Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Tl Wr841n Firmware HIGH 8.8
CVE-2018-12577

The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow authenticated blind Comma…

Mitigation only
Fix from $1,950 2018-07-02
Prtg Network Monitor HIGH 7.2
CVE-2018-9276 KEVEPSS 87%

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administ…

Fix: 18.2.39 / 21.2.68+
Fix from $1,950 2018-07-02
Secure Messaging Gateway HIGH 7.2
CVE-2018-12465EPSS 79%

An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker auth…

Fix: 471+
Fix from $1,950 2018-06-29
Opentsdb CRITICAL 9.8
CVE-2018-12972

An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and th…

Mitigation only
Fix from $2,300 2018-06-29
Adm CRITICAL 9.8
CVE-2018-11510EPSS 45%

The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by…

Fix: after 3.1.2.rhg1
Fix from $2,300 2018-06-28
A1001 Firmware CRITICAL 9.8
CVE-2018-10660EPSS 82%

An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.

Fix: 1.65.0 / 1.65.1+
Fix from $2,300 2018-06-26
Scalance M875 Firmware HIGH 7.2
CVE-2018-4859

A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the web interface (443/tcp), cou…

Mitigation only
Fix from $1,950 2018-06-26
Scalance M875 Firmware HIGH 7.2
CVE-2018-4860

A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the web interface (443/tcp), cou…

Mitigation only
Fix from $1,950 2018-06-26
Basercms HIGH 8.8
CVE-2018-0569

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to execute arbitrary OS …

Fix: after 4.1.0.1
Fix from $1,950 2018-06-26
Tl Wa850re Firmware HIGH 8.8
CVE-2018-12692EPSS 29%

TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell metacharact…

No fix yet
Fix from $1,950 2018-06-23
Nx Os HIGH 7.8
CVE-2018-0306

A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an af…

Fix: 5.2 / 7.3+
Fix from $1,950 2018-06-21
Nx Os HIGH 8.8
CVE-2018-0293

A vulnerability in role-based access control (RBAC) for Cisco NX-OS Software could allow an authenticated, remote attacker to execute CLI commands th…

Fix: 7.0 / 7.3+
Fix from $1,950 2018-06-20
Nx Os HIGH 7.8
CVE-2018-0307

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an affected …

Fix: 7.0 / 7.3+
Fix from $1,950 2018-06-20
Nx Os HIGH 8.8
CVE-2018-0330

A vulnerability in the NX-API management application programming interface (API) in devices running, or based on, Cisco NX-OS Software could allow an…

Fix: 7.0 / 7.3+
Fix from $1,950 2018-06-20
Dir 620 Firmware HIGH 7.2
CVE-2018-6211EPSS 6%

On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command in…

No fix yet
Fix from $1,950 2018-06-20
Edgeswitch Firmware HIGH 7.2
CVE-2018-12591

Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an improperly neutralized element in an OS command due to lack of protection on the …

Fix: after 1.7.3
Fix from $1,950 2018-06-20
Epolicy Orchestrator CRITICAL 9.8
CVE-2017-3936

OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run a…

Mitigation only
Fix from $2,300 2018-06-13
Acccheck.pl CRITICAL 9.8
CVE-2018-12268

acccheck.pl in acccheck 0.2.1 allows Command Injection via shell metacharacters in a username or password file, as demonstrated by injection into an …

No fix yet
Fix from $2,300 2018-06-13
Nsx Sd Wan By Velocloud HIGH 8.1
CVE-2018-6961 KEVEPSS 86%

VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component i…

Fix: 3.1.0+
Fix from $1,950 2018-06-11
Open Build Service CRITICAL 9.8
CVE-2014-0593

The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). In versions prior to 0.5.3-1.1…

Fix: 1.1+
Fix from $2,300 2018-06-08
Crestron Toolbox Protocol Firmware CRITICAL 9.8
CVE-2018-11229EPSS 6%

Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code executio…

Fix: 2.001.0037.001+
Fix from $2,300 2018-06-08
Network Services Orchestrator HIGH 8.8
CVE-2018-0274

A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to execute arbitrary she…

Fix: after 4.4.2.0
Fix from $1,950 2018-06-07
Nas Proxy Server CRITICAL 9.8
CVE-2017-7637

QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges.

Fix: 1.3.0+
Fix from $2,300 2018-06-05
Management Of Native Encryption HIGH 7.8
CVE-2018-6662

Privilege Escalation vulnerability in McAfee Management of Native Encryption (MNE) before 4.1.4 allows local users to gain elevated privileges via a …

Fix: 4.1.4+
Fix from $1,950 2018-06-05
Growl CRITICAL 9.8
CVE-2017-16042

Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitra…

Fix: 1.10.2+
Fix from $2,300 2018-06-04
Disk Backup HIGH 8.8
CVE-2018-11175

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 33 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11176

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 34 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11177

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 35 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11178

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 36 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11179

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 37 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02