Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Pfsense HIGH 8.8
CVE-2018-16055EPSS 11%

An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passi…

Fix: 2.4.4+
Fix from $1,950 2018-09-26
Fruitywifi CRITICAL 9.8
CVE-2018-17317

FruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the io_mode, ap_mode,…

No fix yet
Fix from $2,300 2018-09-21
Edr 810 Firmware HIGH 8.8
CVE-2018-16282EPSS 5%

A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS…

No fix yet
Fix from $1,950 2018-09-20
Lw N605r Firmware HIGH 8.8
CVE-2018-16752EPSS 43%

LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at ad…

No fix yet
Fix from $1,950 2018-09-20
Nmap4j CRITICAL 9.8
CVE-2018-17228

nmap4j 1.1.0 allows attackers to execute arbitrary commands via shell metacharacters in an includeHosts call.

Patch available
Fix from $2,300 2018-09-19
C1 Firmware HIGH 7.2
CVE-2017-2873EPSS 5%

An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firm…

No fix yet
Fix from $1,950 2018-09-19
Velop Firmware HIGH 8.8
CVE-2018-17208

Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cg…

No fix yet
Fix from $1,950 2018-09-19
Dir 816 A2 Firmware CRITICAL 9.8
CVE-2018-17063

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fu…

No fix yet
Fix from $2,300 2018-09-15
Dir 816 A2 Firmware CRITICAL 9.8
CVE-2018-17064EPSS 7%

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fu…

No fix yet
Fix from $2,300 2018-09-15
Dir 816 A2 Firmware CRITICAL 9.8
CVE-2018-17066EPSS 7%

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler functi…

No fix yet
Fix from $2,300 2018-09-15
Dir 816 A2 Firmware CRITICAL 9.8
CVE-2018-17068

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler functi…

No fix yet
Fix from $2,300 2018-09-15
Debian Linux HIGH 7.8
CVE-2018-16741

An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to p…

Fix: 1.2.1+
Fix from $1,950 2018-09-13
Mgetty HIGH 7.8
CVE-2018-16744

An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow for command …

Fix: 1.2.1+
Fix from $1,950 2018-09-13
Group Controller Firmware CRITICAL 9.8
CVE-2018-15484EPSS 8%

An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Remote Code Execution is possible through the open HTTP …

Fix: 4.6.5+
Fix from $2,300 2018-09-07
Ps CRITICAL 9.8
CVE-2018-16460

A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.

Fix: 1.0.0+
Fix from $2,300 2018-09-07
Nordvpn HIGH 8.8
CVE-2018-3952

An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0. A specially crafted configuration file can caus…

No fix yet
Fix from $1,950 2018-09-07
Protonvpn HIGH 7.8
CVE-2018-4010EPSS 5%

An exploitable code execution vulnerability exists in the connect functionality of ProtonVPN VPN client 1.5.1. A specially crafted configuration file…

No fix yet
Fix from $1,950 2018-09-07
Ubuntu Linux MEDIUM 6.6
CVE-2018-0643

Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker with administrator rights to…

Mitigation only
Fix from $1,600 2018-09-07
Pulse Secure Desktop Client MEDIUM 5.3
CVE-2018-15726

The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Privilege Escalation Vulnerability.

No fix yet
Fix from $1,600 2018-09-06
Openvcloud CRITICAL 9.8
CVE-2018-1000666EPSS 8%

GIG Technology NV JumpScale Portal 7 version before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb contains a CWE-78: Improper Neutralization of Spe…

Fix: 2.3.0+
Fix from $2,300 2018-09-06
Opsview CRITICAL 9.8
CVE-2018-16144EPSS 33%

The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command injection d…

Fix: 5.3.1 / 5.4.2+
Fix from $2,300 2018-09-05
Opsview HIGH 7.2
CVE-2018-16146EPSS 6%

The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated administrator to test notifica…

Fix: 5.4.2+
Fix from $1,950 2018-09-05
Dir 846 Firmware HIGH 7.2
CVE-2018-16408

D-Link DIR-846 devices with firmware 100.26 allow remote attackers to execute arbitrary code as root via a SetNetworkTomographySettings request by le…

No fix yet
Fix from $1,950 2018-09-03
Ac10 Firmware HIGH 8.8
CVE-2018-16334

An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST request is used directly in …

Fix: after 15.03.06.23
Fix from $1,950 2018-09-02
Wifi Switch Firmware CRITICAL 9.8
CVE-2018-15477

myStrom WiFi Switch V1 devices before 2.66 did not sanitize a parameter received from the cloud that was used in an OS command. Malicious servers wer…

Fix: 2.66+
Fix from $2,300 2018-08-30
Foxmail HIGH 8.8
CVE-2018-11616

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115. User interaction is re…

Mitigation only
Fix from $1,950 2018-08-30
Conference Scheduler Cli HIGH 7.8
CVE-2018-14572

In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a crafted .pickle file, as dem…

Fix: after 0.10.1
Fix from $1,950 2018-08-28
Mutiny HIGH 8.8
CVE-2018-15529

A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to th…

Fix: 6.1.0-5263+
Fix from $1,950 2018-08-28
Dsl N12e C1 Firmware HIGH 8.8
CVE-2018-15887

Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allows a remote attacker to execu…

No fix yet
Fix from $1,950 2018-08-27
Plainview Activity Monitor HIGH 8.8
CVE-2018-15877EPSS 77%

The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the ip paramete…

Fix: 20180826+
Fix from $1,950 2018-08-26