Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-09-07 CVE-2021-37721 Command Injection vulnerability in multiple products
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25.
network
low complexity
arubanetworks siemens CWE-77
7.2
2021-09-07 CVE-2021-37722 Command Injection vulnerability in multiple products
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25.
network
low complexity
arubanetworks siemens CWE-77
7.2
2021-09-07 CVE-2021-37723 Command Injection vulnerability in multiple products
A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16.
network
low complexity
arubanetworks siemens CWE-77
7.2
2021-09-07 CVE-2021-37724 Command Injection vulnerability in multiple products
A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16.
network
low complexity
arubanetworks siemens CWE-77
7.2
2021-09-02 CVE-2020-18048 Command Injection vulnerability in Bertanddip Craigms 1.0
An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered into the DB Name field.
network
low complexity
bertanddip CWE-77
critical
9.8
2021-09-02 CVE-2019-10095 Command Injection vulnerability in Apache Zeppelin
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings.
network
low complexity
apache CWE-77
critical
9.8
2021-09-01 CVE-2021-36024 Command Injection vulnerability in Adobe Commerce and Magento Open Source
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint.
network
low complexity
adobe CWE-77
7.2
2021-08-31 CVE-2021-35220 Command Injection vulnerability in Solarwinds Orion Platform
Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.
network
low complexity
solarwinds CWE-77
7.2
2021-08-27 CVE-2020-19001 Command Injection vulnerability in Simiki Project Simiki 1.6.2.1
Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'.
network
low complexity
simiki-project CWE-77
critical
9.8
2021-08-25 CVE-2021-1580 Command Injection vulnerability in Cisco Application Policy Infrastructure Controller
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system.
network
low complexity
cisco CWE-77
7.2