Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,285 CVEs tagged with CWE-782,019 Critical, 3,175 High, 898 Medium, 193 Low, 0 Unrated.

CVE-2018-1144

Published Apr 19, 2018

A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to proxy.cgi.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1143

Published Apr 19, 2018

A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to twonky_command.cgi.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1167

Published Apr 19, 2018

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336. User interaction is required to exploit this v…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8735

Published Apr 18, 2018

Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command i…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14459

Published Apr 11, 2018

An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/cli…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-0545

Published Apr 9, 2018

LXR version 1.0.0 to 2.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-0194

Published Apr 2, 2018

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0193

Published Mar 28, 2018

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0185

Published Mar 28, 2018

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0184

Published Mar 28, 2018

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and exec…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0183

Published Mar 28, 2018

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and exec…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0182

Published Mar 28, 2018

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0176

Published Mar 28, 2018

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0169

Published Mar 28, 2018

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1238

Published Mar 27, 2018

Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA). This component is used for central management of ScaleIO d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3178

Published Mar 20, 2018

In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to execute shellcode.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6231

Published Mar 15, 2018

A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could allow remote attackers to esca…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6222

Published Mar 15, 2018

Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to execute arbitrary commands and at…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-7890

Published Mar 8, 2018

A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7640

Published Mar 8, 2018

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 5,826-5,850 of 6,285 CVEsPage 234 of 252