Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unified Computing System HIGH 7.2
CVE-2015-4183

Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution via a crafted CLI parameter, aka Bug ID CSCut32795.

Mitigation only
Fix from $1,950 2015-06-17
Milkystep Light HIGH 7.5
CVE-2015-2955

Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to execute arbitrary OS commands via unspecified ve…

Fix: after 1.82
Fix from $1,950 2015-06-13
Wsr 600dhp Firmware HIGH 7.7
CVE-2014-9284

The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60 and earli…

Fix: after 1.60
Fix from $1,950 2015-06-09
Fritz\!box HIGH 10.0
CVE-2014-9727EPSS 72%

AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.

Mitigation only
Fix from $1,950 2015-05-29
Goadmin Ce HIGH 10.0
CVE-2015-2845EPSS 72%

The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arbitrary commands via the $type…

Mitigation only
Fix from $1,950 2015-05-12
Goadmin Ce HIGH 10.0
CVE-2015-2844EPSS 13%

The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $acti…

Mitigation only
Fix from $1,950 2015-05-12
Secure Desktop HIGH 9.3
CVE-2015-0691

A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a …

Mitigation only
Fix from $1,950 2015-04-17
Arubaos HIGH 7.2
CVE-2015-1388

The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point…

Fix: after 6.2.3.9
Fix from $1,950 2015-03-24
Secure Remote Services HIGH 7.5
CVE-2015-0525

The Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary O…

No fix yet
Fix from $1,950 2015-03-12
Intravue HIGH 10.0
CVE-2015-0977

Network Vision IntraVue before 2.3.0a14 on Windows allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Fix: after 2.3.0a11
Fix from $1,950 2015-02-27
Rt N66u Firmware MEDIUM 6.5
CVE-2014-7269

ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers…

Fix: after 3.0.0.4.378.3754
Fix from $1,600 2015-02-01
Webuzo HIGH 7.5
CVE-2013-6041

index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cook…

Fix: after 2.1.3
Fix from $1,950 2014-12-27
Arrows Kiss F 03d HIGH 7.2
CVE-2014-7253

FUJITSU F-12C, ARROWS Tab LTE F-01D, ARROWS Kiss F-03D, and REGZA Phone T-01D for Android allows local users to execute arbitrary commands via unspec…

Mitigation only
Fix from $1,950 2014-12-05
Eki 6340 Firmware HIGH 9.0
CVE-2014-8387EPSS 31%

cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metachar…

No fix yet
Fix from $1,950 2014-11-20
Wp Dbmanager MEDIUM 6.5
CVE-2014-8334

The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute arbitrary commands via shell m…

Fix: after 2.71
Fix from $1,600 2014-10-31
Cyberoam Os HIGH 9.0
CVE-2014-5502

The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_ke…

Fix: after 10.6.1
Fix from $1,950 2014-10-07
Gopro Hero Firmware HIGH 10.0
CVE-2014-6434

gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a restart action.

Mitigation only
Fix from $1,950 2014-10-07
Vyatta 5400 Vrouter Software HIGH 9.0
CVE-2014-4868

The management console on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows remote authenticated users to execute arbitrary Linux co…

Mitigation only
Fix from $1,950 2014-10-07
Security Access Manager For Web 7.0 Firmware HIGH 10.0
CVE-2014-4823

The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security A…

Patch available
Fix from $1,950 2014-10-03
Bash HIGH 8.8
CVE-2014-6278 KEVEPSS 100%

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to…

Patch available
Fix from $1,950 2014-09-30
Bash HIGH 10.0
CVE-2014-6277EPSS 64%

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to…

Patch available
Fix from $1,950 2014-09-27
iOS HIGH 7.8
CVE-2014-3357

Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allo…

Mitigation only
Fix from $1,950 2014-09-25
iOS HIGH 7.8
CVE-2014-3358

Memory leak in Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS befo…

Mitigation only
Fix from $1,950 2014-09-25
iOS HIGH 7.8
CVE-2014-3360

Cisco IOS 12.4 and 15.0 through 15.4 and IOS XE 3.1.xS, 3.2.xS, 3.3.xS, 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7.6S; 3.8.xS, 3.9.xS, and 3.10.xS…

Mitigation only
Fix from $1,950 2014-09-25
Linux CRITICAL 9.8
CVE-2014-7169 KEVEPSS 100%

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which…

Patch available
Fix from $2,300 2014-09-25
Linux CRITICAL 9.8
CVE-2014-6271 KEVEPSS 100%

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to e…

Patch available
Fix from $2,300 2014-09-24
Global Console Manager 16 Firmware HIGH 7.1
CVE-2014-3085EPSS 8%

systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute ar…

Fix: after 1.20.0.22575
Fix from $1,950 2014-08-17
Sip T38g HIGH 9.0
CVE-2013-5758EPSS 12%

cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in …

No fix yet
Fix from $1,950 2014-08-03
Logstash HIGH 7.5
CVE-2014-4326

Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb o…

Mitigation only
Fix from $1,950 2014-07-22
Garoon HIGH 10.0
CVE-2014-1987

The CGI component in Cybozu Garoon 3.1.0 through 3.7 SP3 allows remote attackers to execute arbitrary commands via unspecified vectors.

Mitigation only
Fix from $1,950 2014-07-20