Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-07-01 CVE-2019-13024 Command Injection vulnerability in Centreon 19.04.0
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it by calling the vulnerable page www/include/configuration/configGenerate/xml/generateFiles.php (which passes the inserted value to the database to shell_exec without sanitizing it, allowing one to execute system arbitrary commands).
network
low complexity
centreon CWE-77
8.8
2019-06-20 CVE-2019-1624 Command Injection vulnerability in Cisco Sd-Wan
A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges.
network
low complexity
cisco CWE-77
8.8
2019-06-18 CVE-2017-8333 Command Injection vulnerability in Securifi products
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096.
network
low complexity
securifi CWE-77
8.8
2019-06-18 CVE-2017-8331 Command Injection vulnerability in Securifi products
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096.
network
low complexity
securifi CWE-77
8.8
2019-06-17 CVE-2018-19450 Command Injection vulnerability in Foxitsoftware Foxit PDF SDK Activex
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a launch action.
local
low complexity
foxitsoftware CWE-77
7.8
2019-06-17 CVE-2018-19445 Command Injection vulnerability in Foxitsoftware Foxit PDF SDK Activex 5.4.0.1031/5.5.0
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API app.launchURL is used.
local
low complexity
foxitsoftware CWE-77
7.8
2019-06-17 CVE-2017-9384 Command Injection vulnerability in Getvera Veraedge Firmware and Veralite Firmware
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices.
network
low complexity
getvera CWE-77
8.8
2019-06-17 CVE-2017-9388 Command Injection vulnerability in Getvera Veraedge Firmware and Veralite Firmware
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices.
network
low complexity
getvera CWE-77
8.8
2019-06-12 CVE-2019-7839 Command Injection vulnerability in Adobe Coldfusion 11.0/2016/2018
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability.
network
low complexity
adobe CWE-77
critical
9.8
2019-06-11 CVE-2017-18378 Command Injection vulnerability in Netgear Readynas Surveillance Firmware
In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=writeuploaddir remote command execution.
network
low complexity
netgear CWE-77
critical
9.8