Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-12651
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute c…
iOS
Mitigation only
HIGH 8.8
CVE-2019-13552
In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and…
Webaccess
after 8.4.1
HIGH 8.8
CVE-2019-16305EPSS 7%
In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants…
Mobaxterm
No fix yet
HIGH 7.8
CVE-2019-9254
In readArgumentList of zygote.java in Android 10, there is a possible command injection due to improper input validation. This could lead to local es…
Android
Mitigation only
HIGH 8.8
CVE-2019-7989EPSS 14%
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to a…
Photoshop Cc
after 20.0.5
CRITICAL 9.8
CVE-2019-7968EPSS 7%
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to a…
Photoshop Cc
after 20.0.5
CRITICAL 9.8
CVE-2019-8060EPSS 6%
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 201…
Acrobat Dc
15.006.30499 / 17.011.30144+
HIGH 8.8
CVE-2019-12104
The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-authentication command injectio…
M7350 Firmware
190531+
HIGH 8.8
CVE-2019-12805
NCSOFT Game Launcher, NC Launcher2 2.4.1.691 and earlier versions have a vulnerability in the custom protocol handler that could allow remote attacke…
Nc Launcher2
after 2.4.1.691
HIGH 7.8
CVE-2019-14745
In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's poss…
Fedora
3.7.0+
MEDIUM 5.3
CVE-2017-18442
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
Cpanel
56.0.49 / 58.0.49+
HIGH 7.8
CVE-2017-18400
cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).
Cpanel
62.0.35 / 64.0.42+
MEDIUM 6.5
CVE-2016-10849
cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82).
Cpanel
11.48.5.2 / 11.50.4.3+
HIGH 8.1
CVE-2016-10843
cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).
Cpanel
11.48.5.2 / 11.50.4.3+
CRITICAL 9.8
CVE-2019-1010174
CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attac…
Debian Linux
2.3.4+
CRITICAL 9.8
CVE-2019-7850EPSS 6%
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitr…
Campaign
after 18.10.5.8984
HIGH 7.5
CVE-2016-10762
The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used.
Camptix Event Ticketing
1.5.0+
MEDIUM 6.6
CVE-2019-1923
A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the devi…
Spa501g Firmware
after 7.6.2sr5
CRITICAL 9.8
CVE-2019-11535EPSS 5%
Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execu…
Re6400 Firmware
after 1.2.04.022
HIGH 7.2
CVE-2019-5446
Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.
Edgeswitch Firmware
1.8.2+
HIGH 7.8
CVE-2019-1893
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on…
Enterprise Nfv Infrastructure Software
Mitigation only
HIGH 7.2
CVE-2019-6622
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4, an undisclosed iControl REST worker is vulnerable to…
Big Ip Access Policy Manager
after 14.1.0.5
HIGH 8.8
CVE-2017-8413EPSS 10%
An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which is called "dldps2121" and lis…
Dcs 1130 Firmware
No fix yet
CRITICAL 9.8
CVE-2017-8404EPSS 8%
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings re…
Dcs 1130 Firmware
No fix yet
HIGH 8.8
CVE-2017-8411EPSS 6%
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings re…
Dcs 1130 Firmware
No fix yet
CRITICAL 9.8
CVE-2017-8408EPSS 5%
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings re…
Dcs 1130 Firmware
No fix yet
HIGH 8.8
CVE-2019-13148
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v…
Tew 827dru Firmware
2.05b11+
HIGH 8.8
CVE-2019-13150
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication). …
Tew 827dru Firmware
2.05b11+
HIGH 8.8
CVE-2019-13152
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) v…
Tew 827dru Firmware
2.05b11+
HIGH 8.8
CVE-2019-13024EPSS 32%
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using t…
Centreon
Patch available