Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 9.0 CVE-2013-7103 McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the value attribute in … Email Gateway No fix yet Fix from $1,9502013-12-14 HIGH 9.0 CVE-2013-7104 McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) … Email Gateway No fix yet Fix from $1,9502013-12-14 MEDIUM 6.8 CVE-2013-4457 The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, related to re… Cocaine Mitigation only Fix from $1,6002013-11-02 HIGH 9.0 CVE-2013-5530 The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.… Identity Services Engine Software Mitigation only Fix from $1,9502013-10-25 MEDIUM 6.8 CVE-2013-5703 The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted… Vigor 2700 Router Firmware Mitigation only Fix from $1,6002013-10-22 MEDIUM 6.8 CVE-2012-4108 The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary operating-syste… Unified Computing System Mitigation only Fix from $1,6002013-10-13 HIGH 10.0 CVE-2013-2578EPSS 74% cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P… Tl Sc3130 after 1.6.18p12_sign5 Fix from $1,9502013-10-11 HIGH 7.2 CVE-2012-4075 Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via shell metacharacters in unspecified command parameters, aka Bug … Nx Os Mitigation only Fix from $1,9502013-10-05 HIGH 10.0 CVE-2013-5486EPSS 76% Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows r… Prime Data Center Network Manager Mitigation only Fix from $1,9502013-09-23 HIGH 7.2 CVE-2013-4984EPSS 8% The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain… Web Appliance after 3.7.9 Fix from $1,9502013-09-10 HIGH 10.0 CVE-2013-4983EPSS 90% The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to execute … Web Appliance Firmware after 3.7.9 Fix from $1,9502013-09-10 HIGH 9.0 CVE-2012-6591 The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote authenticated administra… Pan Os after 3.1.9 Fix from $1,9502013-08-31 HIGH 10.0 CVE-2012-6592 Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref… Pan Os after 3.1.9 Fix from $1,9502013-08-31 HIGH 10.0 CVE-2012-6593 Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref… Pan Os after 3.1.9 Fix from $1,9502013-08-31 HIGH 9.0 CVE-2012-6594 The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11, 4.0.x before 4.0.8, and 4.1.x before 4.1.1 allows remote aut… Pan Os after 3.1.10 Fix from $1,9502013-08-31 HIGH 9.0 CVE-2012-6595 The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated admin… Pan Os Mitigation only Fix from $1,9502013-08-31 HIGH 9.0 CVE-2012-6598 The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote authenticated users to execute arbitrary c… Pan Os Mitigation only Fix from $1,9502013-08-31 HIGH 9.0 CVE-2012-6599 The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 and 4.1.x before 4.1.1 allows remote authenticated users… Pan Os Mitigation only Fix from $1,9502013-08-31 HIGH 9.0 CVE-2012-6600 The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users… Pan Os Mitigation only Fix from $1,9502013-08-31 HIGH 10.0 CVE-2012-6601 The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote at… Pan Os after 3.1.11 Fix from $1,9502013-08-31 HIGH 9.0 CVE-2012-6602 The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote authenticated users to e… Pan Os after 3.1.9 Fix from $1,9502013-08-31 HIGH 9.0 CVE-2012-6604 The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to e… Pan Os after 3.1.10 Fix from $1,9502013-08-31 HIGH 9.0 CVE-2012-6605 The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to e… Pan Os after 3.1.10 Fix from $1,9502013-08-31 HIGH 9.0 CVE-2013-3444 The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5… Wide Area Application Services Mitigation only Fix from $1,9502013-08-01 HIGH 8.3 CVE-2013-1616EPSS 11% The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbitrary commands by injecting a … Web Gateway after 5.1 Fix from $1,9502013-08-01 HIGH 10.0 CVE-2013-4781 core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R… Openscape Session Border Controller Mitigation only Fix from $1,9502013-07-18 HIGH 9.0 CVE-2013-3578 SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote authenticated users to exe… Embassy Remote Administration Server Mitigation only Fix from $1,9502013-07-15 HIGH 9.0 CVE-2013-3576EPSS 67% ginkgosnmp.inc in HP System Management Homepage (SMH) allows remote authenticated users to execute arbitrary commands via shell metacharacters in the… System Management Homepage No fix yet Fix from $1,9502013-06-14 HIGH 9.3 CVE-2013-1933 The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows context-dependen… Karteek Docsplit Mitigation only Fix from $1,9502013-04-25 HIGH 9.3 CVE-2013-1947 kelredd-pruview gem 0.3.8 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename argument t… Kelredd Pruview Mitigation only Fix from $1,9502013-04-25