Vulnerabilities (CVE)

Filtered by CWE-78
Total 5705 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-4868 1 Brocade 2 Vyatta 5400 Vrouter, Vyatta 5400 Vrouter Software 2026-05-06 9.0 HIGH N/A
The management console on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows remote authenticated users to execute arbitrary Linux commands via shell metacharacters in a console command.
CVE-2016-2876 1 Ibm 1 Qradar Security Information And Event Manager 2026-05-06 8.5 HIGH 7.5 HIGH
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier for remote authenticated users to obtain root access by leveraging a command-injection issue.
CVE-2015-6370 1 Cisco 1 Firepower Extensible Operating System 2026-05-06 7.2 HIGH N/A
The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows local users to execute arbitrary OS commands as root via crafted CLI input, aka Bug ID CSCux10578.
CVE-2013-5758 1 Yealink 1 Sip-t38g 2026-05-06 9.0 HIGH N/A
cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running unauthorized services, changing directory permissions, and modifying files.
CVE-2015-2845 1 Goautodial 1 Goadmin Ce 2026-05-06 10.0 HIGH N/A
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arbitrary commands via the $type portion of the PATH_INFO.
CVE-2016-4965 1 Fortinet 1 Fortiwan 2026-05-06 9.0 HIGH 8.8 HIGH
Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary commands with root privileges via the graph parameter to diagnosis_control.php.
CVE-2016-3028 1 Ibm 2 Security Access Manager, Security Access Manager For Web 2026-05-06 9.0 HIGH 9.1 CRITICAL
IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.
CVE-2014-3085 1 Ibm 2 Global Console Manager 16 Firmware, Global Console Manager 32 Firmware 2026-05-06 7.1 HIGH N/A
systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the lpres parameter.
CVE-2016-1352 1 Cisco 1 Unified Computing System Central Software 2026-05-06 7.5 HIGH 9.8 CRITICAL
Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuv33856.
CVE-2016-1000216 1 Ruckus 1 Wireless H500 2026-05-06 9.0 HIGH 8.8 HIGH
Ruckus Wireless H500 web management interface authenticated command injection
CVE-2015-8024 1 Mcafee 1 Mcafee Enterprise Security Manager 2026-05-06 9.3 HIGH N/A
McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) 9.3.x before 9.3.2MR19, 9.4.x before 9.4.2MR9, and 9.5.x before 9.5.0MR8, when configured to use Active Directory or LDAP authentication sources, allow remote attackers to bypass authentication by logging in with the username "NGCP|NGCP|NGCP;" and any password.
CVE-2014-9727 1 Avm 1 Fritz\!box 2026-05-06 10.0 HIGH N/A
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.
CVE-2015-5673 1 Isucon 1 Isucon 5 Qualifier Eventapp 2026-05-06 6.5 MEDIUM N/A
eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper popen calls, which allows remote attackers to execute arbitrary commands via an HTTP request that includes shell metacharacters in an argument to a "gcloud compute" command.
CVE-2013-6719 1 Ibm 1 Tealeaf Cx 2026-05-06 6.0 MEDIUM N/A
delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the testconn_host parameter.
CVE-2013-6041 1 Softaculous 1 Webuzo 2026-05-06 7.5 HIGH N/A
index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action.
CVE-2014-2565 1 Bluecoat 2 Content Analysis System, Content Analysis System Software 2026-05-06 6.5 MEDIUM N/A
The commandline interface in Blue Coat Content Analysis System (CAS) 1.1 before 1.1.4.2 allows remote administrators to execute arbitrary commands via unspecified vectors, related to "command injection."
CVE-2016-1468 1 Cisco 1 Telepresence Video Communication Server 2026-05-06 6.5 MEDIUM 8.8 HIGH
The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531.
CVE-2015-5018 1 Ibm 3 Security Access Manager 9.0 Firmware, Security Access Manager For Web 7.0 Firmware, Security Access Manager For Web 8.0 Firmware 2026-05-06 8.5 HIGH 8.0 HIGH
IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote authenticated users to execute arbitrary OS commands by leveraging Local Management Interface (LMI) access.
CVE-2015-4279 1 Cisco 1 Unified Computing System 2026-05-06 7.2 HIGH N/A
The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing arbitrary CLI commands by leveraging access to the subordinate fabric interconnect, aka Bug ID CSCut32778.
CVE-2014-4823 1 Ibm 5 Security Access Manager For Mobile 8.0 Firmware, Security Access Manager For Mobile Appliance, Security Access Manager For Web 7.0 Firmware and 2 more 2026-05-06 10.0 HIGH N/A
The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject system commands via unspecified vectors.