Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Terramaster Operating System CRITICAL 9.8
CVE-2018-13338EPSS 10%

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter d…

No fix yet
Fix from $2,300 2018-11-27
Terramaster Operating System HIGH 8.8
CVE-2018-13353EPSS 6%

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute commands via the "checkport" parameter.

No fix yet
Fix from $1,950 2018-11-27
Terramaster Operating System CRITICAL 9.8
CVE-2018-13354EPSS 23%

System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.

No fix yet
Fix from $2,300 2018-11-27
Terramaster Operating System HIGH 8.8
CVE-2018-13358EPSS 25%

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter.

No fix yet
Fix from $1,950 2018-11-27
Miwifi Os HIGH 8.8
CVE-2018-13023EPSS 24%

System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via the "time…

No fix yet
Fix from $1,950 2018-11-27
A3002ru Firmware CRITICAL 9.8
CVE-2018-13306

System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter.

No fix yet
Fix from $2,300 2018-11-27
A3002ru Firmware CRITICAL 9.8
CVE-2018-13307

System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST paramet…

No fix yet
Fix from $2,300 2018-11-27
A3002ru Firmware CRITICAL 9.8
CVE-2018-13314

System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ipAddr" POST parameter.

No fix yet
Fix from $2,300 2018-11-27
A3002ru Firmware CRITICAL 9.8
CVE-2018-13316

System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "subnet" POST parameter.

No fix yet
Fix from $2,300 2018-11-27
Nsa325 V2 Firmware HIGH 8.8
CVE-2018-14893

A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web applic…

No fix yet
Fix from $1,950 2018-11-27
Miwifi Os HIGH 8.8
CVE-2018-16130EPSS 24%

System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload…

No fix yet
Fix from $1,950 2018-11-27
System Management Module Firmware HIGH 7.5
CVE-2018-16089

In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing p…

Fix: 1.06+
Fix from $1,950 2018-11-27
System Management Module Firmware HIGH 7.5
CVE-2018-16090

In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command…

Fix: 1.06+
Fix from $1,950 2018-11-27
A3002ru Firmware CRITICAL 9.8
CVE-2018-13311

System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.

Mitigation only
Fix from $2,300 2018-11-26
Ts5600d1206 Firmware HIGH 7.2
CVE-2018-13318

System command injection in User.create method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute system commands via the "name" pa…

No fix yet
Fix from $1,950 2018-11-26
Ts5600d1206 Firmware HIGH 7.2
CVE-2018-13320

System Command Injection in network.set_auth_settings in Buffalo TS5600D1206 version 3.70-0.10 allows attackers to execute system commands via the ad…

No fix yet
Fix from $1,950 2018-11-26
Vsphere Data Protection MEDIUM 6.7
CVE-2018-11077

'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Pro…

Patch available
Fix from $1,600 2018-11-26
Liquidvpn HIGH 7.8
CVE-2018-18856

Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate …

Fix: after 1.37
Fix from $1,950 2018-11-20
Liquidvpn HIGH 7.8
CVE-2018-18857

Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate …

Fix: after 1.37
Fix from $1,950 2018-11-20
Liquidvpn HIGH 7.8
CVE-2018-18858

Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate …

Fix: after 1.37
Fix from $1,950 2018-11-20
Liquidvpn HIGH 7.8
CVE-2018-18859

Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate …

Fix: after 1.37
Fix from $1,950 2018-11-20
Thinkserver Rd340 Firmware HIGH 7.2
CVE-2018-9086

In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged u…

Fix: 60.00 / 64.00+
Fix from $1,950 2018-11-16
Filezen CRITICAL 9.8
CVE-2018-0694

FileZen V3.0.0 to V4.2.1 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Fix: after 4.2.1
Fix from $2,300 2018-11-15
Nagios Xi HIGH 8.8
CVE-2018-15709EPSS 21%

Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.

No fix yet
Fix from $1,950 2018-11-14
Nagios Xi HIGH 7.8
CVE-2018-15710EPSS 44%

Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.

No fix yet
Fix from $1,950 2018-11-14
Nagios Xi HIGH 8.8
CVE-2018-15711EPSS 36%

Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new…

No fix yet
Fix from $1,950 2018-11-14
Fruitywifi CRITICAL 9.8
CVE-2018-19168EPSS 7%

Shell Metacharacter Injection in www/modules/save.php in FruityWifi (aka PatatasFritas/PatataWifi) through 2.4 allows remote attackers to execute arb…

Fix: after 2.4
Fix from $2,300 2018-11-11
I5 Application Firmware CRITICAL 9.8
CVE-2018-19081

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS m…

No fix yet
Fix from $2,300 2018-11-07
I5 Application Firmware HIGH 7.2
CVE-2018-19073

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…

No fix yet
Fix from $1,950 2018-11-07
I5 Application Firmware HIGH 7.2
CVE-2018-19070

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…

No fix yet
Fix from $1,950 2018-11-07