Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2018-13338EPSS 10% System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter d… Terramaster Operating System No fix yet Fix from $2,3002018-11-27 HIGH 8.8 CVE-2018-13353EPSS 6% System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute commands via the "checkport" parameter. Terramaster Operating System No fix yet Fix from $1,9502018-11-27 CRITICAL 9.8 CVE-2018-13354EPSS 23% System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter. Terramaster Operating System No fix yet Fix from $2,3002018-11-27 HIGH 8.8 CVE-2018-13358EPSS 25% System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter. Terramaster Operating System No fix yet Fix from $1,9502018-11-27 HIGH 8.8 CVE-2018-13023EPSS 24% System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via the "time… Miwifi Os No fix yet Fix from $1,9502018-11-27 CRITICAL 9.8 CVE-2018-13306 System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter. A3002ru Firmware No fix yet Fix from $2,3002018-11-27 CRITICAL 9.8 CVE-2018-13307 System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST paramet… A3002ru Firmware No fix yet Fix from $2,3002018-11-27 CRITICAL 9.8 CVE-2018-13314 System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ipAddr" POST parameter. A3002ru Firmware No fix yet Fix from $2,3002018-11-27 CRITICAL 9.8 CVE-2018-13316 System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "subnet" POST parameter. A3002ru Firmware No fix yet Fix from $2,3002018-11-27 HIGH 8.8 CVE-2018-14893 A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web applic… Nsa325 V2 Firmware No fix yet Fix from $1,9502018-11-27 HIGH 8.8 CVE-2018-16130EPSS 24% System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload… Miwifi Os No fix yet Fix from $1,9502018-11-27 HIGH 7.5 CVE-2018-16089 In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing p… System Management Module Firmware 1.06+ Fix from $1,9502018-11-27 HIGH 7.5 CVE-2018-16090 In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command… System Management Module Firmware 1.06+ Fix from $1,9502018-11-27 CRITICAL 9.8 CVE-2018-13311 System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter. A3002ru Firmware Mitigation only Fix from $2,3002018-11-26 HIGH 7.2 CVE-2018-13318 System command injection in User.create method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute system commands via the "name" pa… Ts5600d1206 Firmware No fix yet Fix from $1,9502018-11-26 HIGH 7.2 CVE-2018-13320 System Command Injection in network.set_auth_settings in Buffalo TS5600D1206 version 3.70-0.10 allows attackers to execute system commands via the ad… Ts5600d1206 Firmware No fix yet Fix from $1,9502018-11-26 MEDIUM 6.7 CVE-2018-11077 'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Pro… Vsphere Data Protection Patch available Fix from $1,6002018-11-26 HIGH 7.8 CVE-2018-18856 Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate … Liquidvpn after 1.37 Fix from $1,9502018-11-20 HIGH 7.8 CVE-2018-18857 Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate … Liquidvpn after 1.37 Fix from $1,9502018-11-20 HIGH 7.8 CVE-2018-18858 Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate … Liquidvpn after 1.37 Fix from $1,9502018-11-20 HIGH 7.8 CVE-2018-18859 Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate … Liquidvpn after 1.37 Fix from $1,9502018-11-20 HIGH 7.2 CVE-2018-9086 In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged u… Thinkserver Rd340 Firmware 60.00 / 64.00+ Fix from $1,9502018-11-16 CRITICAL 9.8 CVE-2018-0694 FileZen V3.0.0 to V4.2.1 allows remote attackers to execute arbitrary OS commands via unspecified vectors. Filezen after 4.2.1 Fix from $2,3002018-11-15 HIGH 8.8 CVE-2018-15709EPSS 21% Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request. Nagios Xi No fix yet Fix from $1,9502018-11-14 HIGH 7.8 CVE-2018-15710EPSS 44% Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php. Nagios Xi No fix yet Fix from $1,9502018-11-14 HIGH 8.8 CVE-2018-15711EPSS 36% Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new… Nagios Xi No fix yet Fix from $1,9502018-11-14 CRITICAL 9.8 CVE-2018-19168EPSS 7% Shell Metacharacter Injection in www/modules/save.php in FruityWifi (aka PatatasFritas/PatataWifi) through 2.4 allows remote attackers to execute arb… Fruitywifi after 2.4 Fix from $2,3002018-11-11 CRITICAL 9.8 CVE-2018-19081 An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS m… I5 Application Firmware No fix yet Fix from $2,3002018-11-07 HIGH 7.2 CVE-2018-19073 An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir… I5 Application Firmware No fix yet Fix from $1,9502018-11-07 HIGH 7.2 CVE-2018-19070 An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir… I5 Application Firmware No fix yet Fix from $1,9502018-11-07