Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Reporter HIGH 7.2
CVE-2018-12237

The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated…

Fix: 10.1.5.6 / 10.2.1.8+
Fix from $1,950 2019-01-24
Vedge 100 Firmware HIGH 8.8
CVE-2019-1650

A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating s…

Fix: 18.4.0+
Fix from $1,950 2019-01-24
Rv320 Firmware HIGH 7.2
CVE-2019-1652 KEVEPSS 96%

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticat…

Fix: 1.4.2.22+
Fix from $1,950 2019-01-24
Launcher HIGH 8.8
CVE-2018-17707

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Epic Games Launcher versions prior to 8.2.2. User…

Fix: 8.2.2+
Fix from $1,950 2019-01-24
Webex Teams HIGH 7.8
CVE-2019-1636EPSS 47%

A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. Th…

Mitigation only
Fix from $1,950 2019-01-23
Network Advisor CRITICAL 9.8
CVE-2018-6444

A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote unauthenticated attacker to execute arbitray code. The vulnera…

Fix: 14.1.0+
Fix from $2,300 2019-01-22
Tl Wdr5620 Firmware HIGH 8.8
CVE-2019-6487EPSS 9%

TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execu…

Fix: after 3.0
Fix from $1,950 2019-01-18
Nedi HIGH 8.8
CVE-2018-20727EPSS 6%

Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt parameter t…

Fix: after 1.7c
Fix from $1,950 2019-01-17
D2200 Firmware CRITICAL 9.8
CVE-2018-16184

RICOH Interactive Whiteboard D2200 V1.6 to V2.2, D5500 V1.6 to V2.2, D5510 V1.6 to V2.2, and the display versions with RICOH Interactive Whiteboard C…

Fix: after 2.2
Fix from $2,300 2019-01-09
Aterm Wf1200cr Firmware HIGH 7.2
CVE-2018-16194

Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated a…

Fix: after 1.1.1
Fix from $1,950 2019-01-09
Aterm Wf1200cr Firmware HIGH 8.8
CVE-2018-16195

Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows an attacker on …

Fix: after 1.1.1
Fix from $1,950 2019-01-09
Hem Gw16a Firmware HIGH 8.8
CVE-2018-16200

Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to …

Fix: after 1.2.9
Fix from $1,950 2019-01-09
Logontracer CRITICAL 9.8
CVE-2018-16167EPSS 75%

LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Fix: after 1.2.0
Fix from $2,300 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0638

Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via import.cgi encKey parameter.

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0639

Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via tools_firmware.cgi date parameter, …

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Bn Sdwbp3 Firmware MEDIUM 6.8
CVE-2018-0677

BN-SDWBP3 firmware version 1.0.9 and earlier allows attacker with administrator rights on the same network segment to execute arbitrary OS commands v…

Fix: after 1.0.9
Fix from $1,600 2019-01-09
Aterm Wg1200hp Firmware HIGH 7.2
CVE-2018-0625

Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via formSysCmd parameter.

Fix: after 1.0.31
Fix from $1,950 2019-01-09
Aterm Wg1200hp Firmware HIGH 7.2
CVE-2018-0626

Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd in formWsc parame…

Fix: after 1.0.31
Fix from $1,950 2019-01-09
Aterm Wg1200hp Firmware HIGH 7.2
CVE-2018-0627

Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.

Fix: after 1.0.31
Fix from $1,950 2019-01-09
Aterm Wg1200hp Firmware HIGH 7.2
CVE-2018-0628

Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and respons…

Fix: after 1.0.31
Fix from $1,950 2019-01-09
Aterm W300p Firmware HIGH 7.2
CVE-2018-0629

Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.

Fix: after 1.0.13
Fix from $1,950 2019-01-09
Aterm W300p Firmware HIGH 7.2
CVE-2018-0630

Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd parameter.

Fix: after 1.0.13
Fix from $1,950 2019-01-09
Aterm W300p Firmware HIGH 7.2
CVE-2018-0631

Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.

Fix: after 1.0.13
Fix from $1,950 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0634

Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter or bootmo…

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0635

Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via filename parameter.

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0636

Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter of a cert…

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0637

Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via export.cgi encKey parameter.

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Dir 818lw Firmware CRITICAL 9.8
CVE-2018-20114EPSS 7%

On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS command execution can occur in the soap.cgi service…

No fix yet
Fix from $2,300 2019-01-02
React Dev Utils CRITICAL 9.8
CVE-2018-6342

react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The in…

Fix: 1.0.4 / 2.0.2+
Fix from $2,300 2018-12-31
180 Outdoor Firmware HIGH 8.1
CVE-2018-18600

The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.

Mitigation only
Fix from $1,950 2018-12-31