Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Gaussdb 200 HIGH 8.8
CVE-2020-1811

GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions…

Mitigation only
Fix from $1,950 2020-02-18
Digital Editions CRITICAL 9.8
CVE-2020-3760EPSS 7%

Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code executi…

Fix: after 4.5.10
Fix from $2,300 2020-02-13
Collaboration Meeting Rooms HIGH 7.2
CVE-2019-16005

A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary co…

Fix: 2019.09.19.1956m+
Fix from $1,950 2020-01-26
Sd Wan Firmware HIGH 7.2
CVE-2019-12629

A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with…

Fix: 18.3.0+
Fix from $1,950 2020-01-26
Debian Linux CRITICAL 9.8
CVE-2019-17361EPSS 15%

In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticat…

Fix: after 2019.2.0
Fix from $2,300 2020-01-17
Bitbucket HIGH 8.8
CVE-2019-15010

Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from versio…

Fix: 5.6.11 / 6.0.11+
Fix from $1,950 2020-01-15
Lpar2rrd CRITICAL 9.8
CVE-2014-4982

LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server.

Fix: after 4.53
Fix from $2,300 2020-01-10
Parallels Desktop HIGH 7.8
CVE-2019-17148

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (454…

Mitigation only
Fix from $1,950 2020-01-07
Brackets CRITICAL 9.8
CVE-2019-8255EPSS 7%

Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

Fix: after 1.14
Fix from $2,300 2019-12-19
GitLab HIGH 7.5
CVE-2019-15575

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blob…

Fix: 12.1.12 / 12.2.6+
Fix from $1,950 2019-12-18
Music Station CRITICAL 9.8
CVE-2018-0729

This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP rec…

Fix: 4.8.8 / 5.1.11+
Fix from $2,300 2019-12-04
Qts CRITICAL 9.8
CVE-2018-0730

This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP reco…

Mitigation only
Fix from $2,300 2019-12-04
Unifi Video Controller HIGH 8.8
CVE-2019-15595

A privilege escalation exists in UniFi Video Controller =<3.10.6 that would allow an attacker on the local machine to run arbitrary commands.

Fix: after 3.10.6
Fix from $1,950 2019-11-26
Ng Firewall HIGH 7.2
CVE-2019-18647

The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.

No fix yet
Fix from $1,950 2019-11-14
Android MEDIUM 6.7
CVE-2019-9467

In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to a local elevation of privileg…

Mitigation only
Fix from $1,600 2019-11-13
Access CRITICAL 9.8
CVE-2019-18780EPSS 6%

An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execut…

Fix: after 7.4.2
Fix from $2,300 2019-11-05
Safe Router P0 Firmware HIGH 8.8
CVE-2018-19031

A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 rout…

Mitigation only
Fix from $1,950 2019-11-04
Nexus Repository Manager HIGH 7.2
CVE-2019-15588EPSS 6%

There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (…

Fix: after 2.14.14
Fix from $1,950 2019-11-01
Zx297520v3 Firmware HIGH 8.0
CVE-2019-3421

The 7520V3V1.0.0B09P27 version, and all earlier versions of ZTE product ZX297520V3 are impacted by a Command Injection vulnerability. Unauthorized us…

Fix: after 7520v3v1.0.0b09p27
Fix from $1,950 2019-10-31
Instant HIGH 7.5
CVE-2018-16417

Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection.

Fix: 4.2.4.12 / 6.5.4.11+
Fix from $1,950 2019-10-30
Apex One HIGH 7.5
CVE-2019-18188

Trend Micro Apex One could be exploited by an attacker utilizing a command injection vulnerability to extract files from an arbitrary zip file to a s…

Mitigation only
Fix from $1,950 2019-10-28
Experience Manager CRITICAL 9.8
CVE-2019-8088EPSS 6%

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code …

Mitigation only
Fix from $2,300 2019-10-25
Uagate Si Firmware HIGH 8.8
CVE-2019-15051

An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to command injection via a malicio…

Fix: after 1.71.00.1225
Fix from $1,950 2019-10-10
Inspector CRITICAL 9.8
CVE-2019-1584

A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a ma…

Fix: after 1.293
Fix from $2,300 2019-10-09
Ktor CRITICAL 9.8
CVE-2019-12736

JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.

Fix: after 1.1.5
Fix from $2,300 2019-10-02
Coldfusion CRITICAL 9.8
CVE-2019-8073EPSS 8%

ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Suc…

Mitigation only
Fix from $2,300 2019-09-27
Uaa Release HIGH 8.8
CVE-2019-11279

CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malici…

Fix: 74.1.0+
Fix from $1,950 2019-09-26
User Account And Authentication HIGH 8.8
CVE-2019-11278

CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update'…

Fix: 74.1.0+
Fix from $1,950 2019-09-26
Ios Xe MEDIUM 6.7
CVE-2019-12661

A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execu…

Mitigation only
Fix from $1,600 2019-09-25
iOS HIGH 8.8
CVE-2019-12650EPSS 29%

Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute c…

Mitigation only
Fix from $1,950 2019-09-25