Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 10.0 CVE-2013-0804EPSS 12% The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of se… Groupwise Mitigation only Fix from $1,9502013-02-24 HIGH 9.3 CVE-2013-0928EPSS 34% The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execute arbitra… Alphastor No fix yet Fix from $1,9502013-01-21 HIGH 10.0 CVE-2012-5863EPSS 25% These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges t… Sinapsi Firmware after 2.0.2870 Fix from $1,9502012-11-23 HIGH 8.5 CVE-2012-3001EPSS 27% Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command injection… Standard after 4.5-1.10 Fix from $1,9502012-10-22 HIGH 9.3 CVE-2012-4011 The Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or … Kunai after 2.0.5 Fix from $1,9502012-09-08 HIGH 7.7 CVE-2012-4361EPSS 48% lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via s… San\/iq after 9.0 Fix from $1,9502012-08-20 HIGH 7.7 CVE-2012-2986 lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell me… San\/iq Mitigation only Fix from $1,9502012-08-20 HIGH 10.0 CVE-2012-4177EPSS 58% The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line a… Uplay Pc after 2.0.3 Fix from $1,9502012-08-07 HIGH 10.0 CVE-2012-2953EPSS 67% The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to appli… Web Gateway Mitigation only Fix from $1,9502012-07-23 HIGH 10.0 CVE-2012-2976EPSS 5% The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to… Web Gateway Mitigation only Fix from $1,9502012-07-23 HIGH 7.5 CVE-2012-2607 The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted pa… Network Controller after 03.1.0.14 Fix from $1,9502012-07-16 HIGH 8.3 CVE-2012-3074 An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging … Telepresence System Software after 1.9.0.1 Fix from $1,9502012-07-12 HIGH 9.0 CVE-2012-3075 The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary… Telepresence System Software after 1.7.2 Fix from $1,9502012-07-12 HIGH 9.0 CVE-2012-3076 The administrative web interface on Cisco TelePresence Recording Server before 1.8.0 allows remote authenticated users to execute arbitrary commands … Telepresence Recording Server after 1.7.3 Fix from $1,9502012-07-12 HIGH 9.3 CVE-2012-2516EPSS 40% An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1… Intelligent Platforms Proficy Batch Execution Mitigation only Fix from $1,9502012-07-05 HIGH 9.0 CVE-2012-3366 The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacha… Bcfg2 Patch available Fix from $1,9502012-07-03 MEDIUM 6.0 CVE-2012-1988 Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote aut… Fedora 2.5.1 / 2.6.15+ Fix from $1,6002012-05-29 HIGH 7.5 CVE-2012-1795 webglimpse.cgi in Webglimpse before 2.20.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter, as … Webglimpse after 2.18.8 Fix from $1,9502012-03-20 HIGH 7.5 CVE-2011-4002 HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injectio… Nikki after 6.6 Fix from $1,9502011-11-30 HIGH 10.0 CVE-2011-4502EPSS 5% The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.… Br 6104k Router Firmware Mitigation only Fix from $1,9502011-11-22 HIGH 7.5 CVE-2011-1513EPSS 6% Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, al… E107 after 0.7.24 Fix from $1,9502011-11-04 HIGH 10.0 CVE-2011-2148EPSS 5% Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a lead… Smarterstats Mitigation only Fix from $1,9502011-05-20 HIGH 7.5 CVE-2011-1904 An unspecified function in the web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server… Messaging Security Gateway after 6.2.0.263 Fix from $1,9502011-05-05 HIGH 7.5 CVE-2011-0456 webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, re… Otrs after 2.3.4 Fix from $1,9502011-03-11 HIGH 9.0 CVE-2011-0375 The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allows remote authenticated users to execute arbitrar… Telepresence System Software Mitigation only Fix from $1,9502011-02-25 HIGH 8.3 CVE-2011-0378 The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary comm… Telepresence System Software Mitigation only Fix from $1,9502011-02-25 HIGH 10.0 CVE-2011-0381EPSS 5% Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to perform unspecified actions and consequently execute arbitrary code via a c… Telepresence Manager Mitigation only Fix from $1,9502011-02-25 HIGH 10.0 CVE-2011-0382 The CGI subsystem on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 allows remote attackers to execute arbitrary comman… Telepresence Recording Server Software Mitigation only Fix from $1,9502011-02-25 HIGH 9.0 CVE-2011-0373 The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrar… Telepresence System Software Mitigation only Fix from $1,9502011-02-25 HIGH 9.0 CVE-2011-0374 The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrar… Telepresence System Software Mitigation only Fix from $1,9502011-02-25