950 2016-02-26
Basercms MEDIUM 6.3
CVE-2015-7769

baserCMS 3.0.2 through 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.

Patch available
Fix from $1,600 2016-02-19