Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,180 CVEs tagged with CWE-781,976 Critical, 3,126 High, 890 Medium, 188 Low, 0 Unrated.

CVE-2020-7645

Published May 2, 2020

All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7351

Published May 1, 2020

An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operat…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11016

Published Apr 30, 2020

IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled messages given by user-input in the "send" functionality of t…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-5623

Published Apr 29, 2020

Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection').

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-12078

Published Apr 28, 2020

An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an e…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7640

Published Apr 27, 2020

pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-21157

Published Apr 27, 2020

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.28, R6700 before 1.0.1.44, R6900 before 1.0.1.44, R7000 before…

CVSS 6.8 · Medium

CVE-2018-21152

Published Apr 27, 2020

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, R7500v2 before 1.0.3.26, R7800 before 1.0.2.42, R8900 befor…

CVSS 6.8 · Medium

CVE-2020-11941

Published Apr 27, 2020

An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12242

Published Apr 27, 2020

Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different user account.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5868

Published Apr 24, 2020

In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell commands on affected systems using HTTP requests to the BIG-…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 4,801-4,825 of 6,180 CVEsPage 193 of 248