Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.8 CVE-2018-15007 The Sky Elite 6.0L+ Android device with a build fingerprint of SKY/x6069_trx_l601_sky/x6069_trx_l601_sky:6.0/MRA58K/1482897127:user/release-keys cont… Sky Elite 6.0l\+ Firmware No fix yet Fix from $1,9502018-12-28 MEDIUM 6.8 CVE-2018-14998 The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a hidde… P1 Firmware No fix yet Fix from $1,6002018-12-28 HIGH 7.2 CVE-2018-19239EPSS 5% TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remot… Tew 673gru Firmware No fix yet Fix from $1,9502018-12-20 CRITICAL 9.8 CVE-2018-1000885 PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Elements used in a Command ('Com… Phkp No fix yet Fix from $2,3002018-12-20 HIGH 8.1 CVE-2018-15722 The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the mid… Harmony Hub Firmware 4.15.206+ Fix from $1,9502018-12-20 CRITICAL 9.9 CVE-2018-18555 A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to administer the device. By issuin… Vyos No fix yet Fix from $2,3002018-12-17 CRITICAL 9.8 CVE-2018-19007 In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration panel) is vulnerable to an OS s… G Cam\/efd 2251 Firmware 1.12.0.25+ Fix from $2,3002018-12-14 HIGH 8.8 CVE-2018-20057EPSS 7% An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. goform/formSysCmd allows remote authenticated … Dir 619l Firmware No fix yet Fix from $1,9502018-12-11 HIGH 8.8 CVE-2018-19659 An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware befor… Nport W2x50a Firmware 2.2+ Fix from $1,9502018-12-06 HIGH 8.8 CVE-2018-19660EPSS 29% An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware befor… Nport W2x50a Firmware 2.2+ Fix from $1,9502018-12-06 HIGH 8.8 CVE-2018-19908EPSS 17% An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to constr… Misp 2.4.99+ Fix from $1,9502018-12-06 HIGH 8.8 CVE-2018-19907 A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/… Crafter Cms after 3.0.18 Fix from $1,9502018-12-06 HIGH 8.8 CVE-2018-12307 OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter. Data Master No fix yet Fix from $1,9502018-12-04 HIGH 8.8 CVE-2018-12312 OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL parameter. Data Master No fix yet Fix from $1,9502018-12-04 CRITICAL 9.8 CVE-2018-12313 OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity… Data Master No fix yet Fix from $2,3002018-12-04 HIGH 8.8 CVE-2018-12316 OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter. Data Master No fix yet Fix from $1,9502018-12-04 HIGH 8.8 CVE-2018-12317 OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST param… Data Master No fix yet Fix from $1,9502018-12-04 CRITICAL 9.8 CVE-2018-14699EPSS 29% System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to exec… 5n2 Firmware No fix yet Fix from $2,3002018-12-03 CRITICAL 9.8 CVE-2018-14701EPSS 20% System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to exec… 5n2 Firmware No fix yet Fix from $2,3002018-12-03 CRITICAL 9.8 CVE-2018-14706EPSS 17% System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to e… 5n2 Firmware No fix yet Fix from $2,3002018-12-03 HIGH 7.2 CVE-2018-4019EPSS 49% An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request… Pfsense No fix yet Fix from $1,9502018-12-03 HIGH 7.2 CVE-2018-4020EPSS 49% An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request… Pfsense No fix yet Fix from $1,9502018-12-03 HIGH 7.2 CVE-2018-4021EPSS 72% An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request… Pfsense No fix yet Fix from $1,9502018-12-03 HIGH 7.8 CVE-2018-16863 It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSA… Enterprise Linux Desktop Patch available Fix from $1,9502018-12-03 HIGH 8.8 CVE-2018-15716EPSS 18% NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to upgrade_handle.php to e… Nvrmini2 Firmware No fix yet Fix from $1,9502018-11-30 CRITICAL 9.8 CVE-2018-19290 In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote attackers to perform a command injection attack against the… Budabot after 4.0 Fix from $2,3002018-11-30 CRITICAL 9.8 CVE-2018-19646 The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because c… Securesphere No fix yet Fix from $2,3002018-11-28 HIGH 8.8 CVE-2018-13418EPSS 5% System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "newname" parameter. Terramaster Operating System No fix yet Fix from $1,9502018-11-27 HIGH 7.2 CVE-2018-13330EPSS 8% System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands during group creation via the … Terramaster Operating System No fix yet Fix from $1,9502018-11-27 CRITICAL 9.8 CVE-2018-13336EPSS 9% System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during… Terramaster Operating System No fix yet Fix from $2,3002018-11-27