Skip to main content

CWE archive

CWE-77 CVEs

Programmatic archive

3,626 CVEs tagged with CWE-77953 Critical, 1,471 High, 772 Medium, 428 Low, 2 Unrated.

CVE-2019-7537

Published Mar 21, 2019

An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can execute arbitrary Python commands, resulting in command execu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-3963

Published Mar 21, 2019

An exploitable command injection vulnerability exists in the DHCP daemon configuration of the CUJO Smart Firewall. When adding a new static DHCP address, its corresponding hostnam…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-5414

Published Mar 21, 2019

If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1611

Published Mar 11, 2019

A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating s…

CVSS 6.7 · Medium

CVE-2018-20236

Published Mar 8, 2019

There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker could send a malicious URI to a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2516

Published Feb 15, 2019

Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variable that is passed to the shell.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1000282

Published Feb 5, 2019

Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-3913

Published Jan 30, 2019

Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker to unmount any drive on the system leading to denial of ser…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19015

Published Jan 28, 2019

An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. An atta…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6986

Published Jan 28, 2019

SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1646

Published Jan 24, 2019

A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device configuration files. The vulner…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Showing 3,326-3,350 of 3,626 CVEsPage 134 of 146