Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2019-12651 Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute c… iOS Mitigation only Fix from $1,9502019-09-25 HIGH 8.8 CVE-2019-13552 In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and… Webaccess after 8.4.1 Fix from $1,9502019-09-18 HIGH 8.8 CVE-2019-16305EPSS 7% In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants… Mobaxterm No fix yet Fix from $1,9502019-09-14 HIGH 7.8 CVE-2019-9254 In readArgumentList of zygote.java in Android 10, there is a possible command injection due to improper input validation. This could lead to local es… Android Mitigation only Fix from $1,9502019-09-05 HIGH 8.8 CVE-2019-7989EPSS 14% Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to a… Photoshop Cc after 20.0.5 Fix from $1,9502019-08-26 CRITICAL 9.8 CVE-2019-7968EPSS 7% Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to a… Photoshop Cc after 20.0.5 Fix from $2,3002019-08-26 CRITICAL 9.8 CVE-2019-8060EPSS 6% Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 201… Acrobat Dc 15.006.30499 / 17.011.30144+ Fix from $2,3002019-08-20 HIGH 8.8 CVE-2019-12104 The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-authentication command injectio… M7350 Firmware 190531+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2019-12805 NCSOFT Game Launcher, NC Launcher2 2.4.1.691 and earlier versions have a vulnerability in the custom protocol handler that could allow remote attacke… Nc Launcher2 after 2.4.1.691 Fix from $1,9502019-08-09 HIGH 7.8 CVE-2019-14745 In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's poss… Fedora 3.7.0+ Fix from $1,9502019-08-07 MEDIUM 5.3 CVE-2017-18442 cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246). Cpanel 56.0.49 / 58.0.49+ Fix from $1,6002019-08-02 HIGH 7.8 CVE-2017-18400 cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333). Cpanel 62.0.35 / 64.0.42+ Fix from $1,9502019-08-02 MEDIUM 6.5 CVE-2016-10849 cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82). Cpanel 11.48.5.2 / 11.50.4.3+ Fix from $1,6002019-08-01 HIGH 8.1 CVE-2016-10843 cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76). Cpanel 11.48.5.2 / 11.50.4.3+ Fix from $1,9502019-08-01 CRITICAL 9.8 CVE-2019-1010174 CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attac… Debian Linux 2.3.4+ Fix from $2,3002019-07-25 CRITICAL 9.8 CVE-2019-7850EPSS 6% Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitr… Campaign after 18.10.5.8984 Fix from $2,3002019-07-18 HIGH 7.5 CVE-2016-10762 The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used. Camptix Event Ticketing 1.5.0+ Fix from $1,9502019-07-18 MEDIUM 6.6 CVE-2019-1923 A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the devi… Spa501g Firmware after 7.6.2sr5 Fix from $1,6002019-07-17 CRITICAL 9.8 CVE-2019-11535EPSS 5% Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execu… Re6400 Firmware after 1.2.04.022 Fix from $2,3002019-07-17 HIGH 7.2 CVE-2019-5446 Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root. Edgeswitch Firmware 1.8.2+ Fix from $1,9502019-07-10 HIGH 7.8 CVE-2019-1893 A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on… Enterprise Nfv Infrastructure Software Mitigation only Fix from $1,9502019-07-06 HIGH 7.2 CVE-2019-6622 On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4, an undisclosed iControl REST worker is vulnerable to… Big Ip Access Policy Manager after 14.1.0.5 Fix from $1,9502019-07-02 HIGH 8.8 CVE-2017-8413EPSS 10% An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which is called "dldps2121" and lis… Dcs 1130 Firmware No fix yet Fix from $1,9502019-07-02 CRITICAL 9.8 CVE-2017-8404EPSS 8% An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings re… Dcs 1130 Firmware No fix yet Fix from $2,3002019-07-02 HIGH 8.8 CVE-2017-8411EPSS 6% An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings re… Dcs 1130 Firmware No fix yet Fix from $1,9502019-07-02 CRITICAL 9.8 CVE-2017-8408EPSS 5% An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings re… Dcs 1130 Firmware No fix yet Fix from $2,3002019-07-02 HIGH 8.8 CVE-2019-13148 An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v… Tew 827dru Firmware 2.05b11+ Fix from $1,9502019-07-02 HIGH 8.8 CVE-2019-13150 An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication). … Tew 827dru Firmware 2.05b11+ Fix from $1,9502019-07-02 HIGH 8.8 CVE-2019-13152 An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v… Tew 827dru Firmware 2.05b11+ Fix from $1,9502019-07-02 HIGH 8.8 CVE-2019-13024EPSS 32% Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using t… Centreon Patch available Fix from $1,9502019-07-01