Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Netmri HIGH 10.0
CVE-2014-3418EPSS 7%

config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skip…

Fix: after 6.8.4
Fix from $1,950 2014-07-15
Vred HIGH 10.0
CVE-2014-2967EPSS 5%

Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API commands t…

Mitigation only
Fix from $1,950 2014-07-07
Usermin MEDIUM 6.8
CVE-2014-3883

Usermin before 1.600 allows remote attackers to execute arbitrary operating-system commands via unspecified vectors related to a user action.

Fix: after 1.590
Fix from $1,600 2014-06-21
Documentum Content Server HIGH 8.5
CVE-2014-2507

EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to execute…

Fix: after 6.7
Fix from $1,950 2014-06-08
Powervault Ml6000 Firmware HIGH 9.0
CVE-2014-2959

logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with fi…

Mitigation only
Fix from $1,950 2014-06-02
Creme Fraiche HIGH 9.3
CVE-2013-2090

The set_meta_data function in lib/cremefraiche.rb in the Creme Fraiche gem before 0.6.1 for Ruby allows remote attackers to execute arbitrary command…

Fix: after 0.6
Fix from $1,950 2014-05-27
Coscms HIGH 8.5
CVE-2013-1668EPSS 7%

The uploadFile function in upload/index.php in CosCMS before 1.822 allows remote administrators to execute arbitrary commands via shell metacharacter…

Fix: after 1.721
Fix from $1,950 2014-05-23
Ltsp Display Manager HIGH 10.0
CVE-2012-1166

The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETU…

Mitigation only
Fix from $1,950 2014-05-21
Rxvt Unicode HIGH 7.6
CVE-2014-3121

rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window …

Fix: after 9.19
Fix from $1,950 2014-05-14
Caldera HIGH 10.0
CVE-2014-2935

costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute arbitrary commands via shell metacharacters in a me…

Mitigation only
Fix from $1,950 2014-05-08
Content Analysis System Software MEDIUM 6.5
CVE-2014-2565

The commandline interface in Blue Coat Content Analysis System (CAS) 1.1 before 1.1.4.2 allows remote administrators to execute arbitrary commands vi…

Fix: after 1.1.2.1
Fix from $1,600 2014-04-30
Neo4j MEDIUM 6.8
CVE-2013-7259

Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for r…

Mitigation only
Fix from $1,600 2014-04-29
Enterprise Backup HIGH 10.0
CVE-2014-3008EPSS 7%

Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to r…

Mitigation only
Fix from $1,950 2014-04-28
Pillow HIGH 10.0
CVE-2014-3007EPSS 12%

Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in un…

Fix: after 1.1.7
Fix from $1,950 2014-04-27
Tm Ac1900 HIGH 8.5
CVE-2013-5948EPSS 10%

The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows re…

No fix yet
Fix from $1,950 2014-04-22
Cups Filters HIGH 8.3
CVE-2014-2707

cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model …

Mitigation only
Fix from $1,950 2014-04-17
Commonspot Content Server HIGH 10.0
CVE-2014-2874EPSS 5%

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharacters in an unspecified c…

Fix: after 7.0.1
Fix from $1,950 2014-04-15
N300 Netusb Nbg 419n Firmware HIGH 7.9
CVE-2014-0356

The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to execute arbitrary code via shell metacharacters…

Mitigation only
Fix from $1,950 2014-04-15
Xangati Software Release HIGH 9.0
CVE-2014-0359EPSS 7%

Xangati XSR before 11 and XNR before 7 allows remote attackers to execute arbitrary commands via shell metacharacters in a gui_input_test.pl params p…

Mitigation only
Fix from $1,950 2014-04-15
Web Appliance Firmware HIGH 8.5
CVE-2014-2850EPSS 58%

The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary comman…

Fix: after 3.8.1.1
Fix from $1,950 2014-04-11
Img646bd Firmware HIGH 10.0
CVE-2014-1982EPSS 10%

The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmwa…

Mitigation only
Fix from $1,950 2014-03-31
Lotus Protector For Mail Security HIGH 7.1
CVE-2014-0886

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restri…

Mitigation only
Fix from $1,950 2014-03-25
Lotus Protector For Mail Security HIGH 7.1
CVE-2014-0887

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to execute arbitrary commands wi…

Mitigation only
Fix from $1,950 2014-03-25
Web Appliance Firmware HIGH 9.3
CVE-2013-2642EPSS 7%

Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to …

Fix: after 3.7.8.1
Fix from $1,950 2014-03-18
Tealeaf Cx MEDIUM 6.0
CVE-2013-6719EPSS 27%

delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows r…

No fix yet
Fix from $1,600 2014-03-06
Tew 812dru HIGH 8.5
CVE-2013-3365

TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) wan network prefix to …

No fix yet
Fix from $1,950 2014-02-04
N8800 Nas Server Firmware HIGH 10.0
CVE-2013-5667

The Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to execute arbitrary commands via a get_userid action with shell metacharac…

Mitigation only
Fix from $1,950 2014-01-24
Rvs4000 Firmware HIGH 10.0
CVE-2014-0659EPSS 74%

The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000…

Fix: after 2.0.6.1
Fix from $1,950 2014-01-12
Ditto Forensic Fieldstation Firmware HIGH 10.0
CVE-2013-6881EPSS 13%

CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the…

Fix: after 2013jun30a
Fix from $1,950 2014-01-07
Dsr 500 Firmware HIGH 10.0
CVE-2013-5946EPSS 7%

The runShellCmd function in systemCheck.htm in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-25…

Fix: after 1.08b51
Fix from $1,950 2013-12-19