Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-09-02 CVE-2019-10095 Command Injection vulnerability in Apache Zeppelin
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings.
network
low complexity
apache CWE-77
critical
9.8
2021-09-01 CVE-2021-36024 Command Injection vulnerability in Adobe Commerce and Magento Open Source
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint.
network
low complexity
adobe CWE-77
7.2
2021-08-31 CVE-2021-35220 Command Injection vulnerability in Solarwinds Orion Platform
Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.
network
low complexity
solarwinds CWE-77
7.2
2021-08-27 CVE-2020-19001 Command Injection vulnerability in Simiki Project Simiki 1.6.2.1
Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'.
network
low complexity
simiki-project CWE-77
critical
9.8
2021-08-25 CVE-2021-1580 Command Injection vulnerability in Cisco Application Policy Infrastructure Controller
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system.
network
low complexity
cisco CWE-77
7.2
2021-08-24 CVE-2021-39509 Command Injection vulnerability in Dlink Dir-816 Firmware 1.10Cnb05R1B011D88210
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function.
network
low complexity
dlink CWE-77
critical
9.8
2021-08-24 CVE-2021-39510 Command Injection vulnerability in Dlink Dir-816 Firmware 101Cnb04
An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function.
network
low complexity
dlink CWE-77
critical
9.8
2021-08-24 CVE-2021-38556 Command Injection vulnerability in Raspap 2.6.6
includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.
network
low complexity
raspap CWE-77
8.8
2021-08-24 CVE-2021-38611 Command Injection vulnerability in Nascent Remkon Device Manager 4.0.0.0
A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to execute arbitrary commands, as root, via shell metacharacters in the filename parameter to assets/index.php.
network
low complexity
nascent CWE-77
critical
9.8
2021-08-20 CVE-2020-18885 Command Injection vulnerability in PHPmywind 5.6
Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.
network
low complexity
phpmywind CWE-77
7.2