Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Yi Home Camera Firmware MEDIUM 6.8
CVE-2018-3890

An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can…

No fix yet
Fix from $1,600 2018-11-02
Enterprise Manager HIGH 7.2
CVE-2018-10587

NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions before 10.0.57. These vulnerabilities could allow rem…

Fix: 10.0.57+
Fix from $1,950 2018-11-01
Yi Home Camera Firmware HIGH 8.0
CVE-2018-3910

An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted SSID can…

No fix yet
Fix from $1,950 2018-11-01
Libnmap CRITICAL 9.8
CVE-2018-16461

A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range option…

Fix: 0.4.16+
Fix from $2,300 2018-10-30
Apex Publish Static Files CRITICAL 10.0
CVE-2018-16462EPSS 7%

A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a…

Fix: 2.0.1+
Fix from $2,300 2018-10-30
Ac7 Firmware CRITICAL 9.8
CVE-2018-14558 KEVEPSS 9%

An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9)…

Fix: after 15.03.06.44_cn
Fix from $2,300 2018-10-30
Ac9 Firmware CRITICAL 9.8
CVE-2018-18728

An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code exec…

No fix yet
Fix from $2,300 2018-10-29
Botvac Connected Firmware HIGH 8.1
CVE-2018-18638

A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execute arbitrary commands via she…

No fix yet
Fix from $1,950 2018-10-24
Webex Meetings Desktop HIGH 7.8
CVE-2018-15442EPSS 16%

A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitra…

Fix: 33.0.6 / 33.6.4+
Fix from $1,950 2018-10-24
H.264 Poe Ip Camera Firmware CRITICAL 9.8
CVE-2018-12670

SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow OS Command Injection.

No fix yet
Fix from $2,300 2018-10-19
Ipfire HIGH 8.8
CVE-2018-16232EPSS 8%

An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. This allows an authenticated us…

Patch available
Fix from $1,950 2018-10-17
Dwr 116 Firmware HIGH 8.8
CVE-2018-10823EPSS 78%

An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and D…

Fix: after 2.02
Fix from $1,950 2018-10-17
E1200 Firmware HIGH 7.2
CVE-2018-3953EPSS 14%

Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to O…

No fix yet
Fix from $1,950 2018-10-17
E1200 Firmware HIGH 7.2
CVE-2018-3954

Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to O…

No fix yet
Fix from $1,950 2018-10-17
E1200 Firmware HIGH 7.2
CVE-2018-3955

An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2…

No fix yet
Fix from $1,950 2018-10-17
Pydio HIGH 7.2
CVE-2018-14772EPSS 7%

Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web applicat…

Fix: after 8.2.1
Fix from $1,950 2018-10-16
Rut900 Firmware CRITICAL 9.8
CVE-2018-17532EPSS 71%

Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi a…

Fix: 00.04.233+
Fix from $2,300 2018-10-15
Webpanel CRITICAL 9.8
CVE-2018-18322EPSS 15%

CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service…

No fix yet
Fix from $2,300 2018-10-15
Ios Xe MEDIUM 6.7
CVE-2018-0477

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux s…

Mitigation only
Fix from $1,600 2018-10-05
Ios Xe MEDIUM 6.7
CVE-2018-0481

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux s…

Mitigation only
Fix from $1,600 2018-10-05
Ios Xe MEDIUM 6.7
CVE-2018-15368

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell …

Mitigation only
Fix from $1,600 2018-10-05
Secure Firewall Threat Defense HIGH 8.2
CVE-2018-0453

A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) …

Mitigation only
Fix from $1,950 2018-10-05
Vedge 100 Firmware HIGH 8.8
CVE-2018-0432

A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges…

Fix: 18.3.0+
Fix from $1,950 2018-10-05
Vedge 100 Firmware HIGH 7.8
CVE-2018-0433

A vulnerability in the command-line interface (CLI) in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbitrary com…

Fix: 18.3.0+
Fix from $1,950 2018-10-05
Rv110w Firmware HIGH 8.8
CVE-2018-0424

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, …

Fix: 1.0.3.44+
Fix from $1,950 2018-10-05
Dir 823g Firmware CRITICAL 9.8
CVE-2018-17787

On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because this data is…

No fix yet
Fix from $2,300 2018-10-02
H660gw Firmware HIGH 7.2
CVE-2018-17867

The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell metacharacters in the cgi-bin/a…

No fix yet
Fix from $1,950 2018-10-01
Lenovoemc Firmware HIGH 8.1
CVE-2018-9075

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a comman…

Fix: after 4.1.402.34662
Fix from $1,950 2018-09-28
Lenovoemc Firmware HIGH 8.1
CVE-2018-9076

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command…

Fix: after 4.1.402.34662
Fix from $1,950 2018-09-28
Lenovoemc Firmware HIGH 8.1
CVE-2018-9077

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command…

Fix: after 4.1.402.34662
Fix from $1,950 2018-09-28