Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Groupwise HIGH 10.0
CVE-2013-0804EPSS 12%

The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of se…

Mitigation only
Fix from $1,950 2013-02-24
Alphastor HIGH 9.3
CVE-2013-0928EPSS 34%

The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execute arbitra…

No fix yet
Fix from $1,950 2013-01-21
Sinapsi Firmware HIGH 10.0
CVE-2012-5863EPSS 25%

These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges t…

Fix: after 2.0.2870
Fix from $1,950 2012-11-23
Standard HIGH 8.5
CVE-2012-3001EPSS 27%

Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command injection…

Fix: after 4.5-1.10
Fix from $1,950 2012-10-22
Kunai HIGH 9.3
CVE-2012-4011

The Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or …

Fix: after 2.0.5
Fix from $1,950 2012-09-08
San\/iq HIGH 7.7
CVE-2012-4361EPSS 48%

lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via s…

Fix: after 9.0
Fix from $1,950 2012-08-20
San\/iq HIGH 7.7
CVE-2012-2986

lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell me…

Mitigation only
Fix from $1,950 2012-08-20
Uplay Pc HIGH 10.0
CVE-2012-4177EPSS 58%

The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line a…

Fix: after 2.0.3
Fix from $1,950 2012-08-07
Web Gateway HIGH 10.0
CVE-2012-2953EPSS 67%

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to appli…

Mitigation only
Fix from $1,950 2012-07-23
Web Gateway HIGH 10.0
CVE-2012-2976EPSS 5%

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to…

Mitigation only
Fix from $1,950 2012-07-23
Network Controller HIGH 7.5
CVE-2012-2607

The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted pa…

Fix: after 03.1.0.14
Fix from $1,950 2012-07-16
Telepresence System Software HIGH 8.3
CVE-2012-3074

An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging …

Fix: after 1.9.0.1
Fix from $1,950 2012-07-12
Telepresence System Software HIGH 9.0
CVE-2012-3075

The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary…

Fix: after 1.7.2
Fix from $1,950 2012-07-12
Telepresence Recording Server HIGH 9.0
CVE-2012-3076

The administrative web interface on Cisco TelePresence Recording Server before 1.8.0 allows remote authenticated users to execute arbitrary commands …

Fix: after 1.7.3
Fix from $1,950 2012-07-12
Intelligent Platforms Proficy Batch Execution HIGH 9.3
CVE-2012-2516EPSS 40%

An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1…

Mitigation only
Fix from $1,950 2012-07-05
Bcfg2 HIGH 9.0
CVE-2012-3366

The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacha…

Patch available
Fix from $1,950 2012-07-03
Fedora MEDIUM 6.0
CVE-2012-1988

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote aut…

Fix: 2.5.1 / 2.6.15+
Fix from $1,600 2012-05-29
Webglimpse HIGH 7.5
CVE-2012-1795

webglimpse.cgi in Webglimpse before 2.20.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter, as …

Fix: after 2.18.8
Fix from $1,950 2012-03-20
Nikki HIGH 7.5
CVE-2011-4002

HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injectio…

Fix: after 6.6
Fix from $1,950 2011-11-30
Br 6104k Router Firmware HIGH 10.0
CVE-2011-4502EPSS 5%

The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.…

Mitigation only
Fix from $1,950 2011-11-22
E107 HIGH 7.5
CVE-2011-1513EPSS 6%

Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, al…

Fix: after 0.7.24
Fix from $1,950 2011-11-04
Smarterstats HIGH 10.0
CVE-2011-2148EPSS 5%

Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a lead…

Mitigation only
Fix from $1,950 2011-05-20
Messaging Security Gateway HIGH 7.5
CVE-2011-1904

An unspecified function in the web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server…

Fix: after 6.2.0.263
Fix from $1,950 2011-05-05
Otrs HIGH 7.5
CVE-2011-0456

webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, re…

Fix: after 2.3.4
Fix from $1,950 2011-03-11
Telepresence System Software HIGH 9.0
CVE-2011-0375

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allows remote authenticated users to execute arbitrar…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence System Software HIGH 8.3
CVE-2011-0378

The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary comm…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence Manager HIGH 10.0
CVE-2011-0381EPSS 5%

Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to perform unspecified actions and consequently execute arbitrary code via a c…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence Recording Server Software HIGH 10.0
CVE-2011-0382

The CGI subsystem on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 allows remote attackers to execute arbitrary comman…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence System Software HIGH 9.0
CVE-2011-0373

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrar…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence System Software HIGH 9.0
CVE-2011-0374

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrar…

Mitigation only
Fix from $1,950 2011-02-25