Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.7
CVE-2019-1782
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands…
Nx Os
2.2.2.91 / 2.3.1.130+
MEDIUM 6.7
CVE-2019-1783
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary c…
Nx Os
7.3 / 8.3+
MEDIUM 6.7
CVE-2019-1784
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux…
Nx Os
4.0 / 7.3+
MEDIUM 6.7
CVE-2019-1790
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with valid administrator credentials to execute arbit…
Nx Os
4.0 / 6.2+
HIGH 7.5
CVE-2019-10640
An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input vali…
GitLab
11.7.10 / 11.8.6+
HIGH 7.8
CVE-2019-1735
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privilege…
Nx Os
4.0 / 5.2+
HIGH 7.8
CVE-2019-6689
An issue was discovered in Dillon Kane Tidal Workload Automation Agent 3.2.0.5 (formerly known as Cisco Workload Automation or CWA). The Enterprise S…
Tidal Workload Automation
Mitigation only
CRITICAL 9.8
CVE-2019-11217
The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the context of the web server via a cr…
Bonobo Git Server
6.5.0+
CRITICAL 9.8
CVE-2019-11076
Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request.
Cribl
No fix yet
CRITICAL 9.8
CVE-2019-6579
A vulnerability has been identified in Spectrum Power 4 (with Web Office Portal). An attacker with network access to the web server on port 80/TCP or…
Spectrum Power 4
Mitigation only
HIGH 8.8
CVE-2019-5424
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to…
Edgeswitch X
after 1.1.0
CRITICAL 9.8
CVE-2019-6552
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-suppli…
Webaccess
after 8.3.5
CRITICAL 9.8
CVE-2019-5420EPSS 92%
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated dev…
Rails
5.2.2.1+
HIGH 8.8
CVE-2019-9743
An issue was discovered on PHOENIX CONTACT RAD-80211-XD and RAD-80211-XD/HP-BUS devices. Command injection can occur in the WebHMI component.
Rad 80211 Xd\/hp Bus Firmware
No fix yet
HIGH 7.2
CVE-2019-9059
An issue was discovered in CMS Made Simple 2.2.8. It is possible, with an administrator account, to achieve command injection by modifying the path o…
Cms Made Simple
after 2.2.8
CRITICAL 9.0
CVE-2019-7610
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.securi…
Kibana
5.6.15 / 6.6.1+
CRITICAL 9.8
CVE-2019-7537
An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can execute arbitrary Python comman…
Donfig
No fix yet
HIGH 8.0
CVE-2018-3963
An exploitable command injection vulnerability exists in the DHCP daemon configuration of the CUJO Smart Firewall. When adding a new static DHCP addr…
Smart Firewall
No fix yet
HIGH 8.8
CVE-2019-6272EPSS 13%
Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.
Gl Ar300m Lite Firmware
No fix yet
HIGH 8.8
CVE-2019-6275EPSS 13%
Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary cod…
Gl Ar300m Lite Firmware
No fix yet
CRITICAL 9.8
CVE-2019-5413
An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.
Morgan
1.9.1+
HIGH 8.1
CVE-2019-5414
If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec fu…
Kill Port
1.3.2+
MEDIUM 6.7
CVE-2019-1610
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…
Nx Os
7.0+
MEDIUM 6.7
CVE-2019-1611
A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands…
Nx Os
2.2.2.91 / 2.3.1.110+
MEDIUM 6.7
CVE-2019-1612
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…
Nx Os
7.0+
MEDIUM 6.7
CVE-2019-1613
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…
Nx Os
Mitigation only
HIGH 8.8
CVE-2019-1614
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root p…
Nx Os
7.0 / 7.3+
HIGH 7.8
CVE-2019-1606
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…
Nx Os
7.0+
MEDIUM 6.7
CVE-2019-1607
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…
Nx Os
6.2 / 7.3+
MEDIUM 6.7
CVE-2019-1608
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying opera…
Nx Os
6.2 / 7.3+