Skip to main content

CWE archive

CWE-77 CVEs

Programmatic archive

3,626 CVEs tagged with CWE-77953 Critical, 1,471 High, 772 Medium, 428 Low, 2 Unrated.

CVE-2019-12591

Published Jun 3, 2019

NETGEAR Insight Cloud with firmware before Insight 5.6 allows remote authenticated users to achieve command injection.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1784

Published May 15, 2019

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the pri…

CVSS 6.7 · Medium

CVE-2019-1783

Published May 15, 2019

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying Linu…

CVSS 6.7 · Medium

CVE-2019-10640

Published May 15, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6689

Published Apr 26, 2019

An issue was discovered in Dillon Kane Tidal Workload Automation Agent 3.2.0.5 (formerly known as Cisco Workload Automation or CWA). The Enterprise Scheduler for AIX allows local…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11217

Published Apr 24, 2019

The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the context of the web server via a crafted http request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11076

Published Apr 23, 2019

Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-6579

Published Apr 17, 2019

A vulnerability has been identified in Spectrum Power 4 (with Web Office Portal). An attacker with network access to the web server on port 80/TCP or 443/TCP could execute system…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-5424

Published Apr 10, 2019

In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to execute shell commands under…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6552

Published Apr 5, 2019

Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-supplied data, may allow remote code…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-9059

Published Mar 26, 2019

An issue was discovered in CMS Made Simple 2.2.8. It is possible, with an administrator account, to achieve command injection by modifying the path of the e-mail executable in Mai…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7610

Published Mar 25, 2019

Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true,…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 3,301-3,325 of 3,626 CVEsPage 133 of 146