Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2015-4183 Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution via a crafted CLI parameter, aka Bug ID CSCut32795. Unified Computing System Mitigation only Fix from $1,9502015-06-17 HIGH 7.5 CVE-2015-2955 Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to execute arbitrary OS commands via unspecified ve… Milkystep Light after 1.82 Fix from $1,9502015-06-13 HIGH 7.7 CVE-2014-9284 The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60 and earli… Wsr 600dhp Firmware after 1.60 Fix from $1,9502015-06-09 HIGH 10.0 CVE-2014-9727EPSS 72% AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm. Fritz\!box Mitigation only Fix from $1,9502015-05-29 HIGH 10.0 CVE-2015-2845EPSS 72% The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arbitrary commands via the $type… Goadmin Ce Mitigation only Fix from $1,9502015-05-12 HIGH 10.0 CVE-2015-2844EPSS 13% The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $acti… Goadmin Ce Mitigation only Fix from $1,9502015-05-12 HIGH 9.3 CVE-2015-0691 A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a … Secure Desktop Mitigation only Fix from $1,9502015-04-17 HIGH 7.2 CVE-2015-1388 The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point… Arubaos after 6.2.3.9 Fix from $1,9502015-03-24 HIGH 7.5 CVE-2015-0525 The Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary O… Secure Remote Services No fix yet Fix from $1,9502015-03-12 HIGH 10.0 CVE-2015-0977 Network Vision IntraVue before 2.3.0a14 on Windows allows remote attackers to execute arbitrary OS commands via unspecified vectors. Intravue after 2.3.0a11 Fix from $1,9502015-02-27 MEDIUM 6.5 CVE-2014-7269 ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers… Rt N66u Firmware after 3.0.0.4.378.3754 Fix from $1,6002015-02-01 HIGH 7.5 CVE-2013-6041 index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cook… Webuzo after 2.1.3 Fix from $1,9502014-12-27 HIGH 7.2 CVE-2014-7253 FUJITSU F-12C, ARROWS Tab LTE F-01D, ARROWS Kiss F-03D, and REGZA Phone T-01D for Android allows local users to execute arbitrary commands via unspec… Arrows Kiss F 03d Mitigation only Fix from $1,9502014-12-05 HIGH 9.0 CVE-2014-8387EPSS 31% cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metachar… Eki 6340 Firmware No fix yet Fix from $1,9502014-11-20 MEDIUM 6.5 CVE-2014-8334 The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute arbitrary commands via shell m… Wp Dbmanager after 2.71 Fix from $1,6002014-10-31 HIGH 9.0 CVE-2014-5502 The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_ke… Cyberoam Os after 10.6.1 Fix from $1,9502014-10-07 HIGH 10.0 CVE-2014-6434 gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a restart action. Gopro Hero Firmware Mitigation only Fix from $1,9502014-10-07 HIGH 9.0 CVE-2014-4868 The management console on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows remote authenticated users to execute arbitrary Linux co… Vyatta 5400 Vrouter Software Mitigation only Fix from $1,9502014-10-07 HIGH 10.0 CVE-2014-4823 The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security A… Security Access Manager For Web 7.0 Firmware Patch available Fix from $1,9502014-10-03 HIGH 8.8 CVE-2014-6278 KEVEPSS 100% GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to… Bash Patch available Fix from $1,9502014-09-30 HIGH 10.0 CVE-2014-6277EPSS 64% GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to… Bash Patch available Fix from $1,9502014-09-27 HIGH 7.8 CVE-2014-3357 Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allo… iOS Mitigation only Fix from $1,9502014-09-25 HIGH 7.8 CVE-2014-3358 Memory leak in Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS befo… iOS Mitigation only Fix from $1,9502014-09-25 HIGH 7.8 CVE-2014-3360 Cisco IOS 12.4 and 15.0 through 15.4 and IOS XE 3.1.xS, 3.2.xS, 3.3.xS, 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7.6S; 3.8.xS, 3.9.xS, and 3.10.xS… iOS Mitigation only Fix from $1,9502014-09-25 CRITICAL 9.8 CVE-2014-7169 KEVEPSS 100% GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which… Linux Patch available Fix from $2,3002014-09-25 CRITICAL 9.8 CVE-2014-6271 KEVEPSS 100% GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to e… Linux Patch available Fix from $2,3002014-09-24 HIGH 7.1 CVE-2014-3085EPSS 8% systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute ar… Global Console Manager 16 Firmware after 1.20.0.22575 Fix from $1,9502014-08-17 HIGH 9.0 CVE-2013-5758EPSS 12% cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in … Sip T38g No fix yet Fix from $1,9502014-08-03 HIGH 7.5 CVE-2014-4326 Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb o… Logstash Mitigation only Fix from $1,9502014-07-22 HIGH 10.0 CVE-2014-1987 The CGI component in Cybozu Garoon 3.1.0 through 3.7 SP3 allows remote attackers to execute arbitrary commands via unspecified vectors. Garoon Mitigation only Fix from $1,9502014-07-20