Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2018-16055EPSS 11%
An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passi…
Pfsense
2.4.4+
CRITICAL 9.8
CVE-2018-17317
FruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the io_mode, ap_mode,…
Fruitywifi
No fix yet
HIGH 8.8
CVE-2018-16282EPSS 5%
A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS…
Edr 810 Firmware
No fix yet
HIGH 8.8
CVE-2018-16752EPSS 43%
LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at ad…
Lw N605r Firmware
No fix yet
CRITICAL 9.8
CVE-2018-17228
nmap4j 1.1.0 allows attackers to execute arbitrary commands via shell metacharacters in an includeHosts call.
Nmap4j
Patch available
HIGH 7.2
CVE-2017-2873EPSS 5%
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firm…
C1 Firmware
No fix yet
HIGH 8.8
CVE-2018-17208
Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cg…
Velop Firmware
No fix yet
CRITICAL 9.8
CVE-2018-17063
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fu…
Dir 816 A2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-17064EPSS 7%
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fu…
Dir 816 A2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-17066EPSS 7%
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler functi…
Dir 816 A2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-17068
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler functi…
Dir 816 A2 Firmware
No fix yet
HIGH 7.8
CVE-2018-16741
An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to p…
Debian Linux
1.2.1+
HIGH 7.8
CVE-2018-16744
An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow for command …
Mgetty
1.2.1+
CRITICAL 9.8
CVE-2018-15484EPSS 8%
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Remote Code Execution is possible through the open HTTP …
Group Controller Firmware
4.6.5+
CRITICAL 9.8
CVE-2018-16460
A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.
Ps
1.0.0+
HIGH 8.8
CVE-2018-3952
An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0. A specially crafted configuration file can caus…
Nordvpn
No fix yet
HIGH 7.8
CVE-2018-4010EPSS 5%
An exploitable code execution vulnerability exists in the connect functionality of ProtonVPN VPN client 1.5.1. A specially crafted configuration file…
Protonvpn
No fix yet
MEDIUM 6.6
CVE-2018-0643
Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker with administrator rights to…
Ubuntu Linux
Mitigation only
MEDIUM 5.3
CVE-2018-15726
The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Privilege Escalation Vulnerability.
Pulse Secure Desktop Client
No fix yet
CRITICAL 9.8
CVE-2018-1000666EPSS 8%
GIG Technology NV JumpScale Portal 7 version before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb contains a CWE-78: Improper Neutralization of Spe…
Openvcloud
2.3.0+
CRITICAL 9.8
CVE-2018-16144EPSS 33%
The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command injection d…
Opsview
5.3.1 / 5.4.2+
HIGH 7.2
CVE-2018-16146EPSS 6%
The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated administrator to test notifica…
Opsview
5.4.2+
HIGH 7.2
CVE-2018-16408
D-Link DIR-846 devices with firmware 100.26 allow remote attackers to execute arbitrary code as root via a SetNetworkTomographySettings request by le…
Dir 846 Firmware
No fix yet
HIGH 8.8
CVE-2018-16334
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST request is used directly in …
Ac10 Firmware
after 15.03.06.23
CRITICAL 9.8
CVE-2018-15477
myStrom WiFi Switch V1 devices before 2.66 did not sanitize a parameter received from the cloud that was used in an OS command. Malicious servers wer…
Wifi Switch Firmware
2.66+
HIGH 8.8
CVE-2018-11616
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115. User interaction is re…
Foxmail
Mitigation only
HIGH 7.8
CVE-2018-14572
In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a crafted .pickle file, as dem…
Conference Scheduler Cli
after 0.10.1
HIGH 8.8
CVE-2018-15529
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to th…
Mutiny
6.1.0-5263+
HIGH 8.8
CVE-2018-15887
Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allows a remote attacker to execu…
Dsl N12e C1 Firmware
No fix yet
HIGH 8.8
CVE-2018-15877EPSS 77%
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the ip paramete…
Plainview Activity Monitor
20180826+