Vulnerabilities (CVE)

Filtered by CWE-78
Total 5705 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-1142 1 Seeds 1 Acmailer 2026-05-06 9.0 HIGH 9.1 CRITICAL
Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
CVE-2012-1166 1 Canonical 2 Ltsp Display Manager, Ubuntu Linux 2026-05-06 10.0 HIGH N/A
The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window.
CVE-2015-7253 1 Commvault 1 Edge Server 2026-05-06 10.0 HIGH N/A
The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a cookie.
CVE-2013-1668 1 Coscms 1 Coscms 2026-05-06 8.5 HIGH N/A
The uploadFile function in upload/index.php in CosCMS before 1.822 allows remote administrators to execute arbitrary commands via shell metacharacters in the name of an uploaded file.
CVE-2016-1141 1 Kddi 2 Home Spot Cube, Home Spot Cube Firmware 2026-05-06 6.5 MEDIUM 4.7 MEDIUM
KDDI HOME SPOT CUBE devices before 2 allow remote authenticated users to execute arbitrary OS commands via unspecified vectors.
CVE-2015-2844 1 Goautodial 1 Goadmin Ce 2026-05-06 10.0 HIGH N/A
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $action portion of the PATH_INFO.
CVE-2015-4244 1 Cisco 1 Asr 5000 Series Software 2026-05-06 7.2 HIGH N/A
The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.
CVE-2014-2935 1 Caldera 1 Caldera 2026-05-06 10.0 HIGH N/A
costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute arbitrary commands via shell metacharacters in a methodCall element in a PHP XMLRPC request.
CVE-2014-3358 1 Cisco 2 Ios, Ios Xe 2026-05-06 7.8 HIGH N/A
Memory leak in Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allows remote attackers to cause a denial of service (memory consumption, and interface queue wedge or device reload) via malformed mDNS packets, aka Bug ID CSCuj58950.
CVE-2014-6434 1 Gopro 2 Gopro Hero, Gopro Hero Firmware 2026-05-06 10.0 HIGH N/A
gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a restart action.
CVE-2016-1320 1 Cisco 1 Prime Collaboration 2026-05-06 6.8 MEDIUM 6.7 MEDIUM
The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges, aka Bug ID CSCux69286.
CVE-2015-7769 1 Basercms 1 Basercms 2026-05-06 6.5 MEDIUM 6.3 MEDIUM
baserCMS 3.0.2 through 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
CVE-2016-6631 1 Phpmyadmin 1 Phpmyadmin 2026-05-06 8.5 HIGH 7.5 HIGH
An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the file generator_plugin.sh. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
CVE-2016-1339 1 Cisco 1 Unified Computing System Platform Emulator 2026-05-06 7.2 HIGH 7.8 HIGH
Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted arguments on a ucspe-copy command line, aka Bug ID CSCux68832.
CVE-2014-3121 1 Marc Lehmann 1 Rxvt-unicode 2026-05-06 7.6 HIGH N/A
rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.
CVE-2016-6414 1 Cisco 1 Ios 2026-05-06 7.2 HIGH 7.8 HIGH
iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223.
CVE-2014-2967 1 Autodesk 1 Vred 2026-05-06 10.0 HIGH N/A
Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API commands to the integrated web server.
CVE-2014-0887 1 Ibm 1 Lotus Protector For Mail Security 2026-05-06 7.1 HIGH N/A
The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.
CVE-2014-3883 1 Webmin 1 Usermin 2026-05-06 6.8 MEDIUM N/A
Usermin before 1.600 allows remote attackers to execute arbitrary operating-system commands via unspecified vectors related to a user action.
CVE-2015-4186 1 Cisco 1 Virtualization Experience Client 6000 Series Firmware 2026-05-06 7.2 HIGH N/A
The diagnostics subsystem in the administrative web interface on Cisco Virtualization Experience (aka VXC) Client 6215 devices with firmware 11.2(27.4) allows local users to gain privileges for OS command execution via a crafted option value, aka Bug ID CSCug54412.