Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
iOS HIGH 8.8
CVE-2019-12651

Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute c…

Mitigation only
Fix from $1,950 2019-09-25
Webaccess HIGH 8.8
CVE-2019-13552

In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and…

Fix: after 8.4.1
Fix from $1,950 2019-09-18
Mobaxterm HIGH 8.8
CVE-2019-16305EPSS 7%

In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants…

No fix yet
Fix from $1,950 2019-09-14
Android HIGH 7.8
CVE-2019-9254

In readArgumentList of zygote.java in Android 10, there is a possible command injection due to improper input validation. This could lead to local es…

Mitigation only
Fix from $1,950 2019-09-05
Photoshop Cc HIGH 8.8
CVE-2019-7989EPSS 14%

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to a…

Fix: after 20.0.5
Fix from $1,950 2019-08-26
Photoshop Cc CRITICAL 9.8
CVE-2019-7968EPSS 7%

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to a…

Fix: after 20.0.5
Fix from $2,300 2019-08-26
Acrobat Dc CRITICAL 9.8
CVE-2019-8060EPSS 6%

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 201…

Fix: 15.006.30499 / 17.011.30144+
Fix from $2,300 2019-08-20
M7350 Firmware HIGH 8.8
CVE-2019-12104

The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-authentication command injectio…

Fix: 190531+
Fix from $1,950 2019-08-14
Nc Launcher2 HIGH 8.8
CVE-2019-12805

NCSOFT Game Launcher, NC Launcher2 2.4.1.691 and earlier versions have a vulnerability in the custom protocol handler that could allow remote attacke…

Fix: after 2.4.1.691
Fix from $1,950 2019-08-09
Fedora HIGH 7.8
CVE-2019-14745

In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's poss…

Fix: 3.7.0+
Fix from $1,950 2019-08-07
Cpanel MEDIUM 5.3
CVE-2017-18442

cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18400

cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).

Fix: 62.0.35 / 64.0.42+
Fix from $1,950 2019-08-02
Cpanel MEDIUM 6.5
CVE-2016-10849

cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82).

Fix: 11.48.5.2 / 11.50.4.3+
Fix from $1,600 2019-08-01
Cpanel HIGH 8.1
CVE-2016-10843

cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).

Fix: 11.48.5.2 / 11.50.4.3+
Fix from $1,950 2019-08-01
Debian Linux CRITICAL 9.8
CVE-2019-1010174

CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attac…

Fix: 2.3.4+
Fix from $2,300 2019-07-25
Campaign CRITICAL 9.8
CVE-2019-7850EPSS 6%

Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitr…

Fix: after 18.10.5.8984
Fix from $2,300 2019-07-18
Camptix Event Ticketing HIGH 7.5
CVE-2016-10762

The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used.

Fix: 1.5.0+
Fix from $1,950 2019-07-18
Spa501g Firmware MEDIUM 6.6
CVE-2019-1923

A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the devi…

Fix: after 7.6.2sr5
Fix from $1,600 2019-07-17
Re6400 Firmware CRITICAL 9.8
CVE-2019-11535EPSS 5%

Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execu…

Fix: after 1.2.04.022
Fix from $2,300 2019-07-17
Edgeswitch Firmware HIGH 7.2
CVE-2019-5446

Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.

Fix: 1.8.2+
Fix from $1,950 2019-07-10
Enterprise Nfv Infrastructure Software HIGH 7.8
CVE-2019-1893

A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on…

Mitigation only
Fix from $1,950 2019-07-06
Big Ip Access Policy Manager HIGH 7.2
CVE-2019-6622

On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4, an undisclosed iControl REST worker is vulnerable to…

Fix: after 14.1.0.5
Fix from $1,950 2019-07-02
Dcs 1130 Firmware HIGH 8.8
CVE-2017-8413EPSS 10%

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which is called "dldps2121" and lis…

No fix yet
Fix from $1,950 2019-07-02
Dcs 1130 Firmware CRITICAL 9.8
CVE-2017-8404EPSS 8%

An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings re…

No fix yet
Fix from $2,300 2019-07-02
Dcs 1130 Firmware HIGH 8.8
CVE-2017-8411EPSS 6%

An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings re…

No fix yet
Fix from $1,950 2019-07-02
Dcs 1130 Firmware CRITICAL 9.8
CVE-2017-8408EPSS 5%

An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings re…

No fix yet
Fix from $2,300 2019-07-02
Tew 827dru Firmware HIGH 8.8
CVE-2019-13148

An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v…

Fix: 2.05b11+
Fix from $1,950 2019-07-02
Tew 827dru Firmware HIGH 8.8
CVE-2019-13150

An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication). …

Fix: 2.05b11+
Fix from $1,950 2019-07-02
Tew 827dru Firmware HIGH 8.8
CVE-2019-13152

An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v…

Fix: 2.05b11+
Fix from $1,950 2019-07-02
Centreon HIGH 8.8
CVE-2019-13024EPSS 32%

Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using t…

Patch available
Fix from $1,950 2019-07-01