Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2018-13353EPSS 6% System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute commands via the "checkport" parameter. Terramaster Operating System No fix yet Fix from $1,9502018-11-27 HIGH 8.8 CVE-2018-13356 Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions. Terramaster Operating System No fix yet Fix from $1,9502018-11-27 HIGH 8.8 CVE-2018-13358EPSS 25% System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter. Terramaster Operating System No fix yet Fix from $1,9502018-11-27 HIGH 7.5 CVE-2018-13332 Directory Traversal in the explorer application in TerraMaster TOS version 3.1.03 allows attackers to upload files to arbitrary locations via the "pa… Terramaster Operating System No fix yet Fix from $1,9502018-11-27 HIGH 7.5 CVE-2018-13352 Session Exposure in the web application for TerraMaster TOS version 3.1.03 allows attackers to view active session tokens in a world-readable directo… Terramaster Operating System No fix yet Fix from $1,9502018-11-27 HIGH 7.2 CVE-2018-13330EPSS 8% System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands during group creation via the … Terramaster Operating System No fix yet Fix from $1,9502018-11-27 MEDIUM 6.5 CVE-2018-13355 Incorrect access controls in ajaxdata.php in TerraMaster TOS version 3.1.03 allow attackers to create user groups without proper authorization. Terramaster Operating System No fix yet Fix from $1,6002018-11-27 MEDIUM 6.1 CVE-2018-13331 Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing users by placing JavaScri… Terramaster Operating System No fix yet Fix from $1,6002018-11-27 MEDIUM 6.1 CVE-2018-13333 Cross-site scripting in File Manager in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript in the permissions window by placing Ja… Terramaster Operating System No fix yet Fix from $1,6002018-11-27 MEDIUM 6.1 CVE-2018-13349 Cross-site scripting in the web application taskbar in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the user's username. Terramaster Operating System No fix yet Fix from $1,6002018-11-27 MEDIUM 5.4 CVE-2018-13335 Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing shared folders via their … Terramaster Operating System No fix yet Fix from $1,6002018-11-27 MEDIUM 5.4 CVE-2018-13357 Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing Shared Folders via JavaSc… Terramaster Operating System No fix yet Fix from $1,6002018-11-27 MEDIUM 6.1 CVE-2018-13329 Cross-site scripting in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "lines" URL parameter. Terramaster Operating System No fix yet Fix from $1,6002018-11-27 MEDIUM 6.1 CVE-2018-13334 Cross-site scripting in handle.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "options[sysname]" parameter. Terramaster Operating System No fix yet Fix from $1,6002018-11-27 MEDIUM 5.4 CVE-2018-13337 Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session cookies via JavaScript. Terramaster Operating System No fix yet Fix from $1,6002018-11-27 CRITICAL 9.8 CVE-2017-9328EPSS 7% Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as r… Terramaster Operating System after 3.0.33 Fix from $2,3002017-09-15