Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-08-26 CVE-2019-7989 Command Injection vulnerability in Adobe Photoshop CC
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability.
network
adobe CWE-77
6.8
2019-08-26 CVE-2019-7968 Command Injection vulnerability in Adobe Photoshop CC
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability.
network
low complexity
adobe CWE-77
critical
10.0
2019-08-20 CVE-2019-8060 Command Injection vulnerability in Adobe Acrobat DC
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a command injection vulnerability.
network
low complexity
adobe CWE-77
critical
10.0
2019-08-14 CVE-2019-12104 Command Injection vulnerability in Tp-Link M7350 Firmware 1.0.16/151021/160330
The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-authentication command injection vulnerabilities.
network
low complexity
tp-link CWE-77
critical
9.0
2019-08-13 CVE-2019-10928 Command Injection vulnerability in Siemens Scalance Sc-600 Firmware 2.0
A vulnerability has been identified in SCALANCE SC-600 (V2.0).
local
low complexity
siemens CWE-77
4.6
2019-08-09 CVE-2019-12805 Command Injection vulnerability in Ncsoft NC Launcher2 2.4.1.691
NCSOFT Game Launcher, NC Launcher2 2.4.1.691 and earlier versions have a vulnerability in the custom protocol handler that could allow remote attacker to execute arbitrary command.
network
ncsoft CWE-77
6.8
2019-08-07 CVE-2019-14745 Command Injection vulnerability in multiple products
In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c.
local
low complexity
radare fedoraproject CWE-77
7.8
2019-08-02 CVE-2017-18442 Command Injection vulnerability in Cpanel
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
network
low complexity
cpanel CWE-77
5.0
2019-08-02 CVE-2017-18400 Command Injection vulnerability in Cpanel
cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).
local
low complexity
cpanel CWE-77
7.2
2019-08-01 CVE-2016-10849 Command Injection vulnerability in Cpanel
cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82).
network
low complexity
cpanel CWE-77
4.0