Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2018-15007
The Sky Elite 6.0L+ Android device with a build fingerprint of SKY/x6069_trx_l601_sky/x6069_trx_l601_sky:6.0/MRA58K/1482897127:user/release-keys cont…
Sky Elite 6.0l\+ Firmware
No fix yet
MEDIUM 6.8
CVE-2018-14998
The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a hidde…
P1 Firmware
No fix yet
HIGH 7.2
CVE-2018-19239EPSS 5%
TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remot…
Tew 673gru Firmware
No fix yet
CRITICAL 9.8
CVE-2018-1000885
PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Elements used in a Command ('Com…
Phkp
No fix yet
HIGH 8.1
CVE-2018-15722
The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the mid…
Harmony Hub Firmware
4.15.206+
CRITICAL 9.9
CVE-2018-18555
A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to administer the device. By issuin…
Vyos
No fix yet
CRITICAL 9.8
CVE-2018-19007
In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration panel) is vulnerable to an OS s…
G Cam\/efd 2251 Firmware
1.12.0.25+
HIGH 8.8
CVE-2018-20057EPSS 7%
An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. goform/formSysCmd allows remote authenticated …
Dir 619l Firmware
No fix yet
HIGH 8.8
CVE-2018-19659
An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware befor…
Nport W2x50a Firmware
2.2+
HIGH 8.8
CVE-2018-19660EPSS 29%
An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware befor…
Nport W2x50a Firmware
2.2+
HIGH 8.8
CVE-2018-19908EPSS 17%
An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to constr…
Misp
2.4.99+
HIGH 8.8
CVE-2018-19907
A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/…
Crafter Cms
after 3.0.18
HIGH 8.8
CVE-2018-12307
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter.
Data Master
No fix yet
HIGH 8.8
CVE-2018-12312
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL parameter.
Data Master
No fix yet
CRITICAL 9.8
CVE-2018-12313
OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity…
Data Master
No fix yet
HIGH 8.8
CVE-2018-12316
OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter.
Data Master
No fix yet
HIGH 8.8
CVE-2018-12317
OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST param…
Data Master
No fix yet
CRITICAL 9.8
CVE-2018-14699EPSS 29%
System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to exec…
5n2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-14701EPSS 20%
System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to exec…
5n2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-14706EPSS 17%
System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to e…
5n2 Firmware
No fix yet
HIGH 7.2
CVE-2018-4019EPSS 49%
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…
Pfsense
No fix yet
HIGH 7.2
CVE-2018-4020EPSS 49%
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…
Pfsense
No fix yet
HIGH 7.2
CVE-2018-4021EPSS 72%
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…
Pfsense
No fix yet
HIGH 7.8
CVE-2018-16863
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSA…
Enterprise Linux Desktop
Patch available
HIGH 8.8
CVE-2018-15716EPSS 18%
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to upgrade_handle.php to e…
Nvrmini2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-19290
In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote attackers to perform a command injection attack against the…
Budabot
after 4.0
CRITICAL 9.8
CVE-2018-19646
The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because c…
Securesphere
No fix yet
HIGH 8.8
CVE-2018-13418EPSS 5%
System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "newname" parameter.
Terramaster Operating System
No fix yet
HIGH 7.2
CVE-2018-13330EPSS 8%
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands during group creation via the …
Terramaster Operating System
No fix yet
CRITICAL 9.8
CVE-2018-13336EPSS 9%
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during…
Terramaster Operating System
No fix yet