Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-06-07 CVE-2018-19451 Command Injection vulnerability in Foxitsoftware Foxit PDF SDK Activex 5.4.0.1031/5.5.0
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when using the Open File action on a Field.
local
low complexity
foxitsoftware CWE-77
7.8
2019-06-07 CVE-2018-20523 Command Injection vulnerability in MI products
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection.
network
low complexity
mi CWE-77
5.3
2019-06-05 CVE-2019-5390 Command Injection vulnerability in HP Intelligent Management Center
A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
network
low complexity
hp CWE-77
critical
9.8
2019-06-03 CVE-2019-6739 Command Injection vulnerability in Malwarebytes Antimalware 3.6.1.2711
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711.
network
low complexity
malwarebytes CWE-77
8.8
2019-06-03 CVE-2019-12591 Command Injection vulnerability in Netgear Insight
NETGEAR Insight Cloud with firmware before Insight 5.6 allows remote authenticated users to achieve command injection.
network
low complexity
netgear CWE-77
7.6
2019-05-23 CVE-2019-10854 Command Injection vulnerability in Computrols Building Automation Software
Computrols CBAS 18.0.0 allows Authenticated Command Injection.
network
low complexity
computrols CWE-77
8.8
2019-05-22 CVE-2018-7826 Command Injection vulnerability in Schneider-Electric products
A Command Injection vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands.
network
low complexity
schneider-electric CWE-77
8.8
2019-05-22 CVE-2018-7825 Command Injection vulnerability in Schneider-Electric products
A Command Injection vulnerability exists in the web-based GUI of the 1st Gen PelcoSarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands.
network
low complexity
schneider-electric CWE-77
8.8
2019-05-15 CVE-2019-10640 Command Injection vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4.
network
low complexity
gitlab CWE-77
7.5
2019-04-26 CVE-2019-6689 Command Injection vulnerability in Dillonkane Tidal Workload Automation 3.2.0.5
An issue was discovered in Dillon Kane Tidal Workload Automation Agent 3.2.0.5 (formerly known as Cisco Workload Automation or CWA).
local
low complexity
dillonkane CWE-77
7.8