Vulnerability index

Browse CVEs

57 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Data Master HIGH 8.8
CVE-2018-12307

OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter.

No fix yet
Fix from $1,950 2018-12-04
Data Master HIGH 8.8
CVE-2018-12312

OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL parameter.

No fix yet
Fix from $1,950 2018-12-04
Data Master HIGH 8.8
CVE-2018-12316

OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter.

No fix yet
Fix from $1,950 2018-12-04
Data Master HIGH 8.8
CVE-2018-12317

OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST param…

No fix yet
Fix from $1,950 2018-12-04
Data Master HIGH 8.8
CVE-2018-12318

Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.

No fix yet
Fix from $1,950 2018-12-04
Data Master HIGH 7.5
CVE-2018-12306

Directory Traversal in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to view arbitrary files by modifying the "file1" URL parameter, a …

No fix yet
Fix from $1,950 2018-12-04
Data Master HIGH 7.5
CVE-2018-12309

Directory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations by modifying the "path" URL pa…

No fix yet
Fix from $1,950 2018-12-04
Data Master HIGH 7.5
CVE-2018-12314

Directory Traversal in downloadwallpaper.cgi in ASUSTOR ADM version 3.1.1 allows attackers to download arbitrary files by manipulating the "file" and…

No fix yet
Fix from $1,950 2018-12-04
Data Master HIGH 7.5
CVE-2018-12319

Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title.

No fix yet
Fix from $1,950 2018-12-04
Data Master MEDIUM 6.5
CVE-2018-12308

Encryption key disclosure in share.cgi in ASUSTOR ADM version 3.1.1 allows attackers to obtain the encryption key via the "encrypt_key" URL parameter.

No fix yet
Fix from $1,600 2018-12-04
Data Master MEDIUM 6.5
CVE-2018-12315

Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password.

No fix yet
Fix from $1,600 2018-12-04
Data Master MEDIUM 6.1
CVE-2018-12305

Cross-site scripting in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript by uploading SVG images with embedded JavaS…

No fix yet
Fix from $1,600 2018-12-04
Data Master MEDIUM 5.4
CVE-2018-12310

Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript via the System Announcement feature.

No fix yet
Fix from $1,600 2018-12-04
Data Master MEDIUM 5.4
CVE-2018-12311

Cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary JavaScript when a file is move…

No fix yet
Fix from $1,600 2018-12-04
Data Master HIGH 7.5
CVE-2018-15694

ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path travers…

Fix: after 3.1.5
Fix from $1,950 2018-08-27
Data Master MEDIUM 6.5
CVE-2018-15695

ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversa…

Fix: after 3.1.5
Fix from $1,600 2018-08-27
Data Master MEDIUM 6.5
CVE-2018-15697

ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For …

Fix: after 3.1.5
Fix from $1,600 2018-08-27
Data Master MEDIUM 6.5
CVE-2018-15698

ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full …

Fix: after 3.1.5
Fix from $1,600 2018-08-27
Data Master MEDIUM 6.1
CVE-2018-15699

ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage …

Fix: after 3.1.5
Fix from $1,600 2018-08-27
Asustor Data Master CRITICAL 9.8
CVE-2018-11509EPSS 13%

ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from …

No fix yet
Fix from $2,300 2018-08-16
Asustor Data Master CRITICAL 9.8
CVE-2018-11511EPSS 11%

The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' …

No fix yet
Fix from $2,300 2018-08-16
Adm CRITICAL 9.8
CVE-2018-11510EPSS 45%

The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by…

Fix: after 3.1.2.rhg1
Fix from $2,300 2018-06-28
As6202t Firmware HIGH 8.8
CVE-2018-11345

An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the POST param…

No fix yet
Fix from $1,950 2018-05-22
As6202t Firmware HIGH 7.2
CVE-2018-11340

An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data to a specified…

No fix yet
Fix from $1,950 2018-05-22
As6202t Firmware HIGH 7.2
CVE-2018-11341

Directory traversal in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to navigate the file system via the filename parameter.

No fix yet
Fix from $1,950 2018-05-22
As6202t Firmware MEDIUM 6.5
CVE-2018-11344

A path traversal vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify a file on the system to down…

No fix yet
Fix from $1,600 2018-05-22
Soundsgood MEDIUM 5.4
CVE-2018-11343

A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attackers to store cross site scri…

No fix yet
Fix from $1,600 2018-05-22