Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2020-1811 GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions… Gaussdb 200 Mitigation only Fix from $1,9502020-02-18 CRITICAL 9.8 CVE-2020-3760EPSS 7% Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code executi… Digital Editions after 4.5.10 Fix from $2,3002020-02-13 HIGH 7.2 CVE-2019-16005 A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary co… Collaboration Meeting Rooms 2019.09.19.1956m+ Fix from $1,9502020-01-26 HIGH 7.2 CVE-2019-12629 A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with… Sd Wan Firmware 18.3.0+ Fix from $1,9502020-01-26 CRITICAL 9.8 CVE-2019-17361EPSS 15% In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticat… Debian Linux after 2019.2.0 Fix from $2,3002020-01-17 HIGH 8.8 CVE-2019-15010 Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from versio… Bitbucket 5.6.11 / 6.0.11+ Fix from $1,9502020-01-15 CRITICAL 9.8 CVE-2014-4982 LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server. Lpar2rrd after 4.53 Fix from $2,3002020-01-10 HIGH 7.8 CVE-2019-17148 This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (454… Parallels Desktop Mitigation only Fix from $1,9502020-01-07 CRITICAL 9.8 CVE-2019-8255EPSS 7% Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. Brackets after 1.14 Fix from $2,3002019-12-19 HIGH 7.5 CVE-2019-15575 A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blob… GitLab 12.1.12 / 12.2.6+ Fix from $1,9502019-12-18 CRITICAL 9.8 CVE-2018-0729 This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP rec… Music Station 4.8.8 / 5.1.11+ Fix from $2,3002019-12-04 CRITICAL 9.8 CVE-2018-0730 This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP reco… Qts Mitigation only Fix from $2,3002019-12-04 HIGH 8.8 CVE-2019-15595 A privilege escalation exists in UniFi Video Controller =<3.10.6 that would allow an attacker on the local machine to run arbitrary commands. Unifi Video Controller after 3.10.6 Fix from $1,9502019-11-26 HIGH 7.2 CVE-2019-18647 The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user. Ng Firewall No fix yet Fix from $1,9502019-11-14 MEDIUM 6.7 CVE-2019-9467 In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to a local elevation of privileg… Android Mitigation only Fix from $1,6002019-11-13 CRITICAL 9.8 CVE-2019-18780EPSS 6% An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execut… Access after 7.4.2 Fix from $2,3002019-11-05 HIGH 8.8 CVE-2018-19031 A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 rout… Safe Router P0 Firmware Mitigation only Fix from $1,9502019-11-04 HIGH 7.2 CVE-2019-15588EPSS 6% There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (… Nexus Repository Manager after 2.14.14 Fix from $1,9502019-11-01 HIGH 8.0 CVE-2019-3421 The 7520V3V1.0.0B09P27 version, and all earlier versions of ZTE product ZX297520V3 are impacted by a Command Injection vulnerability. Unauthorized us… Zx297520v3 Firmware after 7520v3v1.0.0b09p27 Fix from $1,9502019-10-31 HIGH 7.5 CVE-2018-16417 Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection. Instant 4.2.4.12 / 6.5.4.11+ Fix from $1,9502019-10-30 HIGH 7.5 CVE-2019-18188 Trend Micro Apex One could be exploited by an attacker utilizing a command injection vulnerability to extract files from an arbitrary zip file to a s… Apex One Mitigation only Fix from $1,9502019-10-28 CRITICAL 9.8 CVE-2019-8088EPSS 6% Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code … Experience Manager Mitigation only Fix from $2,3002019-10-25 HIGH 8.8 CVE-2019-15051 An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to command injection via a malicio… Uagate Si Firmware after 1.71.00.1225 Fix from $1,9502019-10-10 CRITICAL 9.8 CVE-2019-1584 A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a ma… Inspector after 1.293 Fix from $2,3002019-10-09 CRITICAL 9.8 CVE-2019-12736 JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection. Ktor after 1.1.5 Fix from $2,3002019-10-02 CRITICAL 9.8 CVE-2019-8073EPSS 8% ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Suc… Coldfusion Mitigation only Fix from $2,3002019-09-27 HIGH 8.8 CVE-2019-11279 CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malici… Uaa Release 74.1.0+ Fix from $1,9502019-09-26 HIGH 8.8 CVE-2019-11278 CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update'… User Account And Authentication 74.1.0+ Fix from $1,9502019-09-26 MEDIUM 6.7 CVE-2019-12661 A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execu… Ios Xe Mitigation only Fix from $1,6002019-09-25 HIGH 8.8 CVE-2019-12650EPSS 29% Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute c… iOS Mitigation only Fix from $1,9502019-09-25