Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Sky Elite 6.0l\+ Firmware HIGH 7.8
CVE-2018-15007

The Sky Elite 6.0L+ Android device with a build fingerprint of SKY/x6069_trx_l601_sky/x6069_trx_l601_sky:6.0/MRA58K/1482897127:user/release-keys cont…

No fix yet
Fix from $1,950 2018-12-28
P1 Firmware MEDIUM 6.8
CVE-2018-14998

The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a hidde…

No fix yet
Fix from $1,600 2018-12-28
Tew 673gru Firmware HIGH 7.2
CVE-2018-19239EPSS 5%

TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remot…

No fix yet
Fix from $1,950 2018-12-20
Phkp CRITICAL 9.8
CVE-2018-1000885

PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Elements used in a Command ('Com…

No fix yet
Fix from $2,300 2018-12-20
Harmony Hub Firmware HIGH 8.1
CVE-2018-15722

The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the mid…

Fix: 4.15.206+
Fix from $1,950 2018-12-20
Vyos CRITICAL 9.9
CVE-2018-18555

A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to administer the device. By issuin…

No fix yet
Fix from $2,300 2018-12-17
G Cam\/efd 2251 Firmware CRITICAL 9.8
CVE-2018-19007

In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration panel) is vulnerable to an OS s…

Fix: 1.12.0.25+
Fix from $2,300 2018-12-14
Dir 619l Firmware HIGH 8.8
CVE-2018-20057EPSS 7%

An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. goform/formSysCmd allows remote authenticated …

No fix yet
Fix from $1,950 2018-12-11
Nport W2x50a Firmware HIGH 8.8
CVE-2018-19659

An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware befor…

Fix: 2.2+
Fix from $1,950 2018-12-06
Nport W2x50a Firmware HIGH 8.8
CVE-2018-19660EPSS 29%

An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware befor…

Fix: 2.2+
Fix from $1,950 2018-12-06
Misp HIGH 8.8
CVE-2018-19908EPSS 17%

An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to constr…

Fix: 2.4.99+
Fix from $1,950 2018-12-06
Crafter Cms HIGH 8.8
CVE-2018-19907

A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/…

Fix: after 3.0.18
Fix from $1,950 2018-12-06
Data Master HIGH 8.8
CVE-2018-12307

OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter.

No fix yet
Fix from $1,950 2018-12-04
Data Master HIGH 8.8
CVE-2018-12312

OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL parameter.

No fix yet
Fix from $1,950 2018-12-04
Data Master CRITICAL 9.8
CVE-2018-12313

OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity…

No fix yet
Fix from $2,300 2018-12-04
Data Master HIGH 8.8
CVE-2018-12316

OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter.

No fix yet
Fix from $1,950 2018-12-04
Data Master HIGH 8.8
CVE-2018-12317

OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST param…

No fix yet
Fix from $1,950 2018-12-04
5n2 Firmware CRITICAL 9.8
CVE-2018-14699EPSS 29%

System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to exec…

No fix yet
Fix from $2,300 2018-12-03
5n2 Firmware CRITICAL 9.8
CVE-2018-14701EPSS 20%

System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to exec…

No fix yet
Fix from $2,300 2018-12-03
5n2 Firmware CRITICAL 9.8
CVE-2018-14706EPSS 17%

System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to e…

No fix yet
Fix from $2,300 2018-12-03
Pfsense HIGH 7.2
CVE-2018-4019EPSS 49%

An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…

No fix yet
Fix from $1,950 2018-12-03
Pfsense HIGH 7.2
CVE-2018-4020EPSS 49%

An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…

No fix yet
Fix from $1,950 2018-12-03
Pfsense HIGH 7.2
CVE-2018-4021EPSS 72%

An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…

No fix yet
Fix from $1,950 2018-12-03
Enterprise Linux Desktop HIGH 7.8
CVE-2018-16863

It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSA…

Patch available
Fix from $1,950 2018-12-03
Nvrmini2 Firmware HIGH 8.8
CVE-2018-15716EPSS 18%

NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to upgrade_handle.php to e…

No fix yet
Fix from $1,950 2018-11-30
Budabot CRITICAL 9.8
CVE-2018-19290

In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote attackers to perform a command injection attack against the…

Fix: after 4.0
Fix from $2,300 2018-11-30
Securesphere CRITICAL 9.8
CVE-2018-19646

The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because c…

No fix yet
Fix from $2,300 2018-11-28
Terramaster Operating System HIGH 8.8
CVE-2018-13418EPSS 5%

System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "newname" parameter.

No fix yet
Fix from $1,950 2018-11-27
Terramaster Operating System HIGH 7.2
CVE-2018-13330EPSS 8%

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands during group creation via the …

No fix yet
Fix from $1,950 2018-11-27
Terramaster Operating System CRITICAL 9.8
CVE-2018-13336EPSS 9%

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during…

No fix yet
Fix from $2,300 2018-11-27