Skip to main content

CWE archive

CWE-77 CVEs

Programmatic archive

3,699 CVEs tagged with CWE-77967 Critical, 1,505 High, 779 Medium, 445 Low, 3 Unrated.

CVE-2020-10514

Published Apr 15, 2020

iCatch DVR firmware before 20200103 do not validate function parameter properly, resulting attackers executing arbitrary command.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-3266

Published Mar 19, 2020

A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2019-16012

Published Mar 19, 2020

A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The v…

CVSS 8.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2020-1980

Published Mar 11, 2020

A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. This issue affects only PAN-OS…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12430

Published Mar 10, 2020

An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely thro…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5323

Published Feb 27, 2020

There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being p…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1790

Published Feb 18, 2020

GaussDB 200 with version of 6.5.1 have a command injection vulnerability. The software constructs part of a command using external input from users, but the software does not suff…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1811

Published Feb 18, 2020

GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerabil…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4635

Published Jan 28, 2020

IBM Security Secret Server 10.7 could allow a privileged user to perform unauthorized command injection due to imporoper input neutralization of special elements. IBM X-Force ID:…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-15010

Published Jan 15, 2020

Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from ver…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4982

Published Jan 10, 2020

LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17148

Published Jan 7, 2020

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (45485). An attacker must first ob…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 3,276-3,300 of 3,699 CVEsPage 132 of 148