Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-05-24 CVE-2020-28902 Command Injection vulnerability in Nagios Fusion
Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.
network
low complexity
nagios CWE-77
critical
9.8
2021-05-24 CVE-2020-28908 Command Injection vulnerability in Nagios Fusion
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.
network
low complexity
nagios CWE-77
critical
9.8
2021-05-22 CVE-2021-1555 Command Injection vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device.
network
low complexity
cisco CWE-77
7.2
2021-05-22 CVE-2021-1560 Command Injection vulnerability in Cisco DNA Spaces: Connector 2.0
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device.
network
low complexity
cisco CWE-77
7.2
2021-05-18 CVE-2020-20951 Command Injection vulnerability in Pluck-Cms Pluck 4.7.10
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
network
low complexity
pluck-cms CWE-77
critical
9.8
2021-05-13 CVE-2020-12967 Command Injection vulnerability in AMD products
The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.
network
low complexity
amd CWE-77
7.2
2021-05-13 CVE-2021-26311 Command Injection vulnerability in AMD products
In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.
network
low complexity
amd CWE-77
7.2
2021-05-10 CVE-2021-29501 Command Injection vulnerability in Dav-Cogs Project Dav-Cogs
Ticketer is a command based ticket system cog (plugin) for the red discord bot.
network
low complexity
dav-cogs-project CWE-77
6.5
2021-05-06 CVE-2021-1498 Command Injection vulnerability in Cisco Hyperflex HX Data Platform
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.
network
low complexity
cisco CWE-77
critical
9.8
2021-05-05 CVE-2020-13664 Command Injection vulnerability in Drupal
Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances.
network
low complexity
drupal CWE-77
8.8