Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Email Gateway HIGH 9.0
CVE-2013-7103

McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the value attribute in …

No fix yet
Fix from $1,950 2013-12-14
Email Gateway HIGH 9.0
CVE-2013-7104

McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) …

No fix yet
Fix from $1,950 2013-12-14
Cocaine MEDIUM 6.8
CVE-2013-4457

The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, related to re…

Mitigation only
Fix from $1,600 2013-11-02
Identity Services Engine Software HIGH 9.0
CVE-2013-5530

The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.…

Mitigation only
Fix from $1,950 2013-10-25
Vigor 2700 Router Firmware MEDIUM 6.8
CVE-2013-5703

The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted…

Mitigation only
Fix from $1,600 2013-10-22
Unified Computing System MEDIUM 6.8
CVE-2012-4108

The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary operating-syste…

Mitigation only
Fix from $1,600 2013-10-13
Tl Sc3130 HIGH 10.0
CVE-2013-2578EPSS 74%

cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P…

Fix: after 1.6.18p12_sign5
Fix from $1,950 2013-10-11
Nx Os HIGH 7.2
CVE-2012-4075

Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via shell metacharacters in unspecified command parameters, aka Bug …

Mitigation only
Fix from $1,950 2013-10-05
Prime Data Center Network Manager HIGH 10.0
CVE-2013-5486EPSS 76%

Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows r…

Mitigation only
Fix from $1,950 2013-09-23
Web Appliance HIGH 7.2
CVE-2013-4984EPSS 8%

The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain…

Fix: after 3.7.9
Fix from $1,950 2013-09-10
Web Appliance Firmware HIGH 10.0
CVE-2013-4983EPSS 90%

The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to execute …

Fix: after 3.7.9
Fix from $1,950 2013-09-10
Pan Os HIGH 9.0
CVE-2012-6591

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote authenticated administra…

Fix: after 3.1.9
Fix from $1,950 2013-08-31
Pan Os HIGH 10.0
CVE-2012-6592

Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref…

Fix: after 3.1.9
Fix from $1,950 2013-08-31
Pan Os HIGH 10.0
CVE-2012-6593

Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref…

Fix: after 3.1.9
Fix from $1,950 2013-08-31
Pan Os HIGH 9.0
CVE-2012-6594

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11, 4.0.x before 4.0.8, and 4.1.x before 4.1.1 allows remote aut…

Fix: after 3.1.10
Fix from $1,950 2013-08-31
Pan Os HIGH 9.0
CVE-2012-6595

The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated admin…

Mitigation only
Fix from $1,950 2013-08-31
Pan Os HIGH 9.0
CVE-2012-6598

The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote authenticated users to execute arbitrary c…

Mitigation only
Fix from $1,950 2013-08-31
Pan Os HIGH 9.0
CVE-2012-6599

The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 and 4.1.x before 4.1.1 allows remote authenticated users…

Mitigation only
Fix from $1,950 2013-08-31
Pan Os HIGH 9.0
CVE-2012-6600

The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users…

Mitigation only
Fix from $1,950 2013-08-31
Pan Os HIGH 10.0
CVE-2012-6601

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote at…

Fix: after 3.1.11
Fix from $1,950 2013-08-31
Pan Os HIGH 9.0
CVE-2012-6602

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote authenticated users to e…

Fix: after 3.1.9
Fix from $1,950 2013-08-31
Pan Os HIGH 9.0
CVE-2012-6604

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to e…

Fix: after 3.1.10
Fix from $1,950 2013-08-31
Pan Os HIGH 9.0
CVE-2012-6605

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to e…

Fix: after 3.1.10
Fix from $1,950 2013-08-31
Wide Area Application Services HIGH 9.0
CVE-2013-3444

The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5…

Mitigation only
Fix from $1,950 2013-08-01
Web Gateway HIGH 8.3
CVE-2013-1616EPSS 11%

The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbitrary commands by injecting a …

Fix: after 5.1
Fix from $1,950 2013-08-01
Openscape Session Border Controller HIGH 10.0
CVE-2013-4781

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R…

Mitigation only
Fix from $1,950 2013-07-18
Embassy Remote Administration Server HIGH 9.0
CVE-2013-3578

SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote authenticated users to exe…

Mitigation only
Fix from $1,950 2013-07-15
System Management Homepage HIGH 9.0
CVE-2013-3576EPSS 67%

ginkgosnmp.inc in HP System Management Homepage (SMH) allows remote authenticated users to execute arbitrary commands via shell metacharacters in the…

No fix yet
Fix from $1,950 2013-06-14
Karteek Docsplit HIGH 9.3
CVE-2013-1933

The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows context-dependen…

Mitigation only
Fix from $1,950 2013-04-25
Kelredd Pruview HIGH 9.3
CVE-2013-1947

kelredd-pruview gem 0.3.8 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename argument t…

Mitigation only
Fix from $1,950 2013-04-25