Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2018-16055EPSS 11% An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passi… Pfsense 2.4.4+ Fix from $1,9502018-09-26 CRITICAL 9.8 CVE-2018-17317 FruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the io_mode, ap_mode,… Fruitywifi No fix yet Fix from $2,3002018-09-21 HIGH 8.8 CVE-2018-16282EPSS 5% A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS… Edr 810 Firmware No fix yet Fix from $1,9502018-09-20 HIGH 8.8 CVE-2018-16752EPSS 43% LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at ad… Lw N605r Firmware No fix yet Fix from $1,9502018-09-20 CRITICAL 9.8 CVE-2018-17228 nmap4j 1.1.0 allows attackers to execute arbitrary commands via shell metacharacters in an includeHosts call. Nmap4j Patch available Fix from $2,3002018-09-19 HIGH 7.2 CVE-2017-2873EPSS 5% An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firm… C1 Firmware No fix yet Fix from $1,9502018-09-19 HIGH 8.8 CVE-2018-17208 Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cg… Velop Firmware No fix yet Fix from $1,9502018-09-19 CRITICAL 9.8 CVE-2018-17063 An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fu… Dir 816 A2 Firmware No fix yet Fix from $2,3002018-09-15 CRITICAL 9.8 CVE-2018-17064EPSS 7% An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fu… Dir 816 A2 Firmware No fix yet Fix from $2,3002018-09-15 CRITICAL 9.8 CVE-2018-17066EPSS 7% An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler functi… Dir 816 A2 Firmware No fix yet Fix from $2,3002018-09-15 CRITICAL 9.8 CVE-2018-17068 An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler functi… Dir 816 A2 Firmware No fix yet Fix from $2,3002018-09-15 HIGH 7.8 CVE-2018-16741 An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to p… Debian Linux 1.2.1+ Fix from $1,9502018-09-13 HIGH 7.8 CVE-2018-16744 An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow for command … Mgetty 1.2.1+ Fix from $1,9502018-09-13 CRITICAL 9.8 CVE-2018-15484EPSS 8% An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Remote Code Execution is possible through the open HTTP … Group Controller Firmware 4.6.5+ Fix from $2,3002018-09-07 CRITICAL 9.8 CVE-2018-16460 A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID. Ps 1.0.0+ Fix from $2,3002018-09-07 HIGH 8.8 CVE-2018-3952 An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0. A specially crafted configuration file can caus… Nordvpn No fix yet Fix from $1,9502018-09-07 HIGH 7.8 CVE-2018-4010EPSS 5% An exploitable code execution vulnerability exists in the connect functionality of ProtonVPN VPN client 1.5.1. A specially crafted configuration file… Protonvpn No fix yet Fix from $1,9502018-09-07 MEDIUM 6.6 CVE-2018-0643 Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker with administrator rights to… Ubuntu Linux Mitigation only Fix from $1,6002018-09-07 MEDIUM 5.3 CVE-2018-15726 The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Privilege Escalation Vulnerability. Pulse Secure Desktop Client No fix yet Fix from $1,6002018-09-06 CRITICAL 9.8 CVE-2018-1000666EPSS 8% GIG Technology NV JumpScale Portal 7 version before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb contains a CWE-78: Improper Neutralization of Spe… Openvcloud 2.3.0+ Fix from $2,3002018-09-06 CRITICAL 9.8 CVE-2018-16144EPSS 33% The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command injection d… Opsview 5.3.1 / 5.4.2+ Fix from $2,3002018-09-05 HIGH 7.2 CVE-2018-16146EPSS 6% The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated administrator to test notifica… Opsview 5.4.2+ Fix from $1,9502018-09-05 HIGH 7.2 CVE-2018-16408 D-Link DIR-846 devices with firmware 100.26 allow remote attackers to execute arbitrary code as root via a SetNetworkTomographySettings request by le… Dir 846 Firmware No fix yet Fix from $1,9502018-09-03 HIGH 8.8 CVE-2018-16334 An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST request is used directly in … Ac10 Firmware after 15.03.06.23 Fix from $1,9502018-09-02 CRITICAL 9.8 CVE-2018-15477 myStrom WiFi Switch V1 devices before 2.66 did not sanitize a parameter received from the cloud that was used in an OS command. Malicious servers wer… Wifi Switch Firmware 2.66+ Fix from $2,3002018-08-30 HIGH 8.8 CVE-2018-11616 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115. User interaction is re… Foxmail Mitigation only Fix from $1,9502018-08-30 HIGH 7.8 CVE-2018-14572 In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a crafted .pickle file, as dem… Conference Scheduler Cli after 0.10.1 Fix from $1,9502018-08-28 HIGH 8.8 CVE-2018-15529 A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to th… Mutiny 6.1.0-5263+ Fix from $1,9502018-08-28 HIGH 8.8 CVE-2018-15887 Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allows a remote attacker to execu… Dsl N12e C1 Firmware No fix yet Fix from $1,9502018-08-27 HIGH 8.8 CVE-2018-15877EPSS 77% The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the ip paramete… Plainview Activity Monitor 20180826+ Fix from $1,9502018-08-26