Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Encryption Management Server CRITICAL 9.1
CVE-2015-8151

Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging conso…

Fix: after 3.3.2
Fix from $2,300 2016-02-18
Qradar Security Information And Event Manager HIGH 7.4
CVE-2015-4956

The Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to execute unspecified OS commands via unknown…

Mitigation only
Fix from $1,950 2016-02-15
Prime Collaboration MEDIUM 6.7
CVE-2016-1320

The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges,…

Mitigation only
Fix from $1,600 2016-02-12
Firepower Extensible Operating System CRITICAL 9.8
CVE-2015-6435EPSS 9%

An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(…

No fix yet
Fix from $2,300 2016-01-22
Acmailer CRITICAL 9.1
CVE-2016-1142

Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.

Fix: 3.8.21+
Fix from $2,300 2016-01-16
Ubuntu Linux CRITICAL 9.0
CVE-2015-8557EPSS 7%

The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary command…

No fix yet
Fix from $2,300 2016-01-08
Spectrum Protect For Virtual Environments CRITICAL 10.0
CVE-2015-7426

The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Prot…

Mitigation only
Fix from $2,300 2016-01-02
Security Access Manager 9.0 Firmware HIGH 8.0
CVE-2015-5018

IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote a…

Mitigation only
Fix from $1,950 2016-01-02
Mcafee Enterprise Security Manager HIGH 9.3
CVE-2015-8024

McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) 9.3.x be…

Mitigation only
Fix from $1,950 2015-12-02
Firepower Extensible Operating System MEDIUM 6.5
CVE-2015-6380

An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenti…

Mitigation only
Fix from $1,600 2015-11-24
Firepower Extensible Operating System HIGH 7.2
CVE-2015-6370

The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows local users to execute …

Mitigation only
Fix from $1,950 2015-11-19
Pwebmanager MEDIUM 6.5
CVE-2015-7774

PC-EGG pWebManager before 3.3.10, and before 2.2.2 for PHP 4.x, allows remote authenticated users to execute arbitrary OS commands by leveraging the …

Fix: after 3.3.9a
Fix from $1,600 2015-11-14
Endpoint Protection Manager HIGH 7.5
CVE-2015-6554

Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary OS commands via crafted data.

Fix: after 12.1
Fix from $1,950 2015-11-12
Web Security Appliance HIGH 9.0
CVE-2015-6298

The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x befor…

Mitigation only
Fix from $1,950 2015-11-06
Fate\/hollow Ataraxia HIGH 10.0
CVE-2015-5672

TYPE-MOON Fate/stay night, Fate/hollow ataraxia, Witch on the Holy Night, and Fate/stay night + hollow ataraxia set allow remote attackers to execute…

Mitigation only
Fix from $1,950 2015-11-06
Edge Server HIGH 10.0
CVE-2015-7253

The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a cookie.

Mitigation only
Fix from $1,950 2015-11-04
Isucon 5 Qualifier Eventapp MEDIUM 6.5
CVE-2015-5673

eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper popen calls, which allows remo…

Patch available
Fix from $1,600 2015-11-04
Mango Automation MEDIUM 6.5
CVE-2015-7901

Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execute arbitrary OS commands via u…

Patch available
Fix from $1,600 2015-10-28
Smb HIGH 9.0
CVE-2015-7698

icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argument in the…

Fix: after 8.1.1
Fix from $1,950 2015-10-21
Owncloud HIGH 9.0
CVE-2015-4718

The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to exec…

Fix: after 6.0.7
Fix from $1,950 2015-10-21
Refbase HIGH 7.5
CVE-2015-6008

install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword paramet…

Fix: after 0.9.6
Fix from $1,950 2015-09-28
Enterprise Security Manager MEDIUM 6.5
CVE-2015-7310

McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9…

Fix: after 9.5.0
Fix from $1,600 2015-09-22
Web Gateway HIGH 8.5
CVE-2015-5690

The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass …

Fix: after 5.2.2
Fix from $1,950 2015-09-20
Telepresence Video Communication Server Software MEDIUM 6.9
CVE-2015-4330

A local file script in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges for OS command exe…

Mitigation only
Fix from $1,600 2015-09-02
Yodobashi MEDIUM 6.8
CVE-2015-2980

The Yodobashi application 1.2.1.0 and earlier for Android allows remote attackers to execute arbitrary Java methods, and consequently obtain sensitiv…

Fix: after 1.2.1.0
Fix from $1,600 2015-08-08
Yoyaku HIGH 7.5
CVE-2015-2979

Webservice-DIC yoyaku_v41 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

No fix yet
Fix from $1,950 2015-07-29
Unified Computing System HIGH 7.2
CVE-2015-4279

The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing a…

Mitigation only
Fix from $1,950 2015-07-20
Asr 5000 Series Software HIGH 7.2
CVE-2015-4244

The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging ad…

Mitigation only
Fix from $1,950 2015-07-10
Wireless Lan Controller Software HIGH 7.2
CVE-2015-4224

Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands in a privileged context via c…

Mitigation only
Fix from $1,950 2015-06-26
Virtualization Experience Client 6000 Series Firmware HIGH 7.2
CVE-2015-4186

The diagnostics subsystem in the administrative web interface on Cisco Virtualization Experience (aka VXC) Client 6215 devices with firmware 11.2(27.…

Mitigation only
Fix from $1,950 2015-06-17